Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Malware gefunden/MWB gestartet (https://www.trojaner-board.de/140043-malware-gefunden-mwb-gestartet.html)

Reissdorfer 18.08.2013 14:13

Malware gefunden/MWB gestartet
 
Liebe User / Liebes Team,

ich hab zur Sicherheit Malwarebytes Anti-Malware laufen lassen ( Quick Scan und vorher update gestartet ) und es wurde etwas gefunden.
Nennt sich PUP.Optional.

Hier ist der Bericht:

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.08.18.01

Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16660
Slide :: R704ASUS [Administrator]

Schutz: Aktiviert

18.08.2013 14:57:49
mbam-log-2013-08-18 (14-57-49).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 237784
Laufzeit: 9 Minute(n), 40 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 1
C:\$Recycle.Bin\S-1-5-21-387495143-3782001425-2203670624-1003\$RGAPLRY.exe (PUP.Optional.BundledToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)


Muss ich jetzt noch etwas beachten oder ist mein PC wieder i.O: ?

Bin absoluter Neuling...

Lieben Gruß

schrauber 18.08.2013 14:17

hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


Reissdorfer 18.08.2013 15:56


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2013
Ran by Slide (administrator) on 18-08-2013 16:53:51
Running from C:\Users\Slide\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\System32\lpksetup.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\system32\dashost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Connectify) C:\Program Files (x86)\Connectify\ConnectifyD.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
() C:\Program Files\WindowsApps\6D698DE4.ICQ_1.0.0.85_x86__x31gp9y6nnhs2\icq.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Opera Software) C:\Program Files (x86)\Opera\15.0.1147.153\opera.exe
() C:\Program Files (x86)\Opera\15.0.1147.153\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\15.0.1147.153\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\15.0.1147.153\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\15.0.1147.153\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\15.0.1147.153\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\15.0.1147.153\opera.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-09-11] (ASUS)
HKLM\...\Run: [Connectify Hotspot] - C:\Program Files (x86)\Connectify\Connectify.exe [4815648 2013-08-06] (Connectify)
HKLM\...\Run: [Connectify Dispatch] - C:\Program Files (x86)\Connectify\DispatchUI.exe [3270432 2013-08-06] (Connectify)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2012-11-27] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe [3423104 2012-08-31] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-08-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [245872 2013-01-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [201576 2013-01-10] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)

FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [811064 2013-08-15] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [427520 2013-08-06] (Connectify)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-08-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130016 2013-08-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-08-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [83672 2013-08-15] (Avira Operations GmbH & Co. KG)
R1 cnnctfy3; C:\Windows\system32\DRIVERS\cnnctfy3.sys [34840 2013-08-17] (Connectify)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [13696 2012-10-04] (ASUSTek Computer Inc.)
R3 RTL8192Ce; C:\Windows\system32\DRIVERS\rtwlane.sys [1119232 2012-06-30] (Realtek Semiconductor Corporation                          )
U0 msahci;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-18 16:53 - 2013-08-18 16:53 - 00000000 ____D C:\FRST
2013-08-18 15:40 - 2013-08-18 15:40 - 00097107 _____ C:\Users\Slide\Downloads\player (7).swf
2013-08-18 15:40 - 2013-08-18 15:40 - 00097107 _____ C:\Users\Slide\Downloads\player (6).swf
2013-08-18 15:23 - 2013-08-18 15:24 - 00307760 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-18 14:53 - 2013-08-18 14:53 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Malwarebytes
2013-08-18 14:52 - 2013-08-18 14:52 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-18 14:52 - 2013-08-18 14:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-18 14:52 - 2013-08-18 14:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-18 14:52 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-18 14:50 - 2013-08-18 14:51 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Slide\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-17 17:15 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2013-08-17 17:15 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2013-08-17 17:15 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2013-08-17 17:15 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2013-08-17 17:15 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2013-08-17 17:15 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2013-08-17 17:15 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-17 17:15 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-08-17 17:15 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2013-08-17 17:15 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2013-08-17 17:15 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2013-08-17 17:15 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2013-08-17 17:15 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2013-08-17 17:15 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2013-08-17 17:15 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2013-08-17 17:15 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2013-08-17 17:15 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2013-08-17 17:15 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2013-08-17 17:15 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2013-08-17 17:15 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2013-08-17 17:15 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2013-08-17 17:15 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2013-08-17 17:15 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2013-08-17 17:15 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2013-08-17 17:15 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2013-08-17 17:15 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2013-08-17 17:15 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2013-08-17 17:15 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll
2013-08-17 17:15 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys
2013-08-17 17:15 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2013-08-17 17:15 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2013-08-17 17:15 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2013-08-17 17:15 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2013-08-17 17:15 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml
2013-08-17 01:36 - 2013-08-17 01:40 - 00000000 ____D C:\ProgramData\Connectify
2013-08-17 01:36 - 2013-08-17 01:36 - 00034840 _____ (Connectify) C:\Windows\system32\Drivers\cnnctfy3.sys
2013-08-17 01:36 - 2013-08-17 01:36 - 00000374 _____ C:\Users\Public\Desktop\Connectify Dispatch.lnk
2013-08-17 01:36 - 2013-08-17 01:36 - 00000358 _____ C:\Users\Public\Desktop\Connectify Hotspot.lnk
2013-08-17 01:36 - 2013-08-17 01:36 - 00000000 ____D C:\Program Files (x86)\Connectify
2013-08-17 01:34 - 2013-08-17 01:34 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-17 01:32 - 2013-08-17 01:33 - 07137400 _____ C:\Users\Slide\Downloads\Connectify6Installer.exe
2013-08-17 01:28 - 2013-08-17 01:28 - 00183296 _____ C:\Users\Slide\Downloads\de.wbb3mods.wbb.stats.tar
2013-08-17 00:32 - 2013-08-17 00:32 - 00097107 _____ C:\Users\Slide\Downloads\player (5).swf
2013-08-17 00:32 - 2013-08-17 00:32 - 00097107 _____ C:\Users\Slide\Downloads\player (4).swf
2013-08-16 23:17 - 2013-08-16 23:18 - 00000000 ____D C:\Users\Slide\Desktop\grafics
2013-08-16 22:09 - 2013-08-16 22:09 - 00097107 _____ C:\Users\Slide\Downloads\player (3).swf
2013-08-16 22:09 - 2013-08-16 22:09 - 00097107 _____ C:\Users\Slide\Downloads\player (2).swf
2013-08-16 20:17 - 2013-08-16 23:17 - 00000000 ____D C:\Users\Slide\Desktop\smile
2013-08-16 20:13 - 2013-08-16 20:13 - 00097107 _____ C:\Users\Slide\Downloads\player.swf
2013-08-16 20:13 - 2013-08-16 20:13 - 00097107 _____ C:\Users\Slide\Downloads\player (1).swf
2013-08-16 19:41 - 2013-08-16 19:41 - 00001892 _____ C:\Users\Slide\Desktop\IrfanView Thumbnails.lnk
2013-08-16 19:41 - 2013-08-16 19:41 - 00001004 _____ C:\Users\Slide\Desktop\IrfanView.lnk
2013-08-16 19:41 - 2013-08-16 19:41 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-08-16 19:41 - 2013-08-16 19:41 - 00000000 ____D C:\Users\Slide\AppData\Roaming\IrfanView
2013-08-16 19:41 - 2013-08-16 19:41 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-08-16 19:33 - 2013-08-16 23:19 - 00000000 ____D C:\Users\Slide\AppData\Roaming\FileZilla
2013-08-16 19:33 - 2013-08-16 19:33 - 00002002 _____ C:\Users\Slide\Desktop\FileZilla Client.lnk
2013-08-16 19:33 - 2013-08-16 19:33 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2013-08-16 19:33 - 2013-08-16 19:33 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-08-16 18:35 - 2013-08-16 23:17 - 00000000 ____D C:\Users\Slide\Desktop\plugins
