Hallo schrauber, TFC habe ich durchlaufen lassen und er hat ca 14.000 dateien runtergeworfen. Nun die ergebnisse:
zu Eset Smartinstaller:
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetesets_scanner_update returned -1 esets_gle=12
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=96eafbed141a9e48898ae511984b00da
# engine=14584
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-07-30 12:36:20
# local_time=2013-07-30 02:36:20 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode=3592 16777213 100 91 1474383 125850276 0 0
# compatibility_mode=5122 16777214 0 9 5956715 34679490 0 0
# compatibility_mode=5893 16776574 100 94 5956972 34693891 0 0
# scanned=183553
# found=0
# cleaned=0
# scan_time=3680
und zu Security Check
Results of screen317's Security Check version 0.99.71
x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Defender
Norton 360
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware Version 1.75.0.1300
Adobe Flash Player 11.8.800.94
Adobe Reader 10.1.7
Adobe Reader out of Date!
Mozilla Firefox (22.0)
Mozilla Thunderbird (17.0.7)
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
zu guter letzt ein neues FRST
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013
Ran by Lutz (administrator) on 30-07-2013 15:14:20
Running from C:\Users\Lutz\Desktop
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\system32\igfxpers.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Users\Lutz\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12936848 2012-07-13] (Realtek Semiconductor)
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKCU\...\RunOnce: [Uninstall C:\Users\Lutz\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Lutz\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64" [404992 2012-07-26] (Microsoft Corporation)
HKCU\...\RunOnce: [Uninstall C:\Users\Lutz\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Lutz\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910" [404992 2012-07-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [37960 2013-05-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2012-11-27] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [3423104 2012-08-31] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation)
Startup: C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login.
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default
FF Keyword.URL: hxxp://www.google.de/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\searchplugins\computer-bild-suche.xml
FF Extension: No Name - C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\sfie7b8a.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\IPSFFPlgn\
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK
FF Extension: No Name - C:\Program Files\McAfee\MSK
==================== Services (Whitelisted) =================
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-06] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
S2 0052531368808816mcinstcleanup; C:\Windows\TEMP\005253~1.EXE -cleanup -nolog [x]
==================== Drivers (Whitelisted) ====================
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-05-31] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-06-11] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-06-11] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-06-11] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130727.001\IDSvia64.sys [513184 2013-06-08] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\IPSDefs\20130727.001\IDSvia64.sys [513184 2013-06-08] (Symantec Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130729.019\ENG64.SYS [126040 2013-06-11] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130729.019\ENG64.SYS [126040 2013-06-11] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130729.019\EX64.SYS [2098776 2013-06-11] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.1.22\Definitions\VirusDefs\20130729.019\EX64.SYS [2098776 2013-06-11] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1404000.028\SymELAM.sys [23448 2012-11-15] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-06-21] (Anchorfree Inc.)
U0 msahci;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-30 13:29 - 2013-07-30 13:29 - 00000000 ____D C:\Program Files (x86)\ESET
2013-07-30 13:25 - 2013-07-30 13:25 - 00891098 _____ C:\Users\Lutz\Desktop\SecurityCheck.exe
2013-07-30 13:24 - 2013-07-30 13:24 - 02347384 _____ (ESET) C:\Users\Lutz\Desktop\esetsmartinstaller_enu.exe
2013-07-30 13:24 - 2013-07-30 13:24 - 00448512 _____ (OldTimer Tools) C:\Users\Lutz\Desktop\TFC.exe
2013-07-29 17:41 - 2013-07-29 17:41 - 00000000 ____D C:\Windows\ERUNT
2013-07-29 17:37 - 2013-07-29 17:37 - 00004568 _____ C:\AdwCleaner[S1].txt
2013-07-29 17:37 - 2013-07-29 17:37 - 00004408 _____ C:\AdwCleaner[R1].txt
2013-07-29 17:24 - 2013-07-29 17:24 - 00666633 _____ C:\Users\Lutz\Desktop\adwcleaner.exe
2013-07-29 17:24 - 2013-07-29 17:24 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\Lutz\Desktop\JRT.exe
2013-07-29 12:42 - 2013-07-29 12:42 - 00000000 ____D C:\FRST
2013-07-29 12:41 - 2013-07-29 12:42 - 01780547 _____ (Farbar) C:\Users\Lutz\Desktop\FRST64.exe
2013-07-27 11:04 - 2013-07-29 14:01 - 00000408 _____ C:\Users\Gast\AppData\Roaming\sp_data.sys
2013-07-27 11:04 - 2013-07-27 11:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ASUS WebStorage
2013-07-27 11:04 - 2013-07-27 11:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Apple Computer
2013-07-27 11:02 - 2013-07-27 11:03 - 00000000 ____D C:\Users\Gast
