Benjamin_ | 26.05.2014 17:52 | FRST Teil 2 Code:
==================== One Month Modified Files and Folders =======
2014-05-25 13:01 - 2014-05-25 11:39 - 00000000 ____D () C:\FRST
2014-05-25 13:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-05-25 12:50 - 2014-03-18 12:04 - 01780340 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-25 12:50 - 2014-03-18 11:25 - 00765378 _____ () C:\Windows\system32\perfh007.dat
2014-05-25 12:50 - 2014-03-18 11:25 - 00159696 _____ () C:\Windows\system32\perfc007.dat
2014-05-25 12:45 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-25 12:40 - 2014-05-10 23:31 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2014-05-25 12:39 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-25 12:35 - 2014-05-11 05:12 - 01426507 _____ () C:\Windows\WindowsUpdate.log
2014-05-25 12:00 - 2014-05-11 05:17 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2974170870-1882922953-1771957966-1001
2014-05-25 11:45 - 2014-05-25 11:45 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-25 11:45 - 2014-05-25 11:45 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-25 11:45 - 2014-05-25 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-25 11:45 - 2014-05-25 11:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-25 11:42 - 2014-05-10 23:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-25 11:42 - 2014-03-18 03:51 - 00090496 _____ () C:\Windows\PFRO.log
2014-05-25 11:37 - 2014-05-25 11:37 - 00000000 _____ () C:\Users\Benjamin_\defogger_reenable
2014-05-25 11:37 - 2014-05-11 05:12 - 00000000 ____D () C:\Users\Benjamin_
2014-05-25 11:35 - 2014-05-25 11:35 - 00000295 _____ () C:\Users\Benjamin_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Papierkorb.lnk
2014-05-25 02:35 - 2014-05-12 19:35 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Skype
2014-05-25 00:17 - 2014-05-12 19:56 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-24 23:59 - 2014-05-24 23:59 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-05-24 14:10 - 2014-05-24 14:10 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-24 14:10 - 2014-05-24 14:10 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-05-24 14:10 - 2014-05-24 14:10 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Mozilla
2014-05-24 14:10 - 2014-05-24 14:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-24 14:06 - 2014-05-24 14:06 - 12758764 _____ () C:\Users\Benjamin_\Desktop\Firefox 29.0.1 (de) - 2014-05-24.pcv
2014-05-24 13:46 - 2014-05-24 13:46 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Skyrim
2014-05-24 13:46 - 2014-05-18 13:26 - 00027750 _____ () C:\Windows\DirectX.log
2014-05-24 12:20 - 2014-05-24 12:20 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-24 12:16 - 2014-05-24 12:11 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Adobe
2014-05-24 12:16 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
2014-05-24 12:12 - 2014-05-24 12:12 - 00000000 ____D () C:\ProgramData\McAfee
2014-05-24 01:45 - 2014-05-18 00:45 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\vlc
2014-05-24 01:29 - 2014-05-24 01:29 - 00281144 _____ () C:\Windows\Minidump\052414-6125-01.dmp
2014-05-24 01:29 - 2014-05-11 12:15 - 542026097 _____ () C:\Windows\MEMORY.DMP
2014-05-24 01:29 - 2014-05-11 12:15 - 00000000 ____D () C:\Windows\Minidump
2014-05-24 01:12 - 2014-05-24 01:12 - 00281200 _____ () C:\Windows\Minidump\052414-6781-01.dmp
2014-05-24 00:11 - 2013-08-22 16:46 - 00014599 _____ () C:\Windows\setupact.log
2014-05-23 18:51 - 2014-05-23 18:51 - 00000222 _____ () C:\Users\Benjamin_\Desktop\Company of Heroes 2.url
2014-05-23 17:29 - 2014-05-15 17:38 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-05-21 21:22 - 2014-05-21 21:22 - 00012125 _____ () C:\Windows\avmacc.log
2014-05-21 21:22 - 2014-05-21 21:22 - 00005962 _____ () C:\Windows\avmsetup.log
2014-05-21 21:22 - 2014-05-21 21:22 - 00002877 _____ () C:\Windows\avmadd32.log
2014-05-21 21:22 - 2014-05-21 21:22 - 00000000 ____D () C:\Program Files (x86)\AVM_update
2014-05-21 21:22 - 2014-05-11 05:15 - 00013661 _____ () C:\Windows\avmfwlanci.log
2014-05-21 21:22 - 2014-05-11 05:15 - 00011202 _____ () C:\Windows\AVMInstall.Log
2014-05-21 21:22 - 2014-05-11 05:15 - 00000000 ____D () C:\Program Files (x86)\avmwlanstick
2014-05-20 20:59 - 2014-05-11 05:12 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Packages
2014-05-19 20:51 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-05-18 18:08 - 2014-05-18 18:08 - 00000815 _____ () C:\Users\Public\Desktop\Foxit Reader.lnk
2014-05-18 18:08 - 2014-05-18 18:08 - 00000000 ____D () C:\Users\Public\Foxit Software