2013-08-16 06:31 - 2013-08-16 06:32 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 05:12 - 2013-08-16 05:12 - 00000000 ____D C:\Users\Slide\AppData\Roaming\RIFT
2013-08-16 05:01 - 2013-08-16 05:01 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-08-15 22:53 - 2013-08-15 22:53 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-08-15 22:51 - 2013-08-16 05:03 - 00000000 ____D C:\Program Files (x86)\RIFT
2013-08-15 22:36 - 2013-07-02 02:44 - 00036288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2013-08-15 22:36 - 2013-07-02 00:08 - 00247216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2013-08-15 21:01 - 2013-08-15 21:06 - 00000033 _____ C:\Users\Slide\Desktop\Neues Textdokument (2).txt
2013-08-15 21:01 - 2013-07-26 07:13 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-08-15 21:01 - 2013-07-26 07:13 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-08-15 21:01 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-15 21:01 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-15 21:01 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-15 21:01 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-15 21:01 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-15 21:01 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-15 21:01 - 2013-07-26 05:13 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-08-15 21:01 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-15 21:01 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-15 21:01 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-15 21:01 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-15 21:01 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-15 21:01 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-15 21:01 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-15 21:01 - 2013-07-26 02:54 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-08-15 21:00 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-15 21:00 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-15 21:00 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-15 21:00 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-15 21:00 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-15 21:00 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-15 21:00 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-15 20:56 - 2013-07-09 08:07 - 02233168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 20:56 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-08-15 20:56 - 2013-05-24 01:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 20:56 - 2013-05-24 00:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-15 20:55 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-08-15 20:55 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-08-15 20:55 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-08-15 20:55 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-08-15 20:54 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 20:54 - 2013-07-13 08:16 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 20:54 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 20:54 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2013-08-15 20:54 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2013-08-15 20:54 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-15 20:54 - 2013-07-13 06:23 - 01568256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-15 20:54 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2013-08-15 20:54 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2013-08-15 20:54 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 20:54 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-15 19:58 - 2013-08-15 19:58 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Avira
2013-08-15 19:51 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Mozilla
2013-08-15 19:51 - 2013-08-15 19:51 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-08-15 19:51 - 2013-08-15 19:51 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-08-15 19:50 - 2013-08-15 19:50 - 00000000 ____D C:\ProgramData\APN
2013-08-15 19:49 - 2013-08-18 14:45 - 00003276 _____ C:\Windows\SysWOW64\bufferpool.txt
2013-08-15 19:49 - 2013-08-15 19:49 - 00002068 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-08-15 19:48 - 2013-08-15 19:48 - 00000000 ____D C:\ProgramData\Avira
2013-08-15 19:48 - 2013-08-15 19:48 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-15 19:48 - 2013-08-15 19:38 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-15 19:48 - 2013-08-15 19:38 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-15 19:48 - 2013-08-15 19:38 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-15 19:48 - 2013-08-15 19:38 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-15 19:34 - 2013-08-15 19:34 - 00013559 _____ C:\Users\Slide\Desktop\foruminfos.odt
2013-08-15 19:31 - 2013-08-15 19:31 - 00000000 ____D C:\Users\Slide\AppData\Roaming\OpenOffice
2013-08-15 19:02 - 2013-08-15 19:02 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-08-15 19:02 - 2013-08-15 19:02 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-15 18:57 - 2013-08-15 18:57 - 00000000 ____D C:\Users\Slide\Desktop\OpenOffice 4.0.0 (de) Installation Files
2013-08-15 18:50 - 2013-08-15 18:51 - 00029322 _____ C:\Users\Slide\Desktop\Neues Textdokument.txt
2013-08-15 18:40 - 2013-08-15 18:40 - 00001131 _____ C:\Users\Public\Desktop\Opera.lnk
2013-08-15 18:40 - 2013-08-15 18:40 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Opera Software
2013-08-15 18:40 - 2013-08-15 18:40 - 00000000 ____D C:\Users\Slide\AppData\Local\Opera Software
2013-08-15 18:40 - 2013-08-15 18:40 - 00000000 ____D C:\Program Files (x86)\Opera
2013-08-15 18:38 - 2013-08-15 18:38 - 00000000 ____D C:\Users\Slide\Desktop\Asus
2013-08-15 18:27 - 2013-08-15 18:27 - 00000355 _____ C:\Users\Slide\Desktop\Computer - Verknüpfung.lnk
2013-08-15 18:18 - 2013-08-15 18:18 - 00000367 _____ C:\Users\Slide\Desktop\Systemsteuerung - Verknüpfung.lnk
2013-07-25 14:51 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll
2013-07-20 19:37 - 2013-07-20 19:37 - 00000021 _____ C:\Users\Slide\AppData\Roaming\my_intel.sys
2013-07-20 19:37 - 2013-07-20 19:37 - 00000000 ____D C:\Users\Slide\Documents\ASUS
2013-07-20 19:37 - 2013-07-20 19:37 - 00000000 ____D C:\ProgramData\ASUS

