Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Nation Zoom nicht entfernbar? (https://www.trojaner-board.de/145457-nation-zoom-entfernbar.html)

Sigrowon 01.12.2013 23:11

Nation Zoom nicht entfernbar?
 
Guten Abend,

ich bin am verzweifeln,(kurze Info) ich bin leider nicht die, die sich gut mit Computern auskennt.
Ich habe wie scheinbar auch andere, feststellen müssen, das wenn ich meinen Browser öffne, immer als Startseite nationzoom.com angezeigt wird.
hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
Nach erfolgreicher Internetrecherche fand ich raus welch Nachteile Nation Zoom hat und welche Probleme es hervorrufen kann.
Mit Hilfe dieses Beitrags:

http://www.trojaner-board.de/145355-...entfernen.html

habe ich versucht Nation Zoom zu entfernen und bin alle Schritte durchgegangen die "schrauber" gepostet hatte, doch es klappt nicht.
Gerne würde ich euch die Ergebnisse posten, doch leider habe ich sehr wenig PC Kenntnisse und müsste daher von jemand gesagt bekommen, wo ich die Ergebnisse finde und posten kann.

Lg

Chiara:bussi:

cosinus 02.12.2013 00:52

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

Sigrowon 02.12.2013 15:49

Als aller erstes hatte ich gestern Malwarebytes Anti-Malware laufen lassen und alle infizierten Funde gelöscht. Hier der Log dazu:

Code:

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.12.01.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
PC :: ---- [Administrator]

Schutz: Aktiviert

01.12.2013 17:02:20
mbam-log-2013-12-01 (17-02-20).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 509795
Laufzeit: 1 Stunde(n), 46 Minute(n), 26 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 18
HKCR\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\YontooIEClient.Layers.1 (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\YontooIEClient.Layers (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\nationzoomSoftware (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo (PUP.Optional.Elex.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} (PUP.Optional.Qone8) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 2
HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {0BEF0CB3-FDC5-11E2-B890-002618D6A2BF} -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: {0BEF0CB3-FDC5-11E2-B890-002618D6A2BF} -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 6
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (PUP.Optional.NationZoom.A) -> Bösartig: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (iexplore.exe) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes|DefaultScope (PUP.Optional.Qone8) -> Bösartig: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}) Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}) -> Erfolgreich ersetzt und in Quarantäne gestellt.
HKLM\Software\Microsoft\Internet Explorer\Main|Default_Page_URL (PUP.Optional.NationZoom.A) -> Bösartig: (hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt.

Infizierte Verzeichnisse: 1
C:\Users\PC\Documents\Optimizer Pro (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateien: 10
C:\Program Files (x86)\Yontoo Layers\YontooIEClient.dll (Adware.Yontoo) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\mgsqlite3.7z (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\fullpackage_temp1385907047\Baofeng.exe (PUP.Optional.NationZoom.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\fullpackage_temp1385907047\tmp\eGdpSvc.exe (PUP.Optional.Wsys.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\installer.exe (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\parent.txt (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\software\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\AppData\Local\Temp\Temporary files\software\tugs_nationzoom.exe (PUP.Optional.SkyTech.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\PC\Documents\Optimizer Pro\CookiesException.txt (PUP.Optional.OptimizerPro.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)

--- --- --- --- --- --- --- ---- --- ---- --- ---- ---

Anschließend startete ich AdwCleaner und erhielt diese 2 Logs (AdwCleaner[RO]:

Code:

# AdwCleaner v3.014 - Bericht erstellt am 01/12/2013 um 21:13:19
# Updated 01/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : PC - ----
# Gestartet von : C:\Users\PC\Desktop\adwcleaner.exe
# Option : Suchen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Datei Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx
Datei Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Datei Gefunden : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Ordner Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
Ordner Gefunden : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Ordner Gefunden C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gefunden C:\Program Files (x86)\DAEMON Tools Toolbar
Ordner Gefunden C:\Program Files (x86)\iMesh Applications
Ordner Gefunden C:\Program Files (x86)\MyPC Backup
Ordner Gefunden C:\Program Files (x86)\Yontoo Layers
Ordner Gefunden C:\ProgramData\Ask
Ordner Gefunden C:\ProgramData\eSafe
Ordner Gefunden C:\ProgramData\Tarma Installer
Ordner Gefunden C:\Users\PC\AppData\Local\cool_mirage
Ordner Gefunden C:\Users\PC\AppData\Local\Mail.Ru
Ordner Gefunden C:\Users\PC\AppData\LocalLow\iac
Ordner Gefunden C:\Users\PC\AppData\Roaming\dvdvideosoftiehelpers

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKCU\Software\Softonic
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gefunden : [x64] HKCU\Software\Softonic
Schlüssel Gefunden : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\FTDownloader
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\lgnbhdnimikkoodkogjlcllngimhlapp
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gefunden : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Tarma Installer
Wert Gefunden : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.57

[ Datei : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [6713 octets] - [01/12/2013 21:13:19]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [6773 octets] ##########



und diesen hier AdwCleaner[SO]:
Code:

# AdwCleaner v3.014 - Bericht erstellt am 01/12/2013 um 21:14:08
# Updated 01/12/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : PC - ----
# Gestartet von : C:\Users\PC\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\Ask
Ordner Gelöscht : C:\ProgramData\eSafe
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\DAEMON Tools Toolbar
Ordner Gelöscht : C:\Program Files (x86)\iMesh Applications
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\Yontoo Layers
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\PC\AppData\Local\cool_mirage
Ordner Gelöscht : C:\Users\PC\AppData\Local\Mail.Ru
Ordner Gelöscht : C:\Users\PC\AppData\LocalLow\iac
Ordner Gelöscht : C:\Users\PC\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml
Ordner Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo
Datei Gelöscht : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Datei Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Datei Gelöscht : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\lgnbhdnimikkoodkogjlcllngimhlapp
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\FTDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@VideoDownloadConverter_ScriptHelper.com/Plugin
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_internet-explorer-9[1]_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D6F0AC3-0C2E-4E07-8FDA-11268AB51211}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{17B10E59-09E1-4C39-A738-6774D7AB7778}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD2049E-E483-4425-8555-8E0775ACB631}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D73F2D0-2FAB-458E-977D-2F9050E0ED60}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9083CE-8758-4704-BA57-3C891D7452BD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3E9469AF-E866-4476-B767-810630F1F6E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47700C35-9E3E-4DAD-934C-0CE28A87237C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{716E443D-7CAA-44F1-866B-F45D00E712CC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72063D77-7590-4DA9-A7F8-F5ECAF3632C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7FC87AC5-FA93-476E-A32C-A941229DED0B}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Tarma Installer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v

-\\ Google Chrome v31.0.1650.57

[ Datei : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [6929 octets] - [01/12/2013 21:13:19]
AdwCleaner[S0].txt - [6633 octets] - [01/12/2013 21:14:08]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6693 octets] ##########

--- --- --- --- --- --- --- --- --- -- -- --- --- ---- -- --- ---

Nun als 3. began ich den Scan mit Junkware Removal Tool und erhielt diesen Log:

Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by PC on 01.12.2013 at 21:28:08,57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\dt soft\daemon tools toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-11D0_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D3998AED-51D6-46E1-9C87-042CA1ED8F95}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{04953E20-4820-445F-84ED-D91A1500D620}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{050B921F-6B59-4988-88F8-4CE19EFB7286}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{05A7CC7D-5873-4C57-B5E3-228EBFC44C66}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{0A4654BF-5C29-4A45-829E-BD5FF6611034}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{0B1F7094-EE18-458F-9FE9-E43C043A68FB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{0CADB3C3-4EC9-4584-BB39-F3BA4B49990D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{11B7B8FC-E114-4D8E-962D-A88891CD4A75}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{138FE3B8-6DC2-4CF7-90FB-9C9BABFE2B18}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{13F2885D-142F-475F-88F9-FAC37B62FC52}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{17783E3C-1114-4162-9663-A5D9A36170A7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{1C49A864-3D29-4C53-BBDF-32CD694A2399}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{1EC59320-0C98-4D12-A3DF-FD1E082179A9}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2491CDE2-86A0-4639-AC84-66E0F747C6E1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{265D547E-7718-4791-B278-CEA603765AD7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2737684E-2CBA-4AFF-8CC1-EB7061AA069F}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{27DBBE79-BA63-4B0B-BDF5-02FA3415B759}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{298EBE99-45FF-4713-9E44-60CFB93DB894}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2C42268D-5AD0-471A-A79A-7F2618E37D4B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2E60CDFF-E4AA-4CAB-B21B-CB92D066F978}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2EBE1BD2-F438-47F6-B755-BF059E256EBF}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2FBE6959-68BF-42DF-8D3C-71F912FB061B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{2FE4E312-0355-4D2F-97A4-0C4BAEA820F7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3143108B-FE67-4A20-96F7-97D323B65DA2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{330A3231-195F-4719-9616-D7FD5DAA03C1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3487BD39-A6B8-448E-BA3E-BD3522B33331}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{361F230D-2A0D-4EFA-84E2-F2EB634E05E4}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{36D6C777-EF9D-4A63-AE35-A4F1DD3C1B3B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3922E2EC-C23B-4160-A060-169FDEB106D8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{39389053-8FEB-4B78-B409-E6D17375598B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3A443088-0761-42B3-BAA6-E2E95004DFCA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3C3D17DF-54C7-4636-9DBF-2AA63C85E615}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3D037E2E-3B5F-441B-958E-2EB8D7D8D8BA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{3D3661AB-10BC-4FE0-AF67-479F216A9679}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4055D348-A94F-4C72-8F6C-06BAFCE26393}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{438B8403-E4DA-41FC-BCD1-5CDE95E905FC}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4AC85563-CF31-4907-B074-E7A9D5E0EB59}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4B8F0C97-2989-47AD-B74F-4EDAE51EB3BB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4D34FCC4-2BEE-41FE-A471-029B599F5407}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4D497D84-12C0-4F77-BE80-77DC7FC32121}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{4D650055-5D7E-44AE-84BD-4BA67D6CAB65}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5261A561-3D7F-4BBD-A6AF-099011462D7E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{52FEB6BD-FCB3-4392-968E-6E8BCB0B0BC1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{54BE864B-A4A0-446B-9F26-B4E3EBF22B74}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{56D8E757-5B57-4E19-B55D-6DB81D045121}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5806E4FC-7824-4269-835C-C50F60BC4B9C}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{59EEB5ED-5EBC-47A3-9442-3D4C138FB373}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5A0AE002-6E00-4E56-9346-0AE0898FB766}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5A3031F0-0CF7-444F-BDDF-BD8A3BF77738}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5AAAC3C6-08DA-4FCC-8484-ECED54C1994B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5C491509-5756-4793-8844-0E92D4228ED4}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{5C6A030D-E693-40FE-892B-CE3917342FDD}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{604CEBC6-FCB1-4D34-8F4E-9042A99A49D6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{61211C89-13C3-440A-8931-6F65CBCA99DF}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{614D6FC4-29B8-49DF-8F6B-EE7743338E86}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{61A31803-A659-4560-B87E-0358A0D9F461}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{684D023F-8285-4572-9543-C7D2C19E0BCB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6906BA98-C1AE-4B1F-9B46-DAA9339EFBF3}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6AC0986C-C779-4F9D-A304-C34CFA22988D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6DA56D56-2BD2-43EB-A518-DA5BA0C784E6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{6FB6FDF7-B797-4DE0-A61A-52F873AD368D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{70698485-0CD8-432F-8F3B-CCE785048582}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{7119EBD4-8C47-46B4-8D2D-992103830F32}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{728872D4-A9E8-4D3E-A9D8-41BA95F0C144}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{77209029-1A41-459E-B12C-F4B1837A6CD7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{7770EB46-E78C-441C-B75C-A089937019E7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{7F03D821-2C49-46E7-8950-34BF00BEBFE9}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8060126E-928A-456C-BF0F-F7ED4A1E40D8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{845D3436-68A4-41DF-B883-6166E318D86E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8558F393-5E67-4830-86DA-4BCB44077301}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{873961C3-CCC6-4303-AEA6-C57D647D3BE7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8883CEDD-DEAF-4842-82A5-CCFAC6093A9A}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8A8FEDA9-1ADD-4D97-8A40-6A16D9D35687}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8E17E7A6-420E-4674-8180-C056CF48A19B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8E747BEA-888F-4800-9C4D-DAB1C487EB47}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{8FFADD15-274F-43B2-8655-132B5F38EBE2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{916719F1-EB08-40C0-A774-EE2FE9A919F7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{944EB0A1-F795-4E80-BE77-CF72C9E2ABAB}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{95E39759-0163-42E2-9862-A3C5950C66DF}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{96E52183-2929-46A7-AEBC-E7F87223BE4C}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{97EE4707-160F-4B5B-A8DA-8DBA3F4192BD}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9CF4AA93-77FA-4155-8D67-CAAE9117ADC5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9DD2251A-68E4-4C00-80FE-B40B4A43ED4D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9E02FD86-67E8-4413-ACDD-10CC7FD58D9D}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{9E3CFE55-A021-4081-8F83-A1B2D320AE37}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A0218593-7E03-4839-B9D4-2671B0DF2CC6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A0F1DF6F-7473-460B-8860-897908639844}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A7748B2F-1CB4-49A5-A7CB-7E203E30E077}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A94297AE-94B9-4B80-BE1C-83FC96070C92}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{A9B26D94-2AAE-4433-BC96-36A429E0E9B8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{ADE83510-A846-4326-9B25-F56CA935CFA3}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{AE205D29-086D-4E27-B369-1E7FB08A326E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{B37CDE30-7230-4870-A9B4-0535148B86A2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{B962A9B9-A3C6-4652-90C8-87044E33B9D5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{BB8B3563-E0D3-4D1F-92A5-6E55382C98D3}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{BC568405-17D4-460A-B88F-E1D3746B37A4}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{BCF60FD0-FDB5-47B5-AD29-B778545D9BE7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C0AC7D20-4865-4D70-A41C-DF4BD16A1EA6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C311D297-36DF-48A1-A107-290DC5180C47}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C3B816CC-3F2B-493B-ADDA-1A38E8BAE45F}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{C4AC966A-C0D5-4F09-96F1-757E36E69E69}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{CB120509-264A-42B4-8927-A8EF4A6FE809}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{CB360A3C-FF3A-4118-8D01-A477662E2324}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{CBC096C3-5B09-4A68-B6B8-5777683A05AA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D05E4A6E-60B6-4BA8-894B-9C7515104774}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D0D113DF-1415-4040-BF35-5FEE82672E5B}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D43C719C-7508-4491-AB72-489A2AB79839}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D569C51D-8099-4CBE-91DD-B8460DB4691E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D6AD0781-DCFA-4F18-A52D-05B4CCAF79A1}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D8693CD1-3C66-4F81-908D-C91DC47B39C2}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D8E124EE-7687-4300-B53A-C7F697E01150}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{D980688C-CD5F-43D0-9221-BB3309704DDA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{DA4C17B4-5821-42D9-8548-5B1F8702EFC5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{DB8A75DD-120F-4DB9-B25D-9D801CC38BCD}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E21FFDE9-54B2-435F-8367-7F92DFF19903}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E318E4BA-02CD-454D-A68A-AA88F6BD7462}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E33A6783-688D-4DE8-B042-6BA674A40AC7}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{E4B86607-9671-4F5A-B3A2-8004F92B59FA}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EA084B54-7280-49C5-B259-1829B997FFEE}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EA4E351B-EE45-48F7-B4DB-A9DF101B2130}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EC38AA63-CF99-4B8C-8869-B03960E2F968}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{EFFF8069-B70E-457E-9E8C-6DF02B23C8F5}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F3AAEBA0-60EA-4475-B81E-ACFDDC237DD8}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F40C664A-09CC-41C3-967E-ACE3C290441E}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F40CF757-7D9B-4824-8078-F43EEA17E260}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F475DE67-AC25-4C42-8101-95AF25178B0F}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F72FC534-9CDC-4104-8DC1-D2A4313EBF38}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{F861EEDA-A303-4F94-B838-871A0828CAD6}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FAF2C561-BCC2-4DB1-8822-D471174FC623}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FBE820AF-8682-469B-A5CB-6FC814A7B006}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FC61FECA-4A46-4755-A34A-DD0C9D931577}
Successfully deleted: [Empty Folder] C:\Users\PC\appdata\local\{FF7229E2-2EF8-4AC6-A627-6102AB285977}



~~~ Chrome