2013-07-27 11:02 - 2013-07-27 11:02 - 00000020 ___SH C:\Users\Gast\ntuser.ini
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Vorlagen
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Startmenü
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Netzwerkumgebung
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Lokale Einstellungen
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Eigene Dateien
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Druckumgebung
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Musik
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Bilder
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\AppData\Local\Verlauf
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\AppData\Local\Anwendungsdaten
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Anwendungsdaten
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Packages
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Local\ASUS
2013-07-27 10:58 - 2013-07-27 10:52 - 00602112 _____ (OldTimer Tools) C:\Users\Lutz\Desktop\OTL.exe
2013-07-27 10:56 - 2013-07-27 10:56 - 00388608 _____ (Trend Micro Inc.) C:\Users\Lutz\Downloads\HijackThis.exe
2013-07-27 10:52 - 2013-07-27 10:52 - 00602112 _____ (OldTimer Tools) C:\Users\Lutz\Downloads\OTL.exe
2013-07-26 22:46 - 2013-07-26 22:46 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984763435-1055683380-3862706603-1004
2013-07-26 22:37 - 2013-07-27 11:00 - 00000000 ____D C:\Users\Maike
2013-07-26 21:46 - 2013-07-26 21:46 - 00000795 _____ C:\Windows\setupact.log
2013-07-26 21:46 - 2013-07-26 21:46 - 00000000 _____ C:\Windows\setuperr.log
2013-07-26 21:35 - 2013-07-26 21:35 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-26 21:35 - 2013-07-26 21:35 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Malwarebytes
2013-07-26 21:35 - 2013-07-26 21:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-26 21:35 - 2013-07-26 21:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-26 21:35 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-07-26 21:29 - 2013-07-26 21:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lutz\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-26 15:26 - 2013-07-26 15:43 - 03260909 _____ (Safer-Networking Ltd. ) C:\Users\Lutz\Downloads\spybot-2.1.exe.part
2013-07-26 15:26 - 2013-07-26 15:26 - 00000000 _____ C:\Users\Lutz\Downloads\spybot-2.1.exe
2013-07-25 16:10 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-07-25 16:10 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-07-25 16:10 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2013-07-25 16:10 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-07-25 16:10 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2013-07-25 16:10 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2013-07-25 16:10 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-07-25 16:10 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-07-25 16:10 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2013-07-25 16:10 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-07-25 16:10 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2013-07-25 16:10 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2013-07-25 16:10 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2013-07-25 16:10 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2013-07-25 16:10 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-07-25 16:10 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2013-07-25 16:10 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-07-25 16:10 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-07-25 16:10 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2013-07-25 16:10 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2013-07-25 16:10 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2013-07-25 16:10 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2013-07-25 16:10 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2013-07-25 16:10 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2013-07-25 16:10 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2013-07-25 16:10 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2013-07-25 16:10 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2013-07-25 16:10 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2013-07-25 16:10 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys
2013-07-25 16:10 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2013-07-25 16:10 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2013-07-25 16:10 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2013-07-25 16:10 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2013-07-25 16:10 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml
2013-07-25 16:09 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-07-25 16:01 - 2013-07-27 12:41 - 00535382 _____ C:\Windows\WindowsUpdate.log
2013-07-18 16:18 - 2013-07-26 22:34 - 00001914 _____ C:\Windows\PFRO.log
2013-07-15 23:34 - 2013-07-15 23:34 - 01067456 _____ (Solid State Networks) C:\Users\Lutz\Downloads\install_flashplayer11x32au_mssd_aaa_aih(1).exe
2013-07-15 17:01 - 2013-07-15 17:01 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Thunderbird
2013-07-15 17:01 - 2013-07-15 17:01 - 00000000 ____D C:\Users\Lutz\AppData\Local\Thunderbird
2013-07-15 16:58 - 2013-07-15 16:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-07-15 16:46 - 2013-07-15 16:48 - 19678576 _____ (Mozilla) C:\Users\Lutz\Downloads\Thunderbird_Setup_17.0.7.exe