2014-05-18 18:08 - 2014-05-18 18:08 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Foxit Software
2014-05-18 00:45 - 2014-05-18 00:45 - 00000637 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-05-18 00:45 - 2014-05-18 00:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-05-17 16:13 - 2014-05-17 16:13 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Halvar Information
2014-05-17 14:25 - 2014-05-17 14:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Synchronization Services
2014-05-17 14:25 - 2014-05-17 14:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Program Files\MSBuild
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-05-17 14:18 - 2014-05-17 14:18 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-05-17 14:18 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\SysWOW64\MUI
2014-05-17 14:18 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\MUI
2014-05-17 12:48 - 2014-05-17 12:48 - 00000521 _____ () C:\Users\Benjamin_\Desktop\Netzwerk- und Freigabecenter - Verknüpfung.lnk
2014-05-17 12:45 - 2014-05-17 12:45 - 00000222 _____ () C:\Users\Benjamin_\Desktop\Alan Wake.url
2014-05-17 00:48 - 2014-05-12 21:12 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-05-16 20:52 - 2014-05-16 20:52 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-05-16 18:37 - 2014-05-11 05:12 - 00000000 ___RD () C:\Users\Benjamin_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 18:37 - 2014-05-11 05:12 - 00000000 ___RD () C:\Users\Benjamin_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 18:37 - 2013-08-22 16:44 - 00473704 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-16 18:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-05-16 18:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2014-05-16 18:36 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\system32\oobe
2014-05-15 21:58 - 2014-05-15 21:58 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-05-15 18:20 - 2014-05-15 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-05-15 18:08 - 2014-05-15 18:08 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-05-14 21:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 21:47 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 21:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-05-14 21:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-05-14 21:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-14 21:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 21:14 - 2014-05-14 21:14 - 00001043 _____ () C:\Users\Public\Desktop\MozBackup.lnk
2014-05-14 21:14 - 2014-05-14 21:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup
2014-05-14 21:14 - 2014-05-14 21:14 - 00000000 ____D () C:\Program Files (x86)\MozBackup
2014-05-14 21:14 - 2014-05-11 00:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 21:13 - 2014-05-11 00:01 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 21:13 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-14 21:12 - 2014-05-14 21:12 - 00000493 _____ () C:\Users\Benjamin_\Desktop\Windows Update.lnk
2014-05-14 21:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-14 20:27 - 2014-05-14 20:27 - 00002114 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-05-14 20:27 - 2014-05-14 20:27 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Thunderbird
2014-05-14 20:27 - 2014-05-14 20:27 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Thunderbird
2014-05-14 20:27 - 2014-05-14 20:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-05-14 20:02 - 2014-05-14 20:02 - 00000000 ____D () C:\ProgramData\ATI
2014-05-13 19:30 - 2014-05-13 19:30 - 00062044 _____ () C:\Windows\SysWOW64\CCCInstall_201405131930001423.log
2014-05-13 19:29 - 2014-05-13 19:29 - 00054596 _____ () C:\Windows\SysWOW64\CCCInstall_201405131929245931.log
2014-05-13 19:29 - 2014-05-13 19:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-05-13 19:29 - 2014-05-13 19:29 - 00000000 ____D () C:\Program Files\ATI
2014-05-13 19:29 - 2014-05-13 19:29 - 00000000 ____D () C:\Program Files\AMD
2014-05-13 19:29 - 2014-05-13 19:29 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2014-05-13 19:29 - 2014-05-13 19:28 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-05-13 19:28 - 2014-05-10 23:31 - 00000000 ____D () C:\AMD
2014-05-13 19:03 - 2014-05-13 19:03 - 00055441 _____ () C:\Windows\SysWOW64\CCCInstall_201405131903542733.log
2014-05-13 19:03 - 2014-05-13 19:03 - 00054723 _____ () C:\Windows\SysWOW64\CCCInstall_201405131903411969.log
2014-05-13 18:15 - 2014-05-13 18:15 - 00000979 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-13 18:15 - 2014-05-13 18:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-13 18:15 - 2014-05-13 18:15 - 00000000 ____D () C:\Program Files (x86)\Fraps