==================== One Month Modified Files and Folders =======

2013-08-18 16:53 - 2013-08-18 16:53 - 01575580 _____ (Farbar) C:\Users\Slide\Downloads\FRST64.exe
2013-08-18 16:53 - 2013-08-18 16:53 - 00000000 ____D C:\FRST
2013-08-18 16:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-08-18 15:40 - 2013-08-18 15:40 - 00097107 _____ C:\Users\Slide\Downloads\player (7).swf
2013-08-18 15:40 - 2013-08-18 15:40 - 00097107 _____ C:\Users\Slide\Downloads\player (6).swf
2013-08-18 15:31 - 2013-06-14 18:56 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-387495143-3782001425-2203670624-1003
2013-08-18 15:28 - 2012-08-03 01:02 - 00753134 _____ C:\Windows\system32\perfh007.dat
2013-08-18 15:28 - 2012-08-03 01:02 - 00155826 _____ C:\Windows\system32\perfc007.dat
2013-08-18 15:28 - 2012-07-26 09:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-18 15:24 - 2013-08-18 15:23 - 00307760 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-18 15:24 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-18 15:23 - 2012-08-02 15:24 - 00008628 _____ C:\Windows\PFRO.log
2013-08-18 15:22 - 2012-07-26 07:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2013-08-18 15:21 - 2013-04-17 19:24 - 01315488 _____ C:\Windows\WindowsUpdate.log
2013-08-18 14:53 - 2013-08-18 14:53 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Malwarebytes
2013-08-18 14:52 - 2013-08-18 14:52 - 00001111 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-18 14:52 - 2013-08-18 14:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-18 14:52 - 2013-08-18 14:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-18 14:51 - 2013-08-18 14:50 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Slide\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-18 14:45 - 2013-08-15 19:49 - 00003276 _____ C:\Windows\SysWOW64\bufferpool.txt
2013-08-18 06:15 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-08-18 06:10 - 2013-06-14 18:49 - 00000000 ____D C:\Users\Slide\AppData\Local\Packages
2013-08-17 17:24 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe
2013-08-17 04:33 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-08-17 01:40 - 2013-08-17 01:36 - 00000000 ____D C:\ProgramData\Connectify
2013-08-17 01:38 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-17 01:37 - 2012-07-26 11:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-17 01:37 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-08-17 01:36 - 2013-08-17 01:36 - 00034840 _____ (Connectify) C:\Windows\system32\Drivers\cnnctfy3.sys
2013-08-17 01:36 - 2013-08-17 01:36 - 00000374 _____ C:\Users\Public\Desktop\Connectify Dispatch.lnk
2013-08-17 01:36 - 2013-08-17 01:36 - 00000358 _____ C:\Users\Public\Desktop\Connectify Hotspot.lnk
2013-08-17 01:36 - 2013-08-17 01:36 - 00000000 ____D C:\Program Files (x86)\Connectify
2013-08-17 01:34 - 2013-08-17 01:34 - 00000000 ____D C:\ProgramData\Package Cache
2013-08-17 01:33 - 2013-08-17 01:32 - 07137400 _____ C:\Users\Slide\Downloads\Connectify6Installer.exe
2013-08-17 01:28 - 2013-08-17 01:28 - 00183296 _____ C:\Users\Slide\Downloads\de.wbb3mods.wbb.stats.tar
2013-08-17 00:32 - 2013-08-17 00:32 - 00097107 _____ C:\Users\Slide\Downloads\player (5).swf
2013-08-17 00:32 - 2013-08-17 00:32 - 00097107 _____ C:\Users\Slide\Downloads\player (4).swf
2013-08-16 23:19 - 2013-08-16 19:33 - 00000000 ____D C:\Users\Slide\AppData\Roaming\FileZilla
2013-08-16 23:18 - 2013-08-16 23:17 - 00000000 ____D C:\Users\Slide\Desktop\grafics
2013-08-16 23:17 - 2013-08-16 20:17 - 00000000 ____D C:\Users\Slide\Desktop\smile
2013-08-16 23:17 - 2013-08-16 18:35 - 00000000 ____D C:\Users\Slide\Desktop\plugins
2013-08-16 22:09 - 2013-08-16 22:09 - 00097107 _____ C:\Users\Slide\Downloads\player (3).swf
2013-08-16 22:09 - 2013-08-16 22:09 - 00097107 _____ C:\Users\Slide\Downloads\player (2).swf
2013-08-16 20:13 - 2013-08-16 20:13 - 00097107 _____ C:\Users\Slide\Downloads\player.swf
2013-08-16 20:13 - 2013-08-16 20:13 - 00097107 _____ C:\Users\Slide\Downloads\player (1).swf
2013-08-16 19:41 - 2013-08-16 19:41 - 00001892 _____ C:\Users\Slide\Desktop\IrfanView Thumbnails.lnk
2013-08-16 19:41 - 2013-08-16 19:41 - 00001004 _____ C:\Users\Slide\Desktop\IrfanView.lnk
2013-08-16 19:41 - 2013-08-16 19:41 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-08-16 19:41 - 2013-08-16 19:41 - 00000000 ____D C:\Users\Slide\AppData\Roaming\IrfanView
2013-08-16 19:41 - 2013-08-16 19:41 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-08-16 19:33 - 2013-08-16 19:33 - 00002002 _____ C:\Users\Slide\Desktop\FileZilla Client.lnk
2013-08-16 19:33 - 2013-08-16 19:33 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2013-08-16 19:33 - 2013-08-16 19:33 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2013-08-16 06:32 - 2013-08-16 06:31 - 00000000 ____D C:\Windows\system32\MRT
2013-08-16 05:12 - 2013-08-16 05:12 - 00000000 ____D C:\Users\Slide\AppData\Roaming\RIFT
2013-08-16 05:03 - 2013-08-15 22:51 - 00000000 ____D C:\Program Files (x86)\RIFT
2013-08-16 05:01 - 2013-08-16 05:01 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-08-15 22:53 - 2013-08-15 22:53 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-08-15 21:06 - 2013-08-15 21:01 - 00000033 _____ C:\Users\Slide\Desktop\Neues Textdokument (2).txt
2013-08-15 19:58 - 2013-08-15 19:58 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Avira