Successfully deleted: [Folder] C:\Users\PC\appdata\local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 01.12.2013 at 21:34:54,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


--- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- ---

Da ich vor dem Malewarebytes Anti-Maleware Vorgang noch nicht diese seite hier entdeckt habe, habe ich leider vor all dem hier kein FRST benutzt.
Ich stieß während meinem Malewarebytes Anti-Malware Scan auf Trojaner-Board und habe daher erst nach all dem hier das FRST gestartet.
Hier sind die Letzten Logs vorerst:

FRST:


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2013
Ran by PC (administrator) on ---- on 01-12-2013 22:12:00
Running from C:\Users\PC\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TeamSpeak Systems GmbH) C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7574048 2009-03-30] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-20] (Microsoft Corporation)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-10-30] ()
MountPoints2: {2a8763ce-c1a6-11df-9d01-002618d6a2bf} - F:\Autorun.exe
MountPoints2: {4d126ea1-d5e6-11df-b593-002618d6a2bf} - G:\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2349392 2013-11-11] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs:  [ ] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x328D93A362C9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {434D452D-5637-006A-76A7-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: No Name - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: ftd - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Unity Player) - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Assassin's Creed IV Black Flag) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\agibflpbghgmiinfaefgnldmfajdance\1.2_0
CHR Extension: (Google Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2011-12-25] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2010-05-25] (Devguru Co., Ltd)
R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [18816 2008-01-17] (Razer USA Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2008-01-21] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-09-16] ()
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [129024 2010-04-27] (MCCI Corporation)
U3 avy50mb9; C:\Windows\System32\Drivers\avy50mb9.sys [0 ] (Microsoft Corporation)
S3 X6va003; \??\C:\Users\PC\AppData\Local\Temp\003977D.tmp [x]
S3 X6va005; \??\C:\Users\PC\AppData\Local\Temp\005422E.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-01 22:12 - 2013-12-01 22:12 - 00013785 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 22:10 - 2013-12-01 22:10 - 01959184 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:12 - 2013-12-01 21:16 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:57 - 2013-12-01 16:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:57 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 16:51 - 2013-12-01 16:55 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:01 - 2013-11-26 03:09 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-14 02:40 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 02:40 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 02:40 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 02:40 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 02:40 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 02:40 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 02:40 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 02:40 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 02:40 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 02:40 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 02:40 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 02:40 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-14 02:39 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 02:39 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 02:39 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment

==================== One Month Modified Files and Folders =======

2013-12-01 22:12 - 2013-12-01 22:12 - 00013785 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 22:10 - 2013-12-01 22:10 - 01959184 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-01 21:52 - 2011-01-29 12:21 - 00000000 ____D C:\Users\PC\AppData\Local\PMB Files
2013-12-01 21:45 - 2013-04-13 17:11 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-01 21:37 - 2013-04-04 20:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:28 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-01 21:28 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:25 - 2010-01-14 17:55 - 01509709 _____ C:\Windows\WindowsUpdate.log
2013-12-01 21:24 - 2012-09-01 12:35 - 00000000 ____D C:\Users\PC\AppData\Roaming\TS3Client
2013-12-01 21:24 - 2009-07-14 05:51 - 00233743 _____ C:\Windows\setupact.log
2013-12-01 21:22 - 2012-12-18 23:41 - 00000000 ____D C:\Users\PC\AppData\Local\LogMeIn Hamachi
2013-12-01 21:21 - 2013-04-13 17:11 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-01 21:20 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-01 21:16 - 2013-12-01 21:12 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 21:09 - 2011-01-29 12:21 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-01 20:42 - 2011-10-17 17:42 - 00188760 _____ C:\Windows\PFRO.log
2013-12-01 19:18 - 2012-12-29 19:56 - 01251840 ___SH C:\Users\PC\Desktop\Thumbs.db
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:58 - 2013-12-01 16:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:55 - 2013-12-01 16:51 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-01 15:43 - 2013-10-15 20:59 - 00000000 ____D C:\ProgramData\Oracle
2013-12-01 15:39 - 2010-01-14 17:56 - 00000000 ___RD C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-01 15:11 - 2010-01-14 17:56 - 00001641 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 01:17 - 2011-04-08 19:42 - 00000000 ____D C:\Users\PC\Desktop\Fotos
2013-12-01 01:17 - 2010-12-04 17:22 - 00000000 ____D C:\Users\PC\Desktop\bilder
2013-12-01 01:13 - 2010-11-30 19:39 - 00000000 ____D C:\Users\PC\Desktop\Lehre
2013-11-30 14:08 - 2013-01-23 23:17 - 00000000 ____D C:\Users\PC\Desktop\Mouseclick, Schneiden - Umwandeln
2013-11-30 14:07 - 2012-10-06 02:02 - 00000000 ____D C:\Users\PC\Desktop\TS
2013-11-30 14:05 - 2009-07-14 18:58 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-11-30 14:05 - 2009-07-14 18:58 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-11-30 14:05 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-26 03:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-26 03:09 - 2013-11-26 03:01 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-25 16:40 - 2010-06-05 12:07 - 00001534 _____ C:\Users\PC\Desktop\Passwörter.txt
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-22 23:36 - 2012-08-12 11:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\Skype
2013-11-22 14:01 - 2012-10-19 14:00 - 00000000 ____D C:\Users\PC\AppData\Roaming\.minecraft
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-19 13:35 - 2013-08-07 10:58 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-17 21:44 - 2010-03-22 03:29 - 00000000 ____D C:\Users\PC\Desktop\Wallpaper
2013-11-16 22:57 - 2013-02-25 00:42 - 00000000 ____D C:\Users\PC\Desktop\TS 3 Icons
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files\Google
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-15 14:55 - 2012-08-17 16:56 - 00000000 ____D C:\Users\PC\AppData\Local\Google
2013-11-15 14:54 - 2013-04-04 20:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 14:54 - 2013-04-04 20:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 14:54 - 2013-04-04 20:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-15 14:54 - 2010-03-22 03:53 - 00000000 ____D C:\Users\PC\AppData\Local\Adobe
2013-11-15 03:13 - 2010-03-22 03:57 - 00000000 ____D C:\Users\PC\Desktop\Musik
2013-11-15 00:14 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-14 02:46 - 2013-07-14 01:17 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 02:45 - 2010-03-22 03:11 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-12 12:48 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-11 05:50 - 2010-03-22 02:59 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment
2013-11-07 22:06 - 2012-08-10 14:59 - 00000000 ____D C:\Users\PC\AppData\Local\Apps\2.0
2013-11-06 21:02 - 2012-12-12 01:41 - 00000000 ___RD C:\Users\PC\Desktop\Movie Maker
2013-11-04 15:32 - 2012-10-08 19:41 - 00000000 ____D C:\Users\PC\Desktop\Text-Dokumente

Some content of TEMP:
====================
C:\Users\PC\AppData\Local\Temp\7za.exe
C:\Users\PC\AppData\Local\Temp\APNStub.exe
C:\Users\PC\AppData\Local\Temp\AskSLib.dll
C:\Users\PC\AppData\Local\Temp\avgnt.exe
C:\Users\PC\AppData\Local\Temp\BackupSetup.exe
C:\Users\PC\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\PC\AppData\Local\Temp\drm_dialogs.dll
C:\Users\PC\AppData\Local\Temp\drm_dyndata_7370007.dll
C:\Users\PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\PC\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\PC\AppData\Local\Temp\InstallAX.exe
C:\Users\PC\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\Quarantine.exe
C:\Users\PC\AppData\Local\Temp\SkypeSetup.exe
C:\Users\PC\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\PC\AppData\Local\Temp\vcredist_x64.exe
C:\Users\PC\AppData\Local\Temp\war3_Install.exe
C:\Users\PC\AppData\Local\Temp\_isAB9A.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-11 16:55

==================== End Of Log ============================

--- --- ---

--- --- ---


--- --- --- --- --- --- --- --- --- --- ---- --- --- --- --- --- --- --- ---

Und hier der Addition Log:

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-12-2013
Ran by PC at 2013-12-01 22:13:22
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.152)
Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8)
AION Free-to-Play Version 1.0 (x32 Version: 1.0)
AMD Catalyst Install Manager (Version: 8.0.903.0)
Assassin's Creed Brotherhood (x32 Version: 1.03)
ATI AVIVO64 Codecs (Version: 10.10.0.40918)
ATI Problem Report Wizard (Version: 3.0.745.0)
Avira Free Antivirus (x32 Version: 14.0.1.749)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Core Implementation (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Full New (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Light (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center HydraVision Full (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485)
Catalyst Control Center Localization All (x32 Version: 2009.0918.2132.36825)
CCC Help Chinese Standard (x32 Version: 2009.0918.2131.36825)
CCC Help Chinese Traditional (x32 Version: 2009.0918.2131.36825)
CCC Help Czech (x32 Version: 2009.0918.2131.36825)
CCC Help Danish (x32 Version: 2009.0918.2131.36825)
CCC Help Dutch (x32 Version: 2009.0918.2131.36825)
CCC Help English (x32 Version: 2009.0918.2131.36825)
CCC Help Finnish (x32 Version: 2009.0918.2131.36825)
CCC Help French (x32 Version: 2009.0918.2131.36825)
CCC Help German (x32 Version: 2009.0918.2131.36825)
CCC Help Greek (x32 Version: 2009.0918.2131.36825)
CCC Help Hungarian (x32 Version: 2009.0918.2131.36825)
CCC Help Italian (x32 Version: 2009.0918.2131.36825)
CCC Help Japanese (x32 Version: 2009.0918.2131.36825)
CCC Help Korean (x32 Version: 2009.0918.2131.36825)
CCC Help Norwegian (x32 Version: 2009.0918.2131.36825)
CCC Help Polish (x32 Version: 2009.0918.2131.36825)
CCC Help Portuguese (x32 Version: 2009.0918.2131.36825)
CCC Help Russian (x32 Version: 2009.0918.2131.36825)
CCC Help Spanish (x32 Version: 2009.0918.2131.36825)
CCC Help Swedish (x32 Version: 2009.0918.2131.36825)
CCC Help Thai (x32 Version: 2009.0918.2131.36825)
CCC Help Turkish (x32 Version: 2009.0918.2131.36825)
ccc-core-static (x32 Version: 2009.0918.2132.36825)
ccc-utility64 (Version: 2009.0918.2132.36825)
D3DX10 (x32 Version: 15.4.2368.0902)
Drachenkrieg (with media and plugins), version 1.1.27 (x32)
FlatOut2 (x32 Version: 1.00.0000)
Free YouTube Download version 3.1.39.1015 (x32 Version: 3.1.39.1015)
Free YouTube to MP3 Converter version 3.11.34.1015 (x32 Version: 3.11.34.1015)
Gameforge Live 1.9.0 "Legend" (x32 Version: 1.9.0)
Google Chrome (x32 Version: 31.0.1650.57)
Google Update Helper (x32 Version: 1.3.21.165)
GRID (x32 Version: 1.00.0000)
HydraVision (x32 Version: 4.2.114.0)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