2014-05-13 17:53 - 2014-05-13 17:53 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-05-12 21:14 - 2014-05-12 21:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-05-12 21:13 - 2014-05-12 21:13 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-05-12 21:13 - 2014-05-12 21:13 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-05-12 21:12 - 2014-05-12 21:12 - 00001145 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-05-12 21:12 - 2014-05-12 21:12 - 00001145 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-05-12 21:12 - 2014-05-12 21:12 - 00000222 _____ () C:\Users\Benjamin_\Desktop\Hitman Absolution.url
2014-05-12 21:12 - 2014-05-12 21:12 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Opera Software
2014-05-12 21:12 - 2014-05-12 21:12 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Opera Software
2014-05-12 20:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-05-12 20:49 - 2014-05-12 20:49 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\OpenOffice
2014-05-12 20:39 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-05-12 20:22 - 2014-05-12 20:22 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Avira
2014-05-12 20:21 - 2014-05-12 20:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-12 20:21 - 2014-05-12 20:05 - 00000000 ____D () C:\ProgramData\Avira
2014-05-12 20:21 - 2014-05-12 20:05 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-12 20:05 - 2014-05-10 23:31 - 00000000 ____D () C:\ProgramData\Package Cache
2014-05-12 19:56 - 2014-05-12 19:56 - 00000979 _____ () C:\Users\Public\Desktop\Steam.lnk
2014-05-12 19:56 - 2014-05-12 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-05-12 19:35 - 2014-05-12 19:35 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-05-12 19:35 - 2014-05-12 19:35 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-12 19:35 - 2014-05-12 19:35 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Skype
2014-05-12 19:35 - 2014-05-12 19:35 - 00000000 ____D () C:\ProgramData\Skype
2014-05-12 19:35 - 2014-05-12 19:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-05-12 18:42 - 2014-05-12 18:42 - 00281088 _____ () C:\Windows\Minidump\051214-4140-01.dmp
2014-05-12 18:41 - 2014-05-12 18:41 - 00000045 _____ () C:\Windows\SysWOW64\initdebug.nfo
2014-05-12 18:40 - 2014-05-12 18:40 - 00001335 _____ () C:\Users\Benjamin_\Desktop\FurMark.lnk
2014-05-12 18:40 - 2014-05-12 18:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D
2014-05-12 18:40 - 2014-05-12 18:40 - 00000000 ____D () C:\Program Files (x86)\Geeks3D
2014-05-12 07:26 - 2014-05-25 11:45 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-05-25 11:45 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-05-25 11:45 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 13:52 - 2014-05-11 13:52 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-05-11 12:15 - 2014-05-11 12:15 - 00281088 _____ () C:\Windows\Minidump\051114-4062-01.dmp
2014-05-11 06:08 - 2013-08-22 17:36 - 00262144 _____ () C:\Windows\system32\config\BCD-Template
2014-05-11 05:15 - 2014-05-11 05:15 - 00000000 ____D () C:\Windows\AVM_Driver
2014-05-11 05:15 - 2014-05-11 05:15 - 00000000 ____D () C:\Users\Benjamin_\AVM_Driver
2014-05-11 05:15 - 2014-05-11 05:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FRITZ!WLAN
2014-05-11 05:12 - 2014-05-11 06:08 - 00000000 ____D () C:\Windows\Panther
2014-05-11 05:12 - 2014-05-11 05:12 - 00001454 _____ () C:\Users\Benjamin_\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-05-11 05:12 - 2014-05-11 05:12 - 00000020 ___SH () C:\Users\Benjamin_\ntuser.ini
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Vorlagen
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Startmenü
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Netzwerkumgebung
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Lokale Einstellungen
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Eigene Dateien
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Druckumgebung
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\AppData\Local\Verlauf
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\AppData\Local\Anwendungsdaten
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 _SHDL () C:\Users\Benjamin_\Anwendungsdaten
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Adobe
2014-05-11 05:12 - 2014-05-11 05:12 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\VirtualStore
2014-05-11 05:11 - 2014-05-11 05:11 - 00000000 ____D () C:\Windows\CSC
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Programme