2013-07-13 18:47 - 2013-07-13 18:47 - 00421880 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-13 16:34 - 2013-07-26 22:33 - 00000000 ____D C:\Users\Lutz\Downloads\Setup
2013-07-12 15:23 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-12 15:19 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-12 15:19 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-12 15:19 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-12 15:19 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-12 15:19 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-12 15:19 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-12 15:19 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-12 15:19 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-12 15:19 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-12 15:19 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-12 15:19 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-12 15:19 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-12 15:19 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-12 15:19 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-12 15:19 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-12 15:19 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-12 15:19 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-12 14:57 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-12 14:57 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-12 14:55 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-12 14:55 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 20:23 - 2013-07-11 20:23 - 00000000 ____D C:\Windows\SysWOW64\Hotspot Shield
2013-07-11 14:45 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-07-11 14:45 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 14:45 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-02 15:51 - 2013-07-02 15:51 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-07-02 15:51 - 2013-07-02 15:51 - 00000000 ____D C:\Windows\system32\NV
2013-07-02 00:38 - 2013-07-02 00:38 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-07-02 00:35 - 2013-06-21 14:06 - 27781920 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 21102368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 15920536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 15144928 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 13411896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 11235104 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2013-07-02 00:35 - 2013-06-21 14:06 - 09239344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 07687592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 07641832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 06324360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 02953504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 02777888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 02363680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00572704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00467232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00465184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00218592 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00181488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2013-07-02 00:35 - 2013-06-21 14:06 - 00030496 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
201
==================== One Month Modified Files and Folders =======
2013-07-30 15:11 - 2013-05-16 15:21 - 00002242 _____ C:\Users\Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2013-07-30 15:10 - 2013-07-30 15:10 - 00000000 ___RD C:\Users\Lutz\SkyDrive
2013-07-30 15:10 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz
2013-07-30 15:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-07-30 14:48 - 2013-05-16 17:54 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-30 14:38 - 2013-05-16 15:31 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984763435-1055683380-3862706603-1002
2013-07-30 13:29 - 2013-07-30 13:29 - 00000000 ____D C:\Program Files (x86)\ESET
2013-07-30 13:27 - 2013-05-16 15:24 - 00000507 _____ C:\Users\Lutz\AppData\Roaming\sp_data.sys
2013-07-30 13:25 - 2013-07-30 13:25 - 00891098 _____ C:\Users\Lutz\Desktop\SecurityCheck.exe
2013-07-30 13:24 - 2013-07-30 13:24 - 02347384 _____ (ESET) C:\Users\Lutz\Desktop\esetsmartinstaller_enu.exe
2013-07-30 13:24 - 2013-07-30 13:24 - 00448512 _____ (OldTimer Tools) C:\Users\Lutz\Desktop\TFC.exe
2013-07-30 13:13 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-30 07:44 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2013-07-29 17:41 - 2013-07-29 17:41 - 00000000 ____D C:\Windows\ERUNT
2013-07-29 17:37 - 2013-07-29 17:37 - 00004568 _____ C:\AdwCleaner[S1].txt
2013-07-29 17:37 - 2013-07-29 17:37 - 00004408 _____ C:\AdwCleaner[R1].txt
2013-07-29 17:24 - 2013-07-29 17:24 - 00666633 _____ C:\Users\Lutz\Desktop\adwcleaner.exe
2013-07-29 17:24 - 2013-07-29 17:24 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\Lutz\Desktop\JRT.exe
2013-07-29 14:01 - 2013-07-27 11:04 - 00000408 _____ C:\Users\Gast\AppData\Roaming\sp_data.sys
2013-07-29 12:42 - 2013-07-29 12:42 - 00000000 ____D C:\FRST
2013-07-29 12:42 - 2013-07-29 12:41 - 01780547 _____ (Farbar) C:\Users\Lutz\Desktop\FRST64.exe
2013-07-28 16:15 - 2013-05-23 15:51 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-07-27 12:41 - 2013-07-25 16:01 - 00535382 _____ C:\Windows\WindowsUpdate.log