2013-08-15 19:54 - 2013-06-14 18:51 - 00000401 _____ C:\Users\Slide\AppData\Roaming\sp_data.sys
2013-08-15 19:54 - 2012-11-27 06:11 - 00000000 ____D C:\ProgramData\McAfee
2013-08-15 19:51 - 2013-08-15 19:51 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Mozilla
2013-08-15 19:51 - 2013-08-15 19:51 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-08-15 19:51 - 2013-08-15 19:51 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
2013-08-15 19:50 - 2013-08-15 19:50 - 00000000 ____D C:\ProgramData\APN
2013-08-15 19:49 - 2013-08-15 19:49 - 00002068 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-08-15 19:48 - 2013-08-15 19:48 - 00000000 ____D C:\ProgramData\Avira
2013-08-15 19:48 - 2013-08-15 19:48 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-15 19:46 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\ELAMBKUP
2013-08-15 19:38 - 2013-08-15 19:48 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-15 19:38 - 2013-08-15 19:48 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-15 19:38 - 2013-08-15 19:48 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-15 19:38 - 2013-08-15 19:48 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-15 19:34 - 2013-08-15 19:34 - 00013559 _____ C:\Users\Slide\Desktop\foruminfos.odt
2013-08-15 19:31 - 2013-08-15 19:31 - 00000000 ____D C:\Users\Slide\AppData\Roaming\OpenOffice
2013-08-15 19:02 - 2013-08-15 19:02 - 00001116 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-08-15 19:02 - 2013-08-15 19:02 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-15 18:57 - 2013-08-15 18:57 - 00000000 ____D C:\Users\Slide\Desktop\OpenOffice 4.0.0 (de) Installation Files
2013-08-15 18:51 - 2013-08-15 18:50 - 00029322 _____ C:\Users\Slide\Desktop\Neues Textdokument.txt
2013-08-15 18:40 - 2013-08-15 18:40 - 00001131 _____ C:\Users\Public\Desktop\Opera.lnk
2013-08-15 18:40 - 2013-08-15 18:40 - 00000000 ____D C:\Users\Slide\AppData\Roaming\Opera Software
2013-08-15 18:40 - 2013-08-15 18:40 - 00000000 ____D C:\Users\Slide\AppData\Local\Opera Software
2013-08-15 18:40 - 2013-08-15 18:40 - 00000000 ____D C:\Program Files (x86)\Opera
2013-08-15 18:38 - 2013-08-15 18:38 - 00000000 ____D C:\Users\Slide\Desktop\Asus
2013-08-15 18:27 - 2013-08-15 18:27 - 00000355 _____ C:\Users\Slide\Desktop\Computer - Verknüpfung.lnk
2013-08-15 18:18 - 2013-08-15 18:18 - 00000367 _____ C:\Users\Slide\Desktop\Systemsteuerung - Verknüpfung.lnk
2013-08-15 16:07 - 2013-06-14 18:51 - 00000000 ___HD C:\Slidexcache
2013-08-13 09:58 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-08-07 14:10 - 2012-11-27 06:08 - 06236380 _____ C:\Windows\AsDebug.log
2013-08-07 14:10 - 2012-11-27 06:08 - 01120834 _____ C:\Windows\AsCDProc.log
2013-08-05 16:14 - 2013-07-02 13:18 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-26 07:13 - 2013-08-15 21:01 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-07-26 07:13 - 2013-08-15 21:01 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-07-26 07:13 - 2013-08-15 21:01 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-26 07:13 - 2013-08-15 21:00 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-26 07:13 - 2013-08-15 21:00 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-26 07:12 - 2013-08-15 21:01 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-26 07:12 - 2013-08-15 21:01 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-26 07:12 - 2013-08-15 21:00 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-26 05:35 - 2013-08-15 21:01 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-26 05:13 - 2013-08-15 21:01 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-26 05:13 - 2013-08-15 21:01 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-26 05:13 - 2013-08-15 21:01 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-07-26 05:12 - 2013-08-15 21:01 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-26 05:12 - 2013-08-15 21:01 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-26 05:12 - 2013-08-15 21:01 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-26 05:12 - 2013-08-15 21:01 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-26 05:12 - 2013-08-15 21:00 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-26 05:12 - 2013-08-15 21:00 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-26 05:12 - 2013-08-15 21:00 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-26 05:12 - 2013-08-15 21:00 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-26 05:11 - 2013-08-15 21:01 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-26 05:11 - 2013-08-15 21:01 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-26 04:49 - 2013-08-15 21:01 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-26 02:54 - 2013-08-15 21:01 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-07-25 20:00 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-07-20 19:37 - 2013-07-20 19:37 - 00000021 _____ C:\Users\Slide\AppData\Roaming\my_intel.sys
2013-07-20 19:37 - 2013-07-20 19:37 - 00000000 ____D C:\Users\Slide\Documents\ASUS
2013-07-20 19:37 - 2013-07-20 19:37 - 00000000 ____D C:\ProgramData\ASUS
2013-07-20 19:37 - 2013-06-14 18:49 - 00000000 ____D C:\Users\Slide\AppData\Local\VirtualStore
2013-07-20 19:37 - 2013-06-14 18:49 - 00000000 ____D C:\Users\Slide\AppData\Local\ASUS