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-05-11 05:09 - 2014-05-11 05:09 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2014-05-11 05:09 - 2013-08-22 17:37 - 00002664 _____ () C:\Windows\DtcInstall.log
2014-05-11 05:09 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\Recovery
2014-05-11 05:09 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-05-11 05:09 - 2013-08-22 15:36 - 00000000 __RHD () C:\Users\Default
2014-05-11 00:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\setup
2014-05-11 00:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-05-11 00:22 - 2014-05-11 00:22 - 00055563 _____ () C:\Windows\SysWOW64\CCCInstall_201405110022535127.log
2014-05-11 00:22 - 2014-05-11 00:22 - 00054596 _____ () C:\Windows\SysWOW64\CCCInstall_201405110022089941.log
2014-05-11 00:01 - 2014-05-11 00:01 - 00000000 ___RD () C:\Windows\BrowserChoice
2014-05-11 00:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-05-10 23:47 - 2014-05-10 23:47 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Macromedia
2014-05-10 23:45 - 2014-05-10 23:45 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\ATI
2014-05-10 23:45 - 2014-05-10 23:45 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\ATI
2014-05-10 23:43 - 2014-05-10 23:43 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Intel Corporation
2014-05-10 23:43 - 2014-05-10 23:43 - 00000000 ____D () C:\Program Files\GIGABYTE
2014-05-10 23:43 - 2014-05-10 23:43 - 00000000 ____D () C:\Program Files (x86)\GIGABYTE
2014-05-10 23:43 - 2014-05-10 23:41 - 00000032 _____ () C:\csb.log
2014-05-10 23:43 - 2014-05-10 23:32 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-10 23:42 - 2014-05-10 23:42 - 01713704 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ____H () C:\ProgramData\DP45977C.lfl
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ____D () C:\Users\Benjamin_\Intel
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ____D () C:\ProgramData\Intel
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ____D () C:\Program Files\Realtek
2014-05-10 23:42 - 2014-05-10 23:42 - 00000000 ____D () C:\Program Files\Intel
2014-05-10 23:42 - 2014-05-10 23:41 - 00000189 _____ () C:\Install.log
2014-05-10 23:42 - 2014-05-10 23:41 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-05-10 23:41 - 2014-05-10 23:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2014-05-10 23:41 - 2014-05-10 23:41 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\InstallShield
2014-05-10 23:41 - 2014-05-10 23:41 - 00000000 ____D () C:\Program Files (x86)\Realtek
2014-05-10 23:40 - 2014-05-10 23:40 - 00000000 ____D () C:\Intel
2014-05-10 23:38 - 2014-05-10 23:38 - 00000010 _____ () C:\Windows\GSetup.ini
2014-05-10 23:32 - 2014-05-10 23:32 - 00055441 _____ () C:\Windows\SysWOW64\CCCInstall_201405102332115384.log
2014-05-10 23:31 - 2014-05-10 23:31 - 00000000 ____D () C:\Users\Benjamin_\Desktop\Prime95
2014-05-10 23:31 - 2014-05-10 23:31 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2014-05-10 23:31 - 2014-05-10 23:31 - 00000000 _____ () C:\Windows\ativpsrm.bin
2014-05-10 23:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\restore
2014-05-10 23:30 - 2014-05-10 23:30 - 00000885 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2014-05-10 23:30 - 2014-05-10 23:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2014-05-10 23:30 - 2014-05-10 23:30 - 00000000 ____D () C:\Program Files\CPUID
2014-05-10 23:27 - 2014-05-10 23:26 - 00000000 ____D () C:\Users\Benjamin_\AppData\Local\Mozilla
2014-05-10 23:26 - 2014-05-10 23:26 - 00000000 ____D () C:\ProgramData\Mozilla
2014-05-10 23:25 - 2014-05-10 23:25 - 00000000 __SHD () C:\Users\Benjamin_\AppData\Local\EmieUserList
2014-05-10 23:25 - 2014-05-10 23:25 - 00000000 __SHD () C:\Users\Benjamin_\AppData\Local\EmieSiteList
2014-05-10 23:25 - 2014-05-10 23:25 - 00000000 ____D () C:\Users\Benjamin_\AppData\Roaming\Macromedia
2014-05-06 06:40 - 2014-05-14 20:07 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 05:25 - 2014-05-14 20:07 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:00 - 2014-05-14 20:07 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-14 20:07 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-01 22:30 - 2013-08-22 17:38 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-01 22:30 - 2013-08-22 17:38 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Users\Benjamin_\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2014-05-16 18:30] - [2014-03-28 17:58] - 0407016 ____A (Microsoft Corporation) 067CB90C277DB4A737D5DEABA3055972