League of Legends (x32 Version: 1.3)
Legend - Legacy Of The Dragons (Chrome)(Chrome), version 3.0.12 (x32)
LogMeIn Hamachi (x32 Version: 2.2.0.105)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
Need For Speed™ World (x32 Version: 1.0.0.131)
NVIDIA PhysX (x32 Version: 9.09.0203)
OpenAL (x32)
OpenOffice.org 3.0 (x32 Version: 3.0.9358)
Overwolf (x32 Version: 0.44.256)
Pando Media Booster (x32 Version: 2.6.0.8)
PDF24 Creator 5.2.0 (x32)
PlanetSide 2 (HKCU Version: 1.0.3.183)
PunkBuster Services (x32 Version: 0.990)
Rapture3D 2.4.4 Game (x32)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5821)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.2300.0)
Skype™ 6.9 (x32 Version: 6.9.106)
TeamSpeak 3 Client (x32 Version: 3.0.13.1)
Ubisoft Game Launcher (x32 Version: 1.0.0.0)
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Warcraft III (x32)
Warcraft III: All Products (HKCU)
WAV To MP3 V2 (x32)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR archiver

==================== Restore Points  =========================

12-11-2013 11:54:07 Windows Update
14-11-2013 01:43:59 Windows Update
19-11-2013 11:48:36 Windows Update
22-11-2013 11:51:44 Windows Update
26-11-2013 02:00:18 Windows Update
29-11-2013 15:58:46 Windows Update
01-12-2013 14:38:11 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
01-12-2013 14:40:00 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
01-12-2013 14:41:41 Removed Java 7 Update 45
01-12-2013 14:42:56 Installed Java 7 Update 45

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {06B433D2-FB99-42C0-BFF0-C61715C3089D} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => Rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
Task: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
Task: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
Task: {2A6ED1F6-5671-4112-9207-09A80106B246} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => Rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
Task: {A5269147-4A7F-4748-A8B4-ACCAC317D04F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-13] (Google Inc.)
Task: {A7C73732-9F11-4281-8D19-764D4EC9D94D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe aepdu.dll,AePduRunUpdate
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: {AD3248AA-E511-4EEE-BD9D-4F102787AD6B} - System32\Tasks\{FABC27FC-E434-42E9-9434-9A87C4604791} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?source=lightinstaller&page=tsMain
Task: {C1362E88-A3A2-443D-8F27-C95A4D73AC60} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-13] (Google Inc.)
Task: {CAD0B32F-C8F3-4155-8B82-9A23F3104DE4} - System32\Tasks\{368995C6-CB26-4D45-9BC0-7A1BEBBF06CF} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/abandoninstall?page=tsBing
Task: {D555A0BC-7A38-46F4-8511-70C3A6F00A38} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-15] (Adobe Systems Incorporated)
Task: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => Rundll32.exe /d acproxy.dll,PerformAutochkOperations
Task: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => Rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2009-08-28 16:08 - 2009-08-28 16:08 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-01-14 20:48 - 2010-01-14 20:48 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2010-10-12 11:21 - 2009-12-12 14:12 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2013-08-06 22:32 - 2013-08-06 22:20 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00230376 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\directsound_win32.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00237032 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win32.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00159208 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\plugins\appscanner_plugin.dll
2012-07-30 15:13 - 2013-10-24 12:37 - 00431080 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
2013-09-11 12:01 - 2013-10-24 12:37 - 00555496 _____ () C:\Program Files (x86)\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 36%
Total physical RAM: 4095.12 MB
Available physical RAM: 2618.98 MB
Total Pagefile: 8188.41 MB
Available Pagefile: 6187.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:265.19 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DACBA7AD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================


--- --- --- --- --- --- --- --- --- -- --- --- --- ---


Ich hab noch etwas vergessen, Entschuldigung dafür. Und zwar habe ich, glaube als aller erstes, scheinbar so ein "Rkill" laufen gelassen, wurde mir in einem YOUTUBE-Video empfohlen. da erhielt ich folgenden Log:

Code:

Rkill 2.6.3 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 hxxp://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 12/01/2013 04:51:13 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
 C:\Users\PC\Desktop\rkill\rkill-12-01-2013-04-51-21.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * No issues found.

Searching for Missing Digital Signatures:



-- --- --- --- --- --- --- --- --- --- --- --- --- --- ---


Ich danke vielmals im Voraus schon und hoffe das ich niemandem zur Last falle hier.

Lg

Chiara :bussi:

cosinus 02.12.2013 16:18

Malwarebytes Anti-Rootkit (MBAR)

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers

Sigrowon 02.12.2013 17:58

Ich habe alles exakt nach der Anleitung + deiner Anweisungen getan.

Nach dem ich den Scan laufen gelassen habe, sagte er mir er hat nichts gefunden bzw. das alles sauber ist. Somit fand ich weder einen Clean-UP button, noch wurde nach einem Neustart gefragt.

Den mbar-log-2013-12-02 (17-08-03), also das Logfile habe ich trotzdem gefunden. Hier das Logfile:

Code:

Malwarebytes Anti-Rootkit BETA 1.07.0.1007
www.malwarebytes.org

Database version: v2013.12.02.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
PC :: ---- [administrator]

02.12.2013 17:08:03
mbar-log-2013-12-02 (17-08-03).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Kernel memory modifications detected. Deep Anti-Rootkit Scan engaged.
Objects scanned: 234366
Time elapsed: 25 minute(s), 38 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)


Lg

Chiara

cosinus 03.12.2013 10:21

Ok :) Ein frisches FRST Log bitte

Sigrowon 03.12.2013 13:21

Hier ist ein von eben gemachtes FRST.log :


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013
Ran by PC (administrator) on ---- on 03-12-2013 12:59:57
Running from C:\Users\PC\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\update.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\updrgui.exe
(Avira Operations GmbH & Co. KG) C:\ProgramData\Avira\AntiVir Desktop\TEMP\SELFUPDATE\update.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7574048 2009-03-30] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-10-30] ()
MountPoints2: {2a8763ce-c1a6-11df-9d01-002618d6a2bf} - F:\Autorun.exe
MountPoints2: {4d126ea1-d5e6-11df-b593-002618d6a2bf} - G:\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2349392 2013-11-11] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs:  [ ] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x328D93A362C9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {434D452D-5637-006A-76A7-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: No Name - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: ftd - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Unity Player) - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Blue Space Sunset Chrome Theme) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nndfdjfoclbidmgpmbelcieibgjjfdog\4.3_0
CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2011-12-25] ()

==================== Drivers (Whitelisted) ====================

S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [107416 2013-12-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2010-05-25] (Devguru Co., Ltd)
R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [18816 2008-01-17] (Razer USA Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2008-01-21] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-09-16] ()
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [129024 2010-04-27] (MCCI Corporation)
U3 aj5xkey4; C:\Windows\System32\Drivers\aj5xkey4.sys [0 ] (Microsoft Corporation)
S3 X6va003; \??\C:\Users\PC\AppData\Local\Temp\003977D.tmp [x]
S3 X6va005; \??\C:\Users\PC\AppData\Local\Temp\005422E.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 13:01 - 2013-12-03 13:02 - 00000000 ____D C:\6317ba9ce3749480250287e0
2013-12-03 12:59 - 2013-12-03 12:59 - 01959434 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-02 17:07 - 2013-12-02 17:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-02 16:58 - 2013-12-02 17:49 - 00000000 ____D C:\Users\PC\Desktop\mbar
2013-12-02 16:58 - 2013-12-02 17:04 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-02 16:56 - 2013-12-02 16:56 - 12576792 _____ (Malwarebytes Corp.) C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
2013-12-02 15:48 - 2013-12-02 15:48 - 00105352 _____ C:\Users\PC\Desktop\Trojaner Board.txt
2013-12-02 03:01 - 2013-12-02 03:01 - 00000968 _____ C:\Users\PC\Desktop\sonja und benny.txt
2013-12-01 22:13 - 2013-12-01 22:13 - 00014258 _____ C:\Users\PC\Desktop\Addition.txt
2013-12-01 22:12 - 2013-12-03 13:00 - 00013920 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:12 - 2013-12-01 21:16 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:57 - 2013-12-01 16:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:57 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 16:51 - 2013-12-01 16:55 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:01 - 2013-11-26 03:09 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-14 02:40 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 02:40 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 02:40 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 02:40 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 02:40 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 02:40 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 02:40 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 02:40 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 02:40 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 02:40 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 02:40 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 02:40 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-14 02:39 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 02:39 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 02:39 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment

==================== One Month Modified Files and Folders =======

2013-12-03 13:02 - 2013-12-03 13:01 - 00000000 ____D C:\6317ba9ce3749480250287e0
2013-12-03 13:02 - 2013-12-01 22:12 - 00013920 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-03 13:02 - 2011-01-29 12:21 - 00000000 ____D C:\Users\PC\AppData\Local\PMB Files
2013-12-03 13:00 - 2010-01-14 17:55 - 01591498 _____ C:\Windows\WindowsUpdate.log
2013-12-03 12:59 - 2013-12-03 12:59 - 01959434 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-03 12:59 - 2013-08-06 22:32 - 00107416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-03 12:55 - 2012-12-18 23:41 - 00000000 ____D C:\Users\PC\AppData\Local\LogMeIn Hamachi
2013-12-03 12:54 - 2013-04-13 17:11 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-03 12:54 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-03 12:54 - 2009-07-14 05:51 - 00234135 _____ C:\Windows\setupact.log
2013-12-03 02:20 - 2012-09-01 12:35 - 00000000 ____D C:\Users\PC\AppData\Roaming\TS3Client
2013-12-03 01:45 - 2013-04-13 17:11 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-03 01:41 - 2011-01-29 12:21 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-03 01:37 - 2013-04-04 20:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-02 22:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-02 17:49 - 2013-12-02 17:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-02 17:49 - 2013-12-02 16:58 - 00000000 ____D C:\Users\PC\Desktop\mbar
2013-12-02 17:04 - 2013-12-02 16:58 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-02 16:56 - 2013-12-02 16:56 - 12576792 _____ (Malwarebytes Corp.) C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