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-16 06:22

==================== End Of Log ============================

--- --- ---


Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-08-2013
Ran by Slide at 2013-08-18 16:54:21
Running from C:\Users\Slide\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

 
Adobe Reader X MUI (x32 Version: 10.0.0)
Alcor Micro USB Card Reader (x32 Version: 3.4.117.01527)
ASUS Instant Connect (x32 Version: 1.2.8)
ASUS InstantOn (x32 Version: 3.0.5)
ASUS LifeFrame3 (x32 Version: 3.1.13)
ASUS Live Update (x32 Version: 3.1.9)
ASUS Power4Gear Hybrid (Version: 2.1.2)
ASUS Smart Gesture (x32 Version: 1.1.3)
ASUS Splendid Video Enhancement Technology (x32 Version: 1.03.0005)
ASUS Tutor (x32 Version: 1.0.8)
ASUS USB Charger Plus (x32 Version: 2.1.5)
ASUS WebStorage Sync Agent (x32 Version: 1.1.10.123)
ASUSDVD (x32 Version: 10.0.4126.52)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.7)
ATK Package (x32 Version: 1.0.0023)
Avira Free Antivirus (x32 Version: 13.0.0.3885)
Avira SearchFree Toolbar plus Web Protection (x32 Version: 12.2.2.663)
Connectify (Version: 6.0.0.28615)
D3DX10 (x32 Version: 15.4.2368.0902)
dows Driver Package - ASUS (ATP) Mouse  (01/10/2013 1.0.0.170) (Version: 01/10/2013 1.0.0.170)
FileZilla Client 3.7.3 (HKCU Version: 3.7.3)
Fotogalerie (x32 Version: 16.4.3505.0912)
Galerie de photos (x32 Version: 16.4.3505.0912)
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252)
Intel(R) Processor Graphics (x32 Version: 9.17.10.2884)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
IrfanView (remove only) (x32 Version: 4.36)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office (x32 Version: 15.0.4420.1017)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106)
Movie Maker (x32 Version: 16.4.3505.0912)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MyBitCast 2.0 (x32 Version: 2.0)
NVIDIA Control Panel 311.00 (Version: 311.00)
NVIDIA Graphics Driver 311.00 (Version: 311.00)
NVIDIA Install Application (Version: 2.1002.108.688)
NVIDIA Optimus 1.11.3 (Version: 1.11.3)
NVIDIA PhysX (x32 Version: 9.12.1031)
NVIDIA PhysX System Software 9.12.1031 (Version: 9.12.1031)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
OpenOffice 4.0.0 (x32 Version: 4.00.9702)
Opera Stable 15.0.1147.153 (x32 Version: 15.0.1147.153)
Photo Common (x32 Version: 16.4.3505.0912)
Photo Gallery (x32 Version: 16.4.3505.0912)
Raccolta foto (x32 Version: 16.4.3505.0912)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6804)
Shared C Run-time for x64 (Version: 10.0.0)
Windows Live (x32 Version: 16.4.3505.0912)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
WinFlash (x32 Version: 2.41.1)

==================== Restore Points  =========================

15-08-2013 16:57:56 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
16-08-2013 23:34:29 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106