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2014-05-16 18:30] - [2014-03-06 14:42] - 0310616 ___AC (Microsoft Corporation) 4BB9BC49DEE1A319EC58274A7BBED663
LastRegBack: 2014-05-22 20:40
==================== End Of Log ============================ FRST - Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014
Ran by Benjamin_ at 2014-05-25 13:01:38
Running from F:\Downloads\trojaner-board.de
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Alan Wake (HKLM-x32\...\Steam App 108710) (Version: - Remedy Entertainment)
AMD Catalyst Control Center (x32 Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Avira (HKLM-x32\...\{3361e961-9e49-487c-b1ac-9255348ccbaf}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
AVM FRITZ!WLAN (HKLM-x32\...\AVMWLANCLI) (Version: 1.2.0.0 - AVM Berlin)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Company of Heroes 2 (HKLM-x32\...\Steam App 231430) (Version: - Relic Entertainment)
CPUID CPU-Z 1.69.2 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.3.99.311 - Foxit Corporation)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.2.0.429 - Foxit Corporation)
Fraps (HKLM-x32\...\Fraps) (Version: - )
Geeks3D FurMark 1.13.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.31.8.1 - Intel Corporation) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4615.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 ENU (HKLM-x32\...\{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}) (Version: 3.5.5386.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4615.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4615.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4615.1002 - Microsoft Corporation) Hidden
ON_OFF Charge 2 B13.1028.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE)
ON_OFF Charge 2 B13.1028.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden
Opera Stable 21.0.1432.67 (HKLM-x32\...\Opera 21.0.1432.67) (Version: 21.0.1432.67 - Opera Software ASA)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.21.909.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7076 - Realtek Semiconductor Corp.)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
==================== Restore Points =========================
21-05-2014 18:46:33 Geplanter Prüfpunkt
24-05-2014 11:46:07 DirectX wurde installiert
==================== Hosts content: ==========================
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0BC32B2D-93F4-45F4-B338-9BC59A6EB744} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {1F2D7BAE-62D4-4467-A97F-CD9E86C0B564} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4E3BDE5F-8ED5-45B1-A946-3641B3488144} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-04-15] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7C825EF8-0E17-468F-A289-5C3E245BD917} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-05-14] (Microsoft Corporation)
Task: {7CD03BED-D7F5-4761-B232-A3EF6D75F008} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {822493E6-F3FD-41DB-B1D3-AE544FB1F321} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-21] (Microsoft Corporation)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A9B946C6-71F6-4504-A414-449D3B0347DF} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {C52E3DF9-B82C-41F5-924C-EEF53EB6DE60} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-05-21] (Microsoft Corporation)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DCE3D606-9E17-4E65-B72D-0EF3F4603DE5} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-03-18] (Microsoft Corporation)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
==================== Loaded Modules (whitelisted) =============
2014-05-15 17:38 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-05-15 17:38 - 2014-04-15 03:39 - 00630952 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll
2014-05-12 20:21 - 2014-02-25 11:41 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-05-12 20:21 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\Benjamin_\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-05-10 23:41 - 2013-09-16 12:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/25/2014 00:47:17 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (05/25/2014 00:41:31 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (05/25/2014 00:35:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: 23ntgpjr.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: 23ntgpjr.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0xb04
Startzeit der fehlerhaften Anwendung: 0x23ntgpjr.exe0
Pfad der fehlerhaften Anwendung: 23ntgpjr.exe1
Pfad des fehlerhaften Moduls: 23ntgpjr.exe2
Berichtskennung: 23ntgpjr.exe3