2013-12-02 15:48 - 2013-12-02 15:48 - 00105352 _____ C:\Users\PC\Desktop\Trojaner Board.txt
2013-12-02 15:13 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-02 15:13 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-02 03:01 - 2013-12-02 03:01 - 00000968 _____ C:\Users\PC\Desktop\sonja und benny.txt
2013-12-02 03:01 - 2013-03-18 00:50 - 00006631 _____ C:\Users\PC\Desktop\randome.txt
2013-12-01 23:14 - 2010-06-05 12:07 - 00001624 _____ C:\Users\PC\Desktop\Passwörter.txt
2013-12-01 22:19 - 2013-01-23 23:17 - 00000000 ____D C:\Users\PC\Desktop\Mouseclick, Schneiden - Umwandeln
2013-12-01 22:19 - 2012-10-06 02:02 - 00000000 ____D C:\Users\PC\Desktop\TS
2013-12-01 22:13 - 2013-12-01 22:13 - 00014258 _____ C:\Users\PC\Desktop\Addition.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:16 - 2013-12-01 21:12 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 20:42 - 2011-10-17 17:42 - 00188760 _____ C:\Windows\PFRO.log
2013-12-01 19:18 - 2012-12-29 19:56 - 01251840 ___SH C:\Users\PC\Desktop\Thumbs.db
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:58 - 2013-12-01 16:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:55 - 2013-12-01 16:51 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-01 15:43 - 2013-10-15 20:59 - 00000000 ____D C:\ProgramData\Oracle
2013-12-01 15:39 - 2010-01-14 17:56 - 00000000 ___RD C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-01 15:11 - 2010-01-14 17:56 - 00001641 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 01:17 - 2011-04-08 19:42 - 00000000 ____D C:\Users\PC\Desktop\Fotos
2013-12-01 01:17 - 2010-12-04 17:22 - 00000000 ____D C:\Users\PC\Desktop\bilder
2013-12-01 01:13 - 2010-11-30 19:39 - 00000000 ____D C:\Users\PC\Desktop\Lehre
2013-11-30 14:05 - 2009-07-14 18:58 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-11-30 14:05 - 2009-07-14 18:58 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-11-30 14:05 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-26 03:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-26 03:09 - 2013-11-26 03:01 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-22 23:36 - 2012-08-12 11:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\Skype
2013-11-22 14:01 - 2012-10-19 14:00 - 00000000 ____D C:\Users\PC\AppData\Roaming\.minecraft
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-19 13:35 - 2013-08-07 10:58 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-17 21:44 - 2010-03-22 03:29 - 00000000 ____D C:\Users\PC\Desktop\Wallpaper
2013-11-16 22:57 - 2013-02-25 00:42 - 00000000 ____D C:\Users\PC\Desktop\TS 3 Icons
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files\Google
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-15 14:55 - 2012-08-17 16:56 - 00000000 ____D C:\Users\PC\AppData\Local\Google
2013-11-15 14:54 - 2013-04-04 20:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 14:54 - 2013-04-04 20:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 14:54 - 2013-04-04 20:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-15 14:54 - 2010-03-22 03:53 - 00000000 ____D C:\Users\PC\AppData\Local\Adobe
2013-11-15 03:13 - 2010-03-22 03:57 - 00000000 ____D C:\Users\PC\Desktop\Musik
2013-11-14 02:46 - 2013-07-14 01:17 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 02:45 - 2010-03-22 03:11 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-12 12:48 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-11 05:50 - 2010-03-22 02:59 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment
2013-11-07 22:06 - 2012-08-10 14:59 - 00000000 ____D C:\Users\PC\AppData\Local\Apps\2.0
2013-11-06 21:02 - 2012-12-12 01:41 - 00000000 ___RD C:\Users\PC\Desktop\Movie Maker
2013-11-04 15:32 - 2012-10-08 19:41 - 00000000 ____D C:\Users\PC\Desktop\Text-Dokumente

Some content of TEMP:
====================
C:\Users\PC\AppData\Local\Temp\7za.exe
C:\Users\PC\AppData\Local\Temp\APNStub.exe
C:\Users\PC\AppData\Local\Temp\AskSLib.dll
C:\Users\PC\AppData\Local\Temp\avgnt.exe
C:\Users\PC\AppData\Local\Temp\BackupSetup.exe
C:\Users\PC\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\PC\AppData\Local\Temp\drm_dialogs.dll
C:\Users\PC\AppData\Local\Temp\drm_dyndata_7370007.dll
C:\Users\PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\PC\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\PC\AppData\Local\Temp\InstallAX.exe
C:\Users\PC\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\Quarantine.exe
C:\Users\PC\AppData\Local\Temp\SkypeSetup.exe
C:\Users\PC\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\PC\AppData\Local\Temp\vcredist_x64.exe
C:\Users\PC\AppData\Local\Temp\war3_Install.exe
C:\Users\PC\AppData\Local\Temp\_isAB9A.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-02 22:07

==================== End Of Log ============================

--- --- ---



Lg

Chiara:knuddel:

cosinus 03.12.2013 13:36

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x328D93A362C9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
C:\Users\PC\AppData\Local\Temp\7za.exe
C:\Users\PC\AppData\Local\Temp\APNStub.exe
C:\Users\PC\AppData\Local\Temp\AskSLib.dll
C:\Users\PC\AppData\Local\Temp\avgnt.exe
C:\Users\PC\AppData\Local\Temp\BackupSetup.exe
C:\Users\PC\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\PC\AppData\Local\Temp\drm_dialogs.dll
C:\Users\PC\AppData\Local\Temp\drm_dyndata_7370007.dll
C:\Users\PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\PC\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\PC\AppData\Local\Temp\InstallAX.exe
C:\Users\PC\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\Quarantine.exe
C:\Users\PC\AppData\Local\Temp\SkypeSetup.exe
C:\Users\PC\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\PC\AppData\Local\Temp\vcredist_x64.exe
C:\Users\PC\AppData\Local\Temp\war3_Install.exe
C:\Users\PC\AppData\Local\Temp\_isAB9A.exe


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Sigrowon 03.12.2013 13:41

Fixlist Log:

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-12-2013
Ran by PC at 2013-12-03 13:40:50 Run:1
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x328D93A362C9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
C:\Users\PC\AppData\Local\Temp\7za.exe
C:\Users\PC\AppData\Local\Temp\APNStub.exe
C:\Users\PC\AppData\Local\Temp\AskSLib.dll
C:\Users\PC\AppData\Local\Temp\avgnt.exe
C:\Users\PC\AppData\Local\Temp\BackupSetup.exe
C:\Users\PC\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\PC\AppData\Local\Temp\drm_dialogs.dll
C:\Users\PC\AppData\Local\Temp\drm_dyndata_7370007.dll
C:\Users\PC\AppData\Local\Temp\FileSystemView.dll
C:\Users\PC\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\PC\AppData\Local\Temp\InstallAX.exe
C:\Users\PC\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\PC\AppData\Local\Temp\Quarantine.exe
C:\Users\PC\AppData\Local\Temp\SkypeSetup.exe
C:\Users\PC\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\PC\AppData\Local\Temp\vcredist_x64.exe
C:\Users\PC\AppData\Local\Temp\war3_Install.exe
C:\Users\PC\AppData\Local\Temp\_isAB9A.exe
*****************

HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache AcceptLangs => Value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{D8278076-BC68-4484-9233-6E7F1628B56C} => Value deleted successfully.
C:\Users\PC\AppData\Local\Temp\7za.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\APNStub.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\AskSLib.dll => Moved successfully.
C:\Users\PC\AppData\Local\Temp\avgnt.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\CmdLineExt02.dll => Moved successfully.
C:\Users\PC\AppData\Local\Temp\drm_dialogs.dll => Moved successfully.
C:\Users\PC\AppData\Local\Temp\drm_dyndata_7370007.dll => Moved successfully.
C:\Users\PC\AppData\Local\Temp\FileSystemView.dll => Moved successfully.
C:\Users\PC\AppData\Local\Temp\FlashPlayerUpdate.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\InstallAX.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\SkypeSetup.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\swt-win32-3349.dll => Moved successfully.
C:\Users\PC\AppData\Local\Temp\vcredist_x64.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\war3_Install.exe => Moved successfully.
C:\Users\PC\AppData\Local\Temp\_isAB9A.exe => Moved successfully.

==== End of Fixlog ====

Lg

Chiara

cosinus 03.12.2013 14:11

Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM)

Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren!

Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Sigrowon 03.12.2013 16:16

Quickscan mbam-log:

Code:

Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.12.03.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16428
PC :: ---- [Administrator]

Schutz: Aktiviert

03.12.2013 14:18:24
mbam-log-2013-12-03 (14-18-24).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 212587
Laufzeit: 5 Minute(n), 47 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)



ESET Logfile:

Code:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=265823a130d90544b894bc2a9772dc4d
# engine=16117
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-12-03 03:05:55
# local_time=2013-12-03 04:05:55 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 94 11496 156754460 7514 0
# compatibility_mode=5893 16776573 100 94 11024 137713005 0 0
# scanned=341724
# found=5
# cleaned=0
# scan_time=5868
sh=AF344D7C5D38ED21BE0CEEDCF4EFDA9E5E2130E7 ft=1 fh=26f8de7cec21fb12 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir"
sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats" ac=I fn="C:\Users\PC\AppData\Local\Temp\{6647D440-2080-41CD-8BDE-D9556761D401}\setup.exe"
sh=440186A1A5642722B3D806C95F52E972B17ABECD ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\PC\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\6349049b-59871480"
sh=C56FE690FD4A2EFD4F519B9234159B02F9B0A887 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\PC\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\5fca3344-4364649b"
sh=DC7568475EA8FAF621EA9BDFE892066B3C5061F9 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\PC\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\7cbe2a-356636b7"



Lg

Chiara:bussi:

cosinus 03.12.2013 20:57

Nur Reste. Bitte TFC ausführen:

TFC - Temp File Cleaner

Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
  • Öffne die TFC.exe.
    Vista und Win 7 User mit Rechtsklick "als Administrator starten".
  • Schließe alle anderen Programme.
  • Drücke auf den Button Start.
  • Falls du zu einem Neustart aufgefordert wirst, bestätige diesen.




Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

Sigrowon 03.12.2013 21:45

Ich habe das TFC nun gestartet und am Ende wurde mir angezeigt das er ein Paar Megabyte gesäubert hat oder so^^.

Zu einem Neustart wurde ich nicht aufgefordert, habe aber selbst zur Sicherheit einen gemacht.

Wenn ich auf Internet Explorer gehe, bekomme ich aber nach wie vor als Startseite das Nation Zoom. Was nun? Verzweifle gerade wieder :(

Lg

Chiara

cosinus 03.12.2013 21:46

Frisches FRST Log posten

Sigrowon 03.12.2013 22:00

FRST Log:


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013 02
Ran by PC (administrator) on ---- on 03-12-2013 21:48:53
Running from C:\Users\PC\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7574048 2009-03-30] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-10-30] ()
MountPoints2: {2a8763ce-c1a6-11df-9d01-002618d6a2bf} - F:\Autorun.exe
MountPoints2: {4d126ea1-d5e6-11df-b593-002618d6a2bf} - G:\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2349392 2013-11-11] (LogMeIn Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs:  [ ] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {434D452D-5637-006A-76A7-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: No Name - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: ftd - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Unity Player) - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Blue Space Sunset Chrome Theme) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nndfdjfoclbidmgpmbelcieibgjjfdog\4.3_0
CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2011-12-25] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [107416 2013-12-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2010-05-25] (Devguru Co., Ltd)