==================== Hosts content: ==========================

2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation)
Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {1B44FB5B-24FB-43A0-8D88-5C3138ED0FF6} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance
Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh
Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks
Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update
Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator
Task: {37B4DE1B-9DF7-44D3-998E-34306C496700} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall
Task: {39112447-DF53-4E7A-BC5F-B415CCCB38F7} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2012-11-27] (Microsoft Corporation)
Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask
Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance
Task: {40D8385E-17FB-4CD5-86FD-45ACE039D38F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-08-22] (ASUSTeK Computer Inc.)
Task: {432EFCFC-7081-4DDB-9D5E-7EF65D98C154} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-10-04] (ASUS)
Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage
Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation)
Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
Task: {539903EA-88D0-4DE3-BCD1-62DC84C9B89B} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\Windows\system32\sc.exe [2012-07-26] (Microsoft Corporation)
Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance
Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required
Task: {5D99A322-9518-43A8-8C56-F17320F0B484} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-10-24] (ASUS)
Task: {5DB365B2-E0F7-4AF9-AA7B-7050BDF6F85F} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-387495143-3782001425-2203670624-1003
Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation)
Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-11-27] (Microsoft Corporation)
Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update
Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance
Task: {80E6C4A5-B2F1-4705-A82A-FD15A84B515C} - System32\Tasks\WPD\SqmUpload_S-1-5-21-387495143-3782001425-2203670624-1002 => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance
Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode)
Task: {8BF7092E-7746-4B49-8E6D-681B40A7A080} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-01-16] (AsusTek)
Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses
Task: {9231FC83-22C1-49C8-982A-C86311F052C4} - System32\Tasks\WPD\SqmUpload_S-1-5-21-387495143-3782001425-2203670624-1003 => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
Task: {A3FC2458-ED81-4FF6-B06B-F2B6915960F7} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask
Task: {A81B92A6-3DF4-43EC-950D-991BF01F9045} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup
Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh
Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask
Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask
Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan
Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific
Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender
Task: {C59DBEF7-7B1F-48F5-88DA-BFBDA9B41A7D} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe [2012-08-15] (Microsoft Corporation)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
Task: {D6C08640-69CB-4FCC-956B-5D4E7F690327} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect
Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-11-27] (Microsoft Corporation)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM
Task: {FA61C9C8-2AC4-479A-8DB5-4E0BA4523368} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {FA9F1441-BF50-4713-BA4A-40ABF691C104} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-387495143-3782001425-2203670624-1002

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/18/2013 06:02:14 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: R704Asus)
Description: Die App „0EB8BD08.MyCountry_erk4rrwmt7jyt!App“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.

Error: (08/17/2013 00:19:08 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005

Error: (08/16/2013 07:58:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: R704Asus)
Description: Bei der Aktivierung der App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ ist folgender Fehler aufgetreten: -2147009280. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.

Error: (08/16/2013 07:57:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: R704Asus)
Description: Die App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.

Error: (08/15/2013 08:56:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: R704Asus)
Description: Die App „6D698DE4.ICQ_x31gp9y6nnhs2!App“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.

Error: (08/15/2013 07:45:46 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: McSvHost.exe, Version: 2.6.259.0, Zeitstempel: 0x5040f1f9
Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2bcac
Ausnahmecode: 0x40000015
Fehleroffset: 0x00000000000761c9
ID des fehlerhaften Prozesses: 0x3c0
Startzeit der fehlerhaften Anwendung: 0xMcSvHost.exe0
Pfad der fehlerhaften Anwendung: McSvHost.exe1
Pfad des fehlerhaften Moduls: McSvHost.exe2
Berichtskennung: McSvHost.exe3
Vollständiger Name des fehlerhaften Pakets: McSvHost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: McSvHost.exe5

Error: (08/15/2013 06:30:34 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.2.9200.16433, Zeitstempel: 0x50763312
Name des fehlerhaften Moduls: igd10umd64.dll, Version: 9.17.10.2884, Zeitstempel: 0x509b2dac
Ausnahmecode: 0xc0000094
Fehleroffset: 0x00000000003b10bb
ID des fehlerhaften Prozesses: 0x860
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Vollständiger Name des fehlerhaften Pakets: Explorer.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Explorer.EXE5

Error: (08/15/2013 06:30:33 PM) (Source: .NET Runtime) (User: )
Description: Anwendung: Explorer.EXE
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: Ausnahmecode c0000094, Ausnahmeadresse 000007FC948510BB

Error: (08/15/2013 06:12:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: R704Asus)
Description: Die App „BrowserChoice_cw5n1h2txyewy!App“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.

Error: (08/09/2013 08:42:25 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: SlideX.exe, Version: 3.0.0.1, Zeitstempel: 0x4da19492
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x02550161
ID des fehlerhaften Prozesses: 0x6c0
Startzeit der fehlerhaften Anwendung: 0xSlideX.exe0
Pfad der fehlerhaften Anwendung: SlideX.exe1
Pfad des fehlerhaften Moduls: SlideX.exe2
Berichtskennung: SlideX.exe3
Vollständiger Name des fehlerhaften Pakets: SlideX.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: SlideX.exe5


System errors:
=============
Error: (08/18/2013 02:45:16 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%1

Error: (08/18/2013 02:44:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%1

Error: (08/18/2013 02:39:30 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%1

Error: (08/18/2013 02:38:59 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%1

Error: (08/18/2013 02:21:07 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet:
%%1

Error: (08/18/2013 02:21:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.

Error: (08/16/2013 07:58:10 PM) (Source: DCOM) (User: R704Asus)
Description: "BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.115616Windows.Networking.BackgroundTransfer.Internal.BackgroundTransferTask.ClassId.1Nicht verfügbarNicht verfügbar

Error: (08/16/2013 05:02:41 PM) (Source: Service Control Manager) (User: )
Description: Dienst "Avira Browser-Schutz" wurde unerwartet beendet. Dies ist bereits 3 Mal passiert.