Vollständiger Name des fehlerhaften Pakets: 23ntgpjr.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: 23ntgpjr.exe5
Error: (05/25/2014 00:30:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: 23ntgpjr.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: 23ntgpjr.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x4dc
Startzeit der fehlerhaften Anwendung: 0x23ntgpjr.exe0
Pfad der fehlerhaften Anwendung: 23ntgpjr.exe1
Pfad des fehlerhaften Moduls: 23ntgpjr.exe2
Berichtskennung: 23ntgpjr.exe3
Vollständiger Name des fehlerhaften Pakets: 23ntgpjr.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: 23ntgpjr.exe5
Error: (05/25/2014 00:30:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: 23ntgpjr.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: 23ntgpjr.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x1024
Startzeit der fehlerhaften Anwendung: 0x23ntgpjr.exe0
Pfad der fehlerhaften Anwendung: 23ntgpjr.exe1
Pfad des fehlerhaften Moduls: 23ntgpjr.exe2
Berichtskennung: 23ntgpjr.exe3
Vollständiger Name des fehlerhaften Pakets: 23ntgpjr.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: 23ntgpjr.exe5
Error: (05/25/2014 00:29:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: exovqmmm.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: exovqmmm.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0005ff40
ID des fehlerhaften Prozesses: 0x2d8
Startzeit der fehlerhaften Anwendung: 0xexovqmmm.exe0
Pfad der fehlerhaften Anwendung: exovqmmm.exe1
Pfad des fehlerhaften Moduls: exovqmmm.exe2
Berichtskennung: exovqmmm.exe3
Vollständiger Name des fehlerhaften Pakets: exovqmmm.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: exovqmmm.exe5
Error: (05/25/2014 00:26:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (05/25/2014 00:02:04 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (05/25/2014 00:00:34 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (05/25/2014 11:34:41 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
System errors:
=============
Error: (05/25/2014 00:45:34 PM) (Source: DCOM) (EventID: 10010) (User: Benjamin)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (05/25/2014 00:45:34 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084ShellHWDetectionNicht verfügbar{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (05/25/2014 00:45:25 PM) (Source: DCOM) (EventID: 10005) (User: Benjamin)
Description: 1084WSearchNicht verfügbar{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Microsoft Office Sessions:
=========================
Error: (05/25/2014 00:47:17 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestF:\Downloads\esetsmartinstaller_deu.exe
Error: (05/25/2014 00:41:31 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestF:\Downloads\esetsmartinstaller_deu.exe
Error: (05/25/2014 00:35:18 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 23ntgpjr.exe2.1.19357.052e7ea8323ntgpjr.exe2.1.19357.052e7ea83c0000005000011aab0401cf78050125b5cbF:\Downloads\trojaner-board.de\23ntgpjr.exeF:\Downloads\trojaner-board.de\23ntgpjr.exe43c99529-e3f8-11e3-826a-74d43583fd69
Error: (05/25/2014 00:30:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 23ntgpjr.exe2.1.19357.052e7ea8323ntgpjr.exe2.1.19357.052e7ea83c0000005000011aa4dc01cf78045c9284b9F:\Downloads\trojaner-board.de\23ntgpjr.exeF:\Downloads\trojaner-board.de\23ntgpjr.exea0cbf9ee-e3f7-11e3-826a-74d43583fd69
Error: (05/25/2014 00:30:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 23ntgpjr.exe2.1.19357.052e7ea8323ntgpjr.exe2.1.19357.052e7ea83c0000005000011aa102401cf7804584d6a65F:\Downloads\trojaner-board.de\23ntgpjr.exeF:\Downloads\trojaner-board.de\23ntgpjr.exe9801e3fd-e3f7-11e3-826a-74d43583fd69
Error: (05/25/2014 00:29:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: exovqmmm.exe2.1.19357.052e7ea83exovqmmm.exe2.1.19357.052e7ea83c00000050005ff402d801cf7804443756bcF:\Downloads\trojaner-board.de\exovqmmm.exeF:\Downloads\trojaner-board.de\exovqmmm.exe84460006-e3f7-11e3-826a-74d43583fd69
Error: (05/25/2014 00:26:09 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestF:\Downloads\esetsmartinstaller_deu.exe
Error: (05/25/2014 00:02:04 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestF:\Downloads\esetsmartinstaller_deu.exe
Error: (05/25/2014 00:00:34 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe
Error: (05/25/2014 11:34:41 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestF:\Downloads\esetsmartinstaller_deu.exe
==================== Memory info ===========================
Percentage of memory in use: 15%
Total physical RAM: 8145.15 MB
Available physical RAM: 6851.24 MB
Total Pagefile: 16337.15 MB