R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [18816 2008-01-17] (Razer USA Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2008-01-21] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-09-16] ()
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [129024 2010-04-27] (MCCI Corporation)
U3 awz3xilm; C:\Windows\System32\Drivers\awz3xilm.sys [0 ] (Microsoft Corporation)
S3 X6va003; \??\C:\Users\PC\AppData\Local\Temp\003977D.tmp [x]
S3 X6va005; \??\C:\Users\PC\AppData\Local\Temp\005422E.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 21:48 - 2013-12-03 21:48 - 01959614 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-03 21:11 - 2013-12-03 21:11 - 00448512 _____ (OldTimer Tools) C:\Users\PC\Desktop\TFC.exe
2013-12-02 17:07 - 2013-12-02 17:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-02 16:58 - 2013-12-02 17:49 - 00000000 ____D C:\Users\PC\Desktop\mbar
2013-12-02 16:58 - 2013-12-02 17:04 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-02 16:56 - 2013-12-02 16:56 - 12576792 _____ (Malwarebytes Corp.) C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
2013-12-02 15:48 - 2013-12-02 15:48 - 00105352 _____ C:\Users\PC\Desktop\Trojaner Board.txt
2013-12-01 22:13 - 2013-12-01 22:13 - 00014258 _____ C:\Users\PC\Desktop\Addition.txt
2013-12-01 22:12 - 2013-12-03 21:48 - 00012450 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:12 - 2013-12-01 21:16 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:57 - 2013-12-01 16:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:57 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 16:51 - 2013-12-01 16:55 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:01 - 2013-11-26 03:09 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-14 02:40 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 02:40 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 02:40 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 02:40 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 02:40 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 02:40 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 02:40 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 02:40 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 02:40 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 02:40 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 02:40 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 02:40 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-14 02:39 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 02:39 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 02:39 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment

==================== One Month Modified Files and Folders =======

2013-12-03 21:49 - 2013-12-01 22:12 - 00012450 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-03 21:49 - 2011-01-29 12:21 - 00000000 ____D C:\Users\PC\AppData\Local\PMB Files
2013-12-03 21:48 - 2013-12-03 21:48 - 01959614 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-03 21:45 - 2013-04-13 17:11 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-03 21:43 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-03 21:43 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-03 21:39 - 2010-01-14 17:55 - 01623039 _____ C:\Windows\WindowsUpdate.log
2013-12-03 21:37 - 2013-04-04 20:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-03 21:37 - 2012-12-18 23:41 - 00000000 ____D C:\Users\PC\AppData\Local\LogMeIn Hamachi
2013-12-03 21:36 - 2013-04-13 17:11 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-03 21:35 - 2011-10-17 17:42 - 00189594 _____ C:\Windows\PFRO.log
2013-12-03 21:35 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-03 21:35 - 2009-07-14 05:51 - 00234191 _____ C:\Windows\setupact.log
2013-12-03 21:11 - 2013-12-03 21:11 - 00448512 _____ (OldTimer Tools) C:\Users\PC\Desktop\TFC.exe
2013-12-03 12:59 - 2013-08-06 22:32 - 00107416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-03 02:20 - 2012-09-01 12:35 - 00000000 ____D C:\Users\PC\AppData\Roaming\TS3Client
2013-12-03 01:41 - 2011-01-29 12:21 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-02 22:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-02 17:49 - 2013-12-02 17:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-02 17:49 - 2013-12-02 16:58 - 00000000 ____D C:\Users\PC\Desktop\mbar
2013-12-02 17:04 - 2013-12-02 16:58 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-02 16:56 - 2013-12-02 16:56 - 12576792 _____ (Malwarebytes Corp.) C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
2013-12-02 15:48 - 2013-12-02 15:48 - 00105352 _____ C:\Users\PC\Desktop\Trojaner Board.txt
2013-12-02 03:01 - 2013-03-18 00:50 - 00006631 _____ C:\Users\PC\Desktop\randome.txt
2013-12-01 23:14 - 2010-06-05 12:07 - 00001624 _____ C:\Users\PC\Desktop\Passwörter.txt
2013-12-01 22:19 - 2013-01-23 23:17 - 00000000 ____D C:\Users\PC\Desktop\Mouseclick, Schneiden - Umwandeln
2013-12-01 22:19 - 2012-10-06 02:02 - 00000000 ____D C:\Users\PC\Desktop\TS
2013-12-01 22:13 - 2013-12-01 22:13 - 00014258 _____ C:\Users\PC\Desktop\Addition.txt
2013-12-01 22:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:16 - 2013-12-01 21:12 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 19:18 - 2012-12-29 19:56 - 01251840 ___SH C:\Users\PC\Desktop\Thumbs.db
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:58 - 2013-12-01 16:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:55 - 2013-12-01 16:51 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-01 15:43 - 2013-10-15 20:59 - 00000000 ____D C:\ProgramData\Oracle
2013-12-01 15:39 - 2010-01-14 17:56 - 00000000 ___RD C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-01 15:11 - 2010-01-14 17:56 - 00001641 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 01:17 - 2011-04-08 19:42 - 00000000 ____D C:\Users\PC\Desktop\Fotos
2013-12-01 01:17 - 2010-12-04 17:22 - 00000000 ____D C:\Users\PC\Desktop\bilder
2013-12-01 01:13 - 2010-11-30 19:39 - 00000000 ____D C:\Users\PC\Desktop\Lehre
2013-11-30 14:05 - 2009-07-14 18:58 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-11-30 14:05 - 2009-07-14 18:58 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-11-30 14:05 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-26 03:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-26 03:09 - 2013-11-26 03:01 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-22 23:36 - 2012-08-12 11:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\Skype
2013-11-22 14:01 - 2012-10-19 14:00 - 00000000 ____D C:\Users\PC\AppData\Roaming\.minecraft
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-19 13:35 - 2013-08-07 10:58 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-17 21:44 - 2010-03-22 03:29 - 00000000 ____D C:\Users\PC\Desktop\Wallpaper
2013-11-16 22:57 - 2013-02-25 00:42 - 00000000 ____D C:\Users\PC\Desktop\TS 3 Icons
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files\Google
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-15 14:55 - 2012-08-17 16:56 - 00000000 ____D C:\Users\PC\AppData\Local\Google
2013-11-15 14:54 - 2013-04-04 20:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 14:54 - 2013-04-04 20:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 14:54 - 2013-04-04 20:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-15 14:54 - 2010-03-22 03:53 - 00000000 ____D C:\Users\PC\AppData\Local\Adobe
2013-11-15 03:13 - 2010-03-22 03:57 - 00000000 ____D C:\Users\PC\Desktop\Musik
2013-11-14 02:46 - 2013-07-14 01:17 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 02:45 - 2010-03-22 03:11 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-13 13:12 - 2013-11-13 13:12 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-11-12 12:48 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-11 05:50 - 2010-03-22 02:59 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment
2013-11-07 22:06 - 2012-08-10 14:59 - 00000000 ____D C:\Users\PC\AppData\Local\Apps\2.0
2013-11-06 21:02 - 2012-12-12 01:41 - 00000000 ___RD C:\Users\PC\Desktop\Movie Maker
2013-11-04 15:32 - 2012-10-08 19:41 - 00000000 ____D C:\Users\PC\Desktop\Text-Dokumente

Some content of TEMP:
====================
C:\Users\PC\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-02 22:07

==================== End Of Log ============================

--- --- ---



Lg

Chiara

cosinus 03.12.2013 22:26

Ich da nix von nationzoom im IE

Scan mit SystemLook (x64)

Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop.
SystemLook (64 bit)
  • Doppelklicke auf die SystemLook_x64.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:
    Code:

    :filefind
    *nationz*

    :folderfind
    *nationz*

    :regfind
    nationz

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich Dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auf dem Desktop als SystemLook.txt gespeichert.

Sigrowon 03.12.2013 22:33

Ist das mit Absicht so das bei dem 3. keine Sternchen sind * *

:filefind
*nationz*

:folderfind
*nationz*

:regfind
nationz


Lg

Chiara

cosinus 03.12.2013 22:35

Ja, das ist Absicht. In der Registry sollte man nicht nach Sternchen suchen, in Dateisystemobjekten dienen sie aber als Platzhalter bzw wildcards

Sigrowon 03.12.2013 22:39

Hier der SystemLook Log, oder so :D

Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 22:32 on 03/12/2013 by PC
Administrator - Elevation successful

========== filefind ==========

Searching for "*nationz*"
C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml        --a---- 13 bytes        [20:58 03/12/2013]        [20:58 03/12/2013] C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
C:\Users\PC\Favorites\Links\Nationzoom entfernen - Trojaner-Board.url        --a---- 2536 bytes        [18:32 01/12/2013]        [18:32 01/12/2013] 332A3BFD7855340224CA398BEB35E110

========== folderfind ==========

Searching for "*nationz*"
No folders found.

========== regfind ==========

Searching for "nationz"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\nationzoom.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
@=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command]
@=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186"
[HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Internet Explorer\DOMStorage\nationzoom.com]

-= EOF =-



Lg

Chiara

cosinus 03.12.2013 23:08

Liste der Anhänge anzeigen (Anzahl: 1)
Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml
Diese Datei bitte von Hand löschen.
Bei der Registry bastel ich mal ein reg-Script zusammen, liegt im Anhang, einfach runterladen auf den Desktop und doppelklicken. Inhalt des Reg-Fixes:

Code:

Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\nationzoom.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
@="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command]
@="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
[-HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Internet Explorer\DOMStorage\nationzoom.com]


Sigrowon 04.12.2013 00:46

Also ich habe jetzt das hier in Start kopiert:

Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml
Es war weg und dann wieder da, aber beim 2. mal konnte ich es nicht löschen. Nach einem PC-Neustart war es komplett weg. Da ich aber nur diese Seite (Trojaner-Board Nation Zoom nicht entfernbar?) nur öffnen kann indem ich meinen Internet Explorer starte und in der Favoritenleiste auf diese Seite hier klicke, startet sich ja automatisch die Nation Zoom Startseite. Das bewirkt nun das unter
Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml
dieses Teil das ich löschen soll, wieder erscheint, weil ich ja auf der Nation Zoom Startseite erneut war.

Hoffe du verstehst was ich meine, wenn nicht einfach melden, ich versuch es anders auszudrücken.


Nun aber noch eine Frage. Ich habe nun auch deinen Anhang geladen auf meinem Desktop und ausgeführt. Ausversehen 2 mal. Für was ist aber der Code den du mir geschrieben hast oder eher, was sol ich damit tun?

Lg

Chiara :) :bussi:

cosinus 04.12.2013 09:27

Zitat:

Also ich habe jetzt das hier in Start kopiert:
Bitte was? :wtf:
Du sollst doch nicht den Pfad dieser XML-Datei kopieren, sondern die Datei manuell löschen. Wie man einen Dateimanager (Windows-Explorer) bedient ist dir bekannt? :confused:


Aber egal, hast du den regfix gemacht? Wenn ja bitte den Suchlauf mit Systemlook wiederholen.

Sigrowon 04.12.2013 12:25

:pfeiff:Ich sagte ja ganz am Anfang, meine Computerkentnisse sind ... naja.
Tut mir echt leid, hoffe habe nichts schlimmes gemacht.

Tut mir leid für die blöde Frage, aber wie lösche ich die Datei manuell?

Lg

Chiara

PS: Entschuldigung :(

cosinus 04.12.2013 15:27

Zitat:

Tut mir leid für die blöde Frage, aber wie lösche ich die Datei manuell?
Grundkenntnisse wie man den Arbeitsplatz verwendet sind schon vorhanden oder? :wtf:
Einfach in der Ordnerstruktir durchklickern oder in die Adresszeile

Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\
das rein kopieren und schon biste im Ordner der die besagte Datei enthält.

Richtiges Hexenwerk :blabla: :lach: über die Console cmd.exe oder Start ausführen:

Code:

rd /s/q "C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\"
löscht den Ordner TAQAM9O2 in C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore

der Befehl

Code:

del "C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml"
löscht hingegen nur die Datei www.nationzoom[1].xml in "C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\"

Sigrowon 04.12.2013 23:00

Cosinus, ich glaube ich bin mit unter die dümmste der du jeher helfen musstest :(
Hab mit meinen 17 Jahren leider nur Kenntnisse von Kleinigkeiten und unwichtigen Sachen.
Zitat:

Grundkenntnisse wie man den Arbeitsplatz verwendet sind schon vorhanden oder?
naja schon ein Paar aber nicht all zu viele. Tut mir echt leid.

Also ich habe das hier
Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\
jetzt in die Adresszeile rein kopiert.
Anschließend habe ich die Nation Zoom Datei gelöscht.

bin mittlerweile nun auch soweit das wenn ich das hier
Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore
rein kopiere, das dann nur noch kommt:
Zitat:

Dieser Ordner ist Leer
Wenn ich dies hier rein kopiere:
Zitat:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\
findet er nichts mehr bzw. es steht folgendes da:
Zitat:

Die Datei "C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\" wurde nicht gefunden. Überprüfen sie die Schreibweise, und wiederhohlen sie den Vorgang
Habe aber wirklich nur die Datei www.nationzoom[1].xml gelöscht, wie befohlen, mehr nicht.

Ich glaube ich bin echt doof :heulen:

Lg

Chiara

cosinus 04.12.2013 23:10

Ja vergiss jetztma die Datei, hast du den regfix gemacht?

Sigrowon 05.12.2013 00:03

Öh kann ich dir nich genau sagen, wie macht man den Reg Fix genau?
Kann dir dann sagen ob ja(gemacht) oder nein(nicht gemacht, mach es aber sofort)

cosinus 05.12.2013 00:27

Ich habs doch erklärt :heulen:
Datei aus meinem Anhang runterladen, doppelklicken, mit ja bestätigen

Sigrowon 05.12.2013 01:09

Ach das, ja hab ich gemacht, direkt am Anfang. Was soll is nu machen?

Zur Sicherheit eben auch nochmal gemacht. Habs aber schon am Anfang getan.

cosinus 05.12.2013 10:12

Gut. Dann schauen wir mal was der Fix gebracht hat:

Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:
    Code:

    :filefind
    *nationz*

    :folderfind
    *nationz*

    :regfind
    nationz

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.


Sigrowon 05.12.2013 13:44

SystemLook Log:
Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 13:33 on 05/12/2013 by PC
Administrator - Elevation successful

========== filefind ==========

Searching for "*nationz*"
C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml        --a---- 13 bytes        [23:12 04/12/2013]        [23:12 04/12/2013] C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
C:\Users\PC\Desktop\62681d1386108610-nation-zoom-entfernbar-nationzoom.reg        --a---- 565 bytes        [23:17 03/12/2013]        [23:17 03/12/2013] 8F0618918586F619C6470FF24609957C
C:\Users\PC\Favorites\Links\Nationzoom entfernen - Trojaner-Board.url        --a---- 2536 bytes        [18:32 01/12/2013]        [18:32 01/12/2013] 332A3BFD7855340224CA398BEB35E110

========== folderfind ==========

Searching for "*nationz*"
No folders found.

========== regfind ==========

Searching for "nationz"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"k"="C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml\1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command]
@=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command]
@=""C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186"
[HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU]
"k"="C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml\1"

-= EOF =-

hoffen wir das beste.

Moment mal, wieso ist den jetzt wieder das "C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\" in dem Log zu sehen. Wenn ich es im Explorer eingebe ist das www.nationzoom..... auch wieder da? Beabsichtigt? Oder weil ich gestern nochmal die Datei aus deinem Anhang ausgeführt habe?

cosinus 05.12.2013 13:58

:hmpf: :nixda:

Probieren wir das nochmal mit FRST

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml               
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Sigrowon 05.12.2013 14:02

Fixlog:

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-12-2013
Ran by PC at 2013-12-05 14:01:38 Run:2
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml               
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v @ /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v @ /f
*****************

"C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml                " => File/Directory not found.

========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f =========

Der Vorgang wurde erfolgreich beendet.



========= End of Reg: =========


========= reg delete "HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k /f =========



========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v @ /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v @ /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


==== End of Fixlog ====


cosinus 05.12.2013 14:34

Nationzoom nun weg?

Sigrowon 05.12.2013 14:42

Nein. Leider nicht. Soll ich nen Neustart oder so machen?

cosinus 05.12.2013 14:45

Durchtesten in welchen Browsern der noch kommt.

Edit: Helfen kann auch noch http://filepony.de/download-avast_browser_cleanup/

Sigrowon 05.12.2013 14:53

Also Filepony findet nichts.

Und Nation Zoom ist nach wie vor als Startseite in Internet Explorer und Google Chrome. Die 2 einzigen Browser die ich verwende.

cosinus 05.12.2013 14:55

Dann musst du den IE und Google Chrome resetten

Zurücksetzen von Internet Explorer-Einstellungen

https://support.google.com/chrome/answer/3296214

Sigrowon 05.12.2013 14:56

Ich entschuldige mich im Voraus für diesen Kommentar aber:

Ich Küss dir die Füße wenn das funktioniert :)

cosinus 05.12.2013 14:58

Zitat:

Zitat von Sigrowon (Beitrag 1207317)
Ich Küss dir die Füße wenn das funktioniert :)

Nice :D hab heute früh aber nicht geduscht :zunge:

Sigrowon 05.12.2013 16:25

Hab mich schon drauf eingestellt aber wird doch leider nix draus, glaube ich.

Habe den Internet Explorer mehrfach automatisch und manuell zurückgesetzt. Nach einem Neustart und der neuen Einrichtung der Startseite "www.google.de" ist Nation Zoom immer noch die Startseite wenn ich es neu öffne. also den Explorer. Öffne ich eine neue Registerkarte ist es nach wie vor Google als Startseite.
Nur wenn ich den Browser ganz neu öffne erscheint Nation Zoom. aber das war schon von Anfang an so, soweit ich weis. Oder falls nicht dann schon seit einer weile so.

Liegt es daran das ich Google Chrome noch nicht resetet habe? Habe es noch nicht getan weil wenn du sagst das wenn es bei Internet Explorer nicht funktioniert, ich erst gar nicht den Chrome zurücksetzen muss, dann wäre das ja unnötig.

Also was tun. nichts mehr zurücksetzen oder beides nochmal?

Edit: Ok habe nun einfach erneut IE und G. Chrom zurückgesetzt. Alles getan aber es ist nach wie vor das, das Nation Zoom.

Ich raste hier aus. Voll am verzweifeln. Ich geb mir noch die Kugel. Wieso bekommen es andere in diesem Forum weg und ich nicht :snyper::headbang::heulen:

:(

Lg

Chiara

cosinus 05.12.2013 16:46

Bitte den Fix nochmal machen

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml               
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


Sigrowon 05.12.2013 18:12

Fixlog:

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-12-2013
Ran by PC at 2013-12-05 18:12:07 Run:3
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml               
reg: reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f
reg: reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f
       
*****************

"C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml                " => File/Directory not found.

========= reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


========= reg delete "HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" /v "k" /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


========= reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Clients\StartMenuInternet\Google Chrome\shell\open\command" /v "@" /f =========

FEHLER: Der angegebene Registrierungsschlssel bzw. Wert wurde nicht gefunden.


========= End of Reg: =========


==== End of Fixlog ====


cosinus 06.12.2013 00:23

Wiederhol bitte die Suche mit Systemlook.

Sigrowon 06.12.2013 01:42

Systemlook log:
hab irgendwie nen gutes Gefühl diesmal^^ aber es täuscht mich eh immer^^

Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 01:12 on 06/12/2013 by PC
Administrator - Elevation successful

========== filefind ==========

Searching for "*nationz*"
C:\Users\PC\AppData\Local\Microsoft\Internet Explorer\DOMStore\TAQAM9O2\www.nationzoom[1].xml        --a---- 13 bytes        [13:51 05/12/2013]        [13:51 05/12/2013] C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
C:\Users\PC\Desktop\62681d1386108610-nation-zoom-entfernbar-nationzoom.reg        --a---- 565 bytes        [23:17 03/12/2013]        [23:17 03/12/2013] 8F0618918586F619C6470FF24609957C
C:\Users\PC\Favorites\Links\Nationzoom entfernen - Trojaner-Board.url        --a---- 2536 bytes        [18:32 01/12/2013]        [15:18 05/12/2013] 332A3BFD7855340224CA398BEB35E110

========== folderfind ==========

Searching for "*nationz*"
No folders found.

========== regfind ==========

Searching for "nationz"
No data found.

Searching for "        "
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\PC\Desktop\Lehre\Bewerbungsunterlagen, ect\pdf24-creator.exe"="PDF24 Creator                                              "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{6BD0AD51-D315-4103-9D4D-CF58F57EE9A6}]
"RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1">
            <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{7A53B0BE-B92D-4e8a-A11F-8E6F9F3C575B}">
                <Descriptor descriptorID="{E04AAEE8-950C-43c4-B75C-D87736A7FAFD}"/>
            </Rating>
            <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{97D9239C-2BA3-4e1d-A710-B626DC4602A6}">
                <Descriptor descriptorID="{F110F831-9412-40c9-860A-B489407ED374}"/>
            </Rating>
            <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" ratingID="{5098B1DF-486F-4e79-A6D6-6E0879A63811}"/>
            <Rating ratingSystemID="{C705DCF4-6AFE-4f4f-BC51-21807E4E5CFB}" ratingID="{6948F4DF-FD98-41ea-979A-8364043D7FD6}"/>
        </Ratings>"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{E933B35F-4A5E-4884-A454-643C3C4D73B3}]
"RatingsInfo"="<Ratings xmlns="urn:schemas-microsoft-com:GameDescription.v1">
            <Rating ratingSystemID="{768BD93D-63BE-46A9-8994-0B53C4B5248F}" ratingID="{78D8CC82-372F-44e4-B70C-8944DB7BCC24}">
                <Descriptor descriptorID="{0CFCF432-3544-4f78-9426-07A36843E6BA}"/>
                <Descriptor descriptorID="{67987CC4-6B79-4c6b-B3F0-3B6D8677BBEC}"/>
                <Descriptor descriptorID="{D49A8F0C-B183-4a34-8D86-33F2DC0E2D6C}"/>
                <Descriptor descriptorID="{BE562A5F-2A80-4c28-9752-74C696E2ABAF}"/>
            </Rating>
            <Rating ratingSystemID="{EC290BBB-D618-4cb9-9963-1CAAE515443E}" ratingID="{75AEE0A2-8640-4a20-8DE5-EC93D8DAB219}"/>