Error: (08/16/2013 05:01:49 AM) (Source: DCOM) (User: R704Asus)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}R704AsusSlideS-1-5-21-387495143-3782001425-2203670624-1003LocalHost (unter Verwendung von LRPC)Microsoft.Adera_1.5.0.25573_x86__8wekyb3d8bbweS-1-15-2-2548604311-957346824-2694208565-872568250-605061286-105396575-2965357857

Error: (08/16/2013 05:01:49 AM) (Source: DCOM) (User: R704Asus)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}R704AsusSlideS-1-5-21-387495143-3782001425-2203670624-1003LocalHost (unter Verwendung von LRPC)Microsoft.Adera_1.5.0.25573_x86__8wekyb3d8bbweS-1-15-2-2548604311-957346824-2694208565-872568250-605061286-105396575-2965357857


Microsoft Office Sessions:
=========================
Error: (08/18/2013 06:02:14 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: R704Asus)
Description: 0EB8BD08.MyCountry_erk4rrwmt7jyt!App

Error: (08/17/2013 00:19:08 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005

Error: (08/16/2013 07:58:15 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: R704Asus)
Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos-2147009280

Error: (08/16/2013 07:57:53 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: R704Asus)
Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos

Error: (08/15/2013 08:56:02 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: R704Asus)
Description: 6D698DE4.ICQ_x31gp9y6nnhs2!App

Error: (08/15/2013 07:45:46 PM) (Source: Application Error)(User: )
Description: McSvHost.exe2.6.259.05040f1f9MSVCR100.dll10.0.40219.3254df2bcac4000001500000000000761c93c001ce998b5bcf1903C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exeC:\Windows\SYSTEM32\MSVCR100.dll83526b39-05d2-11e3-beb3-74d02b6faa2e

Error: (08/15/2013 06:30:34 PM) (Source: Application Error)(User: )
Description: Explorer.EXE6.2.9200.1643350763312igd10umd64.dll9.17.10.2884509b2dacc000009400000000003b10bb86001ce99d13f5b41c1C:\Windows\Explorer.EXEC:\Windows\System32\igd10umd64.dll01d78fea-05c8-11e3-beb3-74d02b6faa2e

Error: (08/15/2013 06:30:33 PM) (Source: .NET Runtime)(User: )
Description: Anwendung: Explorer.EXE
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: Ausnahmecode c0000094, Ausnahmeadresse 000007FC948510BB

Error: (08/15/2013 06:12:59 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: R704Asus)
Description: BrowserChoice_cw5n1h2txyewy!App

Error: (08/09/2013 08:42:25 PM) (Source: Application Error)(User: )
Description: SlideX.exe3.0.0.14da19492unknown0.0.0.000000000c0000005025501616c001ce94d4df7bd16fC:\Slidexcache\files\SlideX.exeunknown6ea8b06b-0123-11e3-beae-74d02b6faa2e


==================== Memory info ===========================

Percentage of memory in use: 36%
Total physical RAM: 3981.57 MB
Available physical RAM: 2540.3 MB
Total Pagefile: 4685.57 MB
Available Pagefile: 2979.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:143.75 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:258.15 GB) (Free:258.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: F7791DB4)

Partition: GPT Partition Type
==================== End Of Log ============================


schrauber 19.08.2013 07:10

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

Reissdorfer 19.08.2013 12:26

Code:

# AdwCleaner v2.306 - Datei am 19/08/2013 um 13:17:53 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 8  (64 bits)
# Benutzer : Slide - R704ASUS
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Slide\Downloads\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****

Gestoppt & Gelöscht : APNMCP

***** [Dateien / Ordner] *****

Datei Gelöscht : C:\Users\Slide\AppData\Local\Temp\Uninstall.exe
Ordner Gelöscht : C:\Program Files (x86)\AskPartnerNetwork
Ordner Gelöscht : C:\ProgramData\APN
Ordner Gelöscht : C:\ProgramData\AskPartnerNetwork
Ordner Gelöscht : C:\Users\Slide\AppData\Local\Temp\APN

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AskPartnerNetwork
Schlüssel Gelöscht : HKLM\Software\AskPartnerNetwork

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16660

[OK] Die Registrierungsdatenbank ist sauber.

*************************

AdwCleaner[R1].txt - [1148 octets] - [19/08/2013 13:14:09]
AdwCleaner[R2].txt - [1129 octets] - [19/08/2013 13:17:45]
AdwCleaner[S1].txt - [1073 octets] - [19/08/2013 13:17:53]

########## EOF - C:\AdwCleaner[S1].txt - [1133 octets] ##########

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.0 (08.18.2013:1)
OS: Windows 8 x64
Ran by Slide on 19.08.2013 at 13:23:49,93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.08.2013 at 13:26:26,73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


schrauber 19.08.2013 16:45


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme? :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 12:46 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19