Available Pagefile: 14880.31 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:223.05 GB) (Free:131.86 GB) NTFS
Drive f: (Programme_Daten) (Fixed) (Total:1862.89 GB) (Free:1733.43 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 224 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================ Defogger Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 11:37 on 25/05/2014 (Benjamin_)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
GMER Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-05-25 12:45:04
Windows 6.3.9600 x64 \Device\Harddisk1\DR1 -> \Device\0000002f Crucial_CT240M500SSD1 rev.MU05 223,57GB
Running: 23ntgpjr.exe; Driver: C:\Users\BENJAM~1\AppData\Local\Temp\uglyqpow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff8025155ed00 4 bytes [C0, 52, AC, FF]
.text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 965 fffff8025155ed05 87 bytes [AD, 4E, 03, 40, 6A, A5, 04, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\Explorer.EXE[1016] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 714 00007ffa5f6d154a 4 bytes [6D, 5F, FA, 7F]
.text C:\Windows\Explorer.EXE[1016] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 722 00007ffa5f6d1552 4 bytes [6D, 5F, FA, 7F]
.text C:\Windows\Explorer.EXE[1016] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 98 00007ffa5f6d162a 4 bytes [6D, 5F, FA, 7F]
.text C:\Windows\Explorer.EXE[1016] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 122 00007ffa5f6d1642 4 bytes [6D, 5F, FA, 7F]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [436:444] fffff96000975b90
---- EOF - GMER 2.1 ---- Anti-Malware Code:
<?xml version="1.0" encoding="UTF-16" ?>
<mbam-log>
<header>
<date>2014/05/25 14:20:29 +0200</date>
<logfile>mbam-log-2014-05-25 (14-20-26).xml</logfile>
<isadmin>yes</isadmin>
</header>
<engine>
<version>2.00.2.1012</version>
<malware-database>v2014.05.25.02</malware-database>
<rootkit-database>v2014.05.21.01</rootkit-database>
<license>trial</license>
<file-protection>enabled</file-protection>
<web-protection>enabled</web-protection>
<self-protection>disabled</self-protection>
</engine>
<system>
<osversion>Windows 8.1</osversion>
<arch>x64</arch>
<username>Benjamin_</username>
<filesys>NTFS</filesys>
</system>
<summary>
<type>threat</type>
<result>completed</result>
<objects>0</objects>
<time>0</time>
<processes>0</processes>
<modules>0</modules>
<keys>0</keys>
<values>0</values>
<datas>0</datas>
<folders>0</folders>
<files>44</files>
<sectors>0</sectors>
</summary>
<options>
<memory>enabled</memory>
<startup>enabled</startup>
<filesystem>enabled</filesystem>
<archives>enabled</archives>
<rootkits>enabled</rootkits>
<deeprootkit>disabled</deeprootkit>
<heuristics>enabled</heuristics>
<pup>enabled</pup>
<pum>enabled</pum>
</options>
<items>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.admin", false);</baddata><gooddata></gooddata><hash>c54a91c3a5d691a563b05e26897b17e9</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.aflt", "babsst");</baddata><gooddata></gooddata><hash>64ab78dc7dfe88ae947fe79dff05a759</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.babExt", "");</baddata><gooddata></gooddata><hash>28e7dd773942d165f71c7b094cb837c9</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.babTrack", "affID=108298");</baddata><gooddata></gooddata><hash>b55a351f9eddca6c977cc3c129dbc33d</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.bbDpng", 24);</baddata><gooddata></gooddata><hash>f718b2a2a2d92e0822f14b39e71d12ee</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.dfltLng", "en");</baddata><gooddata></gooddata><hash>d23d43115823eb4bcb489de75da750b0</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.dfltSrch", false);</baddata><gooddata></gooddata><hash>e32c4f054536db5b2ce7057fb64edd23</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.hmpg", false);</baddata><gooddata></gooddata><hash>6ba4b3a15a21d264c84bb9cb29db9b65</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.id", "a0272f3700000000000000215de92fc9");</baddata><gooddata></gooddata><hash>06093e164a31082e4ac9fd87a65e758b</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.instlDay", "15375");</baddata><gooddata></gooddata><hash>8689bc982a516fc7db383d47a0645aa6</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.instlRef", "sst");</baddata><gooddata></gooddata><hash>937c193ba9d23402cc470c7836ce5fa1</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.lastDP", 