2013-07-27 11:04 - 2013-07-27 11:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\ASUS WebStorage
2013-07-27 11:04 - 2013-07-27 11:04 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Apple Computer
2013-07-27 11:03 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast
2013-07-27 11:02 - 2013-07-27 11:02 - 00000020 ___SH C:\Users\Gast\ntuser.ini
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Vorlagen
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Startmenü
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Netzwerkumgebung
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Lokale Einstellungen
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Eigene Dateien
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Druckumgebung
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Musik
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Documents\Eigene Bilder
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\AppData\Local\Verlauf
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\AppData\Local\Anwendungsdaten
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 _SHDL C:\Users\Gast\Anwendungsdaten
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Adobe
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Local\Packages
2013-07-27 11:02 - 2013-07-27 11:02 - 00000000 ____D C:\Users\Gast\AppData\Local\ASUS
2013-07-27 11:00 - 2013-07-26 22:37 - 00000000 ____D C:\Users\Maike
2013-07-27 11:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-07-27 10:57 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz\AppData\Local\VirtualStore
2013-07-27 10:56 - 2013-07-27 10:56 - 00388608 _____ (Trend Micro Inc.) C:\Users\Lutz\Downloads\HijackThis.exe
2013-07-27 10:52 - 2013-07-27 10:58 - 00602112 _____ (OldTimer Tools) C:\Users\Lutz\Desktop\OTL.exe
2013-07-27 10:52 - 2013-07-27 10:52 - 00602112 _____ (OldTimer Tools) C:\Users\Lutz\Downloads\OTL.exe
2013-07-26 22:46 - 2013-07-26 22:46 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2984763435-1055683380-3862706603-1004
2013-07-26 22:34 - 2013-07-18 16:18 - 00001914 _____ C:\Windows\PFRO.log
2013-07-26 22:33 - 2013-07-13 16:34 - 00000000 ____D C:\Users\Lutz\Downloads\Setup
2013-07-26 21:50 - 2012-08-03 01:02 - 00753134 _____ C:\Windows\system32\perfh007.dat
2013-07-26 21:50 - 2012-08-03 01:02 - 00155826 _____ C:\Windows\system32\perfc007.dat
2013-07-26 21:50 - 2012-07-26 09:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-26 21:46 - 2013-07-26 21:46 - 00000795 _____ C:\Windows\setupact.log
2013-07-26 21:46 - 2013-07-26 21:46 - 00000000 _____ C:\Windows\setuperr.log
2013-07-26 21:35 - 2013-07-26 21:35 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-26 21:35 - 2013-07-26 21:35 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Malwarebytes
2013-07-26 21:35 - 2013-07-26 21:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-26 21:35 - 2013-07-26 21:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-07-26 21:35 - 2013-07-26 21:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lutz\Downloads\mbam-setup-1.75.0.1300.exe
2013-07-26 15:43 - 2013-07-26 15:26 - 03260909 _____ (Safer-Networking Ltd. ) C:\Users\Lutz\Downloads\spybot-2.1.exe.part
2013-07-26 15:26 - 2013-07-26 15:26 - 00000000 _____ C:\Users\Lutz\Downloads\spybot-2.1.exe
2013-07-26 13:56 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-07-15 23:37 - 2013-05-16 17:20 - 00000000 ____D C:\Users\Lutz\AppData\Local\Adobe
2013-07-15 23:36 - 2013-05-16 17:54 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-15 23:34 - 2013-07-15 23:34 - 01067456 _____ (Solid State Networks) C:\Users\Lutz\Downloads\install_flashplayer11x32au_mssd_aaa_aih(1).exe
2013-07-15 21:54 - 2013-05-16 16:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-15 17:01 - 2013-07-15 17:01 - 00000000 ____D C:\Users\Lutz\AppData\Roaming\Thunderbird
2013-07-15 17:01 - 2013-07-15 17:01 - 00000000 ____D C:\Users\Lutz\AppData\Local\Thunderbird
2013-07-15 16:58 - 2013-07-15 16:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-07-15 16:48 - 2013-07-15 16:46 - 19678576 _____ (Mozilla) C:\Users\Lutz\Downloads\Thunderbird_Setup_17.0.7.exe
2013-07-14 15:22 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe
2013-07-13 18:47 - 2013-07-13 18:47 - 00421880 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-13 13:01 - 2012-07-26 11:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 15:20 - 2013-05-17 16:38 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-11 20:23 - 2013-07-11 20:23 - 00000000 ____D C:\Windows\SysWOW64\Hotspot Shield
2013-07-11 20:23 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-07-05 13:48 - 2013-05-16 15:39 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-07-04 22:49 - 2013-06-27 22:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-02 15:51 - 2013-07-02 15:51 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-07-02 15:51 - 2013-07-02 15:51 - 00000000 ____D C:\Windows\system32\NV
2013-07-02 00:38 - 2013-07-02 00:38 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2013-07-02 00:38 - 2012-12-28 18:23 - 00000000 ____D C:\ProgramData\NVIDIA
2013-07-02 00:38 - 2012-12-28 18:22 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-07-01 15:27 - 2013-05-16 15:21 - 00000000 ____D C:\Users\Lutz\AppData\Local\Packages
2013-07-01 01:05 - 2013-06-17 15:10 - 00000000 ____D C:\Users\Lutz\AppData\Local\CrashDumps
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-21 13:38
==================== End Of Log ============================
--- --- ---
--- --- ---
ich hoffe es hilft