24);</baddata><gooddata></gooddata><hash>c14ec19369120630f320f58ffe0633cd</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1713:04:39");</baddata><gooddata></gooddata><hash>b9569eb6bfbcd56163b0d9abf80cfa06</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "29.0");</baddata><gooddata></gooddata><hash>d93604504a317bbbd83b6a1a64a007f9</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.newTab", true);</baddata><gooddata></gooddata><hash>c8475400bfbc87af80938df7768e4cb4</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");</baddata><gooddata></gooddata><hash>24eb75df9cdf78bead666321887c30d0</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.noFFXTlbr", false);</baddata><gooddata></gooddata><hash>e926272ddaa188aec94aa5dfe91b21df</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");</baddata><gooddata></gooddata><hash>3fd076de1a6172c4db381e660ff556aa</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.propectorlck", 139486219);</baddata><gooddata></gooddata><hash>0f00ed67e596c175a96acdb7b15345bb</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.prtnrId", "babylon");</baddata><gooddata></gooddata><hash>709fd97b54270135868df4904bb90ff1</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.ptch_0717", true);</baddata><gooddata></gooddata><hash>b05fdf75a3d83bfbd53ecfb5ca3a57a9</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.smplGrp", "azb");</baddata><gooddata></gooddata><hash>33dcc88cc4b71125a0734f3516ee47b9</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.srcExt", "ss");</baddata><gooddata></gooddata><hash>28e76fe5d3a8bf77fd16c6bedc28a35d</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.tlbrId", "base");</baddata><gooddata></gooddata><hash>a966b69e5625a6908a89424234d09a66</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");</baddata><gooddata></gooddata><hash>fc13fb597b008fa773a08df7b94bfa06</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1713:04:39");</baddata><gooddata></gooddata><hash>2be4b0a47209b1857e95d6ae33d135cb</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");</baddata><gooddata></gooddata><hash>58b7054f3546989e0e0598ec33d1b64a</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.aflt", "babsst");</baddata><gooddata></gooddata><hash>8d82d87cbcbf75c1789bec98f311a45c</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.babExt", "");</baddata><gooddata></gooddata><hash>8f80262e88f34ee87b984b391be9d12f</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108298");</baddata><gooddata></gooddata><hash>9e715df780fbb28433e08ff50bf952ae</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.hardId", "a0272f3700000000000000215de92fc9");</baddata><gooddata></gooddata><hash>f817df7552298aacc64d1d67877d0000</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.id", "a0272f3700000000000000215de92fc9");</baddata><gooddata></gooddata><hash>6fa000545229fb3bce450d77956fcf31</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.instlDay", "15375");</baddata><gooddata></gooddata><hash>13fc99bb7dfe2115c74cf4902ed6a25e</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.instlRef", "sst");</baddata><gooddata></gooddata><hash>9877e86c2556f14541d26f1558acf907</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.newTab", false);</baddata><gooddata></gooddata><hash>bf501c38017a16200d06127264a0857b</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");</baddata><gooddata></gooddata><hash>a867f65eafcc42f4a86b9fe53dc77c84</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");</baddata><gooddata></gooddata><hash>6aa52430295257df32e193f172926d93</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.smplGrp", "none");</baddata><gooddata></gooddata><hash>22ed045082f98aaca76ce3a103012cd4</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.srcExt", "ss");</baddata><gooddata></gooddata><hash>9f7084d02d4ea591bd560183d72dc23e</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.tlbrId", "base");</baddata><gooddata></gooddata><hash>cd42d97b8bf01d19070cabd98b798878</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");</baddata><gooddata></gooddata><hash>3cd3064ecbb049ed9f74d9ab4cb86f91</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1713:04:39");</baddata><gooddata></gooddata><hash>a867a8ac4b3052e43cd7b4d0699bab55</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Babylon.A</vendor><action>replaced</action><baddata>user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");</baddata><gooddata></gooddata><hash>e629490b0873d95dbf54374d37cdab55</hash></file>
<file><path>C:\Users\Benjamin_\AppData\Roaming\Mozilla\Firefox\Profiles\auh2a4hb.default\prefs.js</path><vendor>PUP.Optional.Conduit.A</vendor><action>replaced</action><baddata>user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}");</baddata><gooddata></gooddata><hash>709fc391f883aa8c4f29a9db8d774bb5</hash></file>
</items>
</mbam-log> |