            <Rating ratingSystemID="{36798944-B235-48ac-BF21-E25671F597EE}" ratingID="{E2681CD6-318A-4935-8275-AF657045C333}">
                <Descriptor descriptorID="{6AB00271-515B-4a4d-8A6E-9E66BF96A437}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell]
"ConfigXML"="            <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" >                <InitializationParameters>                    <Param Name="PSVersion" Value="2.0"/>                </InitializationParameters>                <Resources>                    <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true">                        <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>                        <Capability Type="Shell"/>                    </Resource>                </Res
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32]
"ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" >                        <InitializationParameters>                            <Param Name="PSVersion" Value="2.0"/>                        </InitializationParameters>                        <Resources>                            <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true">                                <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>                               
[HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\PC\Desktop\Lehre\Bewerbungsunterlagen, ect\pdf24-creator.exe"="PDF24 Creator                                              "
[HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Users\PC\Desktop\Lehre\Bewerbungsunterlagen, ect\pdf24-creator.exe"="PDF24 Creator                                              "

-= EOF =-

oh ich sehe gerade das dort steht: searching for " " :
ich glaube das ist weil ich bei deinem
Zitat:

:filefind
*nationz*

:folderfind
*nationz*

:regfind
nationz
auf "Alles auswählen" klicke, ist ja alles makiert. aber unten ist noch ein platz frei der dann so ist wie wenn da mehrfach die Leertaste gedrückt wurde.

cosinus 06.12.2013 01:42

Nee so bitte nicht.

Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:
    Code:

    :regfind
    nationzoom

  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.


Sigrowon 06.12.2013 01:47

ok also nurnoch das
Code:

:regfind
nationzoom

reinkopieren, sonst nichts?

Systemlook log:

Code:

SystemLook 30.07.11 by jpshortstuff
Log created at 01:44 on 06/12/2013 by PC
Administrator - Elevation successful

========== regfind ==========

Searching for "nationzoom"
No data found.

-= EOF =-


cosinus 06.12.2013 09:33

Da ist doch garnix mehr von "nationzoom" :rofl:

Sigrowon 06.12.2013 12:49

Ich weis ich verstehs ja auch net, deswegen sag ich ja ich bin am verzweifeln.

Nichts findet mehr was von Nation Zoom aber trotzdem hab ich den versch***enen Nation Zoom "Virus" noch drauf, erkennbar daran das es einfach nicht mehr als Startseite weggeht und das nervt einfach total. Es behindert mich und es ist behindert.
Entschuldige für den Text aber langsam ist es doch wahr. :schrei:

:abklatsch::dankeschoen:für deine Geduld und deine Hilfe aber ich komme trotzdem nicht weiter mit N. Zoom. :heulen:

cosinus 06.12.2013 13:09

Hmpf

Mach nochmal neue FRST Logs. FRST neu runterladen, starten, Haken rein bei additions.txt und scannen. Beide Logs in CODE-Tags posten

Sigrowon 06.12.2013 14:46

Ok hab alles was mit FRST zu tun hat rausgeworfen und neu drauf gemacht.

FRSTlog:


FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-12-2013
Ran by PC (administrator) on ---- on 06-12-2013 14:06:05
Running from C:\Users\PC\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7574048 2009-03-30] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-03-30] (Realtek Semiconductor Corp.)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-10-30] ()
MountPoints2: {2a8763ce-c1a6-11df-9d01-002618d6a2bf} - F:\Autorun.exe
MountPoints2: {4d126ea1-d5e6-11df-b593-002618d6a2bf} - G:\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.)
AppInit_DLLs:  [ ] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {434D452D-5637-006A-76A7-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: No Name - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions
FF Extension: ftd - C:\Users\PC\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftd@ftd.com.xpi

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Unity Player) - C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Raindrops(Lite)) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\egljojpdbafibmmbdcemkdcdahloclop\1.0_0
CHR Extension: (Colorfull Sun Set) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\iknflcjkkahjgichcidlfcalplplegii\1_0
CHR Extension: (Google Wallet) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-19] (Avira Operations GmbH & Co. KG)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2011-12-25] ()

==================== Drivers (Whitelisted) ====================

R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [107416 2013-12-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-19] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20568 2010-05-25] (Devguru Co., Ltd)
R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [18816 2008-01-17] (Razer USA Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2008-01-21] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-09-16] ()
S3 ssceserd; C:\Windows\System32\DRIVERS\ssceserd.sys [129024 2010-04-27] (MCCI Corporation)
U3 a0lxaykf; C:\Windows\System32\Drivers\a0lxaykf.sys [0 ] (Microsoft Corporation)
S3 X6va003; \??\C:\Users\PC\AppData\Local\Temp\003977D.tmp [x]
S3 X6va005; \??\C:\Users\PC\AppData\Local\Temp\005422E.tmp [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-06 14:06 - 2013-12-06 14:06 - 00012225 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-06 14:04 - 2013-12-06 14:04 - 01925820 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-05 14:49 - 2013-12-05 14:49 - 02753344 _____ (AVAST Software) C:\Users\PC\Desktop\avast-browser-cleanup_90.exe
2013-12-04 00:28 - 2013-12-04 00:28 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-12-04 00:17 - 2013-12-04 00:17 - 00000565 _____ C:\Users\PC\Desktop\62681d1386108610-nation-zoom-entfernbar-nationzoom.reg
2013-12-03 22:32 - 2013-12-06 01:44 - 00000414 _____ C:\Users\PC\Desktop\SystemLook.txt
2013-12-03 22:31 - 2013-12-03 22:31 - 00165376 _____ C:\Users\PC\Desktop\SystemLook_x64.exe
2013-12-03 21:11 - 2013-12-03 21:11 - 00448512 _____ (OldTimer Tools) C:\Users\PC\Desktop\TFC.exe
2013-12-02 17:07 - 2013-12-02 17:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-02 16:58 - 2013-12-02 17:49 - 00000000 ____D C:\Users\PC\Desktop\mbar
2013-12-02 16:58 - 2013-12-02 17:04 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-02 16:56 - 2013-12-02 16:56 - 12576792 _____ (Malwarebytes Corp.) C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
2013-12-02 15:48 - 2013-12-04 00:25 - 00000094 _____ C:\Users\PC\Desktop\Trojaner Board.txt
2013-12-01 22:11 - 2013-12-05 18:11 - 00000000 ____D C:\FRST
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:12 - 2013-12-01 21:16 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:57 - 2013-12-01 16:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:57 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-12-01 16:51 - 2013-12-01 16:55 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-26 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 03:01 - 2013-11-26 03:09 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-14 02:40 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 02:40 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-14 02:40 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-14 02:40 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-14 02:40 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-14 02:40 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-14 02:40 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 02:40 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-14 02:40 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 02:40 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 02:40 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 02:40 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 02:40 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 02:40 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-14 02:40 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-14 02:40 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-14 02:40 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 02:40 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-14 02:39 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 02:39 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 02:39 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-14 02:39 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment

==================== One Month Modified Files and Folders =======

2013-12-06 14:06 - 2013-12-06 14:06 - 00012225 _____ C:\Users\PC\Desktop\FRST.txt
2013-12-06 14:04 - 2013-12-06 14:04 - 01925820 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2013-12-06 14:02 - 2012-09-01 12:35 - 00000000 ____D C:\Users\PC\AppData\Roaming\TS3Client
2013-12-06 13:59 - 2011-01-29 12:21 - 00000000 ____D C:\Users\PC\AppData\Local\PMB Files
2013-12-06 13:59 - 2011-01-29 12:21 - 00000000 ____D C:\ProgramData\PMB Files
2013-12-06 13:45 - 2013-04-13 17:11 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-06 13:37 - 2013-04-04 20:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-06 12:59 - 2009-07-14 05:51 - 00234751 _____ C:\Windows\setupact.log
2013-12-06 12:47 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-06 12:47 - 2009-07-14 05:45 - 00014800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-06 12:44 - 2010-12-04 17:22 - 00000000 ____D C:\Users\PC\Desktop\bilder
2013-12-06 12:44 - 2010-01-14 17:55 - 01757337 _____ C:\Windows\WindowsUpdate.log
2013-12-06 12:40 - 2013-04-13 17:11 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-06 12:40 - 2012-12-18 23:41 - 00000000 ____D C:\Users\PC\AppData\Local\LogMeIn Hamachi
2013-12-06 12:38 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-06 01:44 - 2013-12-03 22:32 - 00000414 _____ C:\Users\PC\Desktop\SystemLook.txt
2013-12-05 18:11 - 2013-12-01 22:11 - 00000000 ____D C:\FRST
2013-12-05 15:05 - 2012-12-29 19:56 - 01251840 ___SH C:\Users\PC\Desktop\Thumbs.db
2013-12-05 14:49 - 2013-12-05 14:49 - 02753344 _____ (AVAST Software) C:\Users\PC\Desktop\avast-browser-cleanup_90.exe
2013-12-04 00:28 - 2013-12-04 00:28 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2013-12-04 00:25 - 2013-12-02 15:48 - 00000094 _____ C:\Users\PC\Desktop\Trojaner Board.txt
2013-12-04 00:17 - 2013-12-04 00:17 - 00000565 _____ C:\Users\PC\Desktop\62681d1386108610-nation-zoom-entfernbar-nationzoom.reg
2013-12-03 22:31 - 2013-12-03 22:31 - 00165376 _____ C:\Users\PC\Desktop\SystemLook_x64.exe
2013-12-03 21:35 - 2011-10-17 17:42 - 00189594 _____ C:\Windows\PFRO.log
2013-12-03 21:11 - 2013-12-03 21:11 - 00448512 _____ (OldTimer Tools) C:\Users\PC\Desktop\TFC.exe
2013-12-03 12:59 - 2013-08-06 22:32 - 00107416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-02 22:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-02 17:49 - 2013-12-02 17:07 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-12-02 17:49 - 2013-12-02 16:58 - 00000000 ____D C:\Users\PC\Desktop\mbar
2013-12-02 17:04 - 2013-12-02 16:58 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-12-02 16:56 - 2013-12-02 16:56 - 12576792 _____ (Malwarebytes Corp.) C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
2013-12-02 03:01 - 2013-03-18 00:50 - 00006631 _____ C:\Users\PC\Desktop\randome.txt
2013-12-01 23:14 - 2010-06-05 12:07 - 00001624 _____ C:\Users\PC\Desktop\Passwörter.txt
2013-12-01 22:19 - 2013-01-23 23:17 - 00000000 ____D C:\Users\PC\Desktop\Mouseclick, Schneiden - Umwandeln
2013-12-01 22:19 - 2012-10-06 02:02 - 00000000 ____D C:\Users\PC\Desktop\TS
2013-12-01 21:34 - 2013-12-01 21:34 - 00015440 _____ C:\Users\PC\Desktop\JRT.txt
2013-12-01 21:28 - 2013-12-01 21:28 - 00000000 ____D C:\Windows\ERUNT
2013-12-01 21:27 - 2013-12-01 21:27 - 01034531 _____ (Thisisu) C:\Users\PC\Desktop\JRT.exe
2013-12-01 21:16 - 2013-12-01 21:12 - 00000000 ____D C:\AdwCleaner
2013-12-01 21:12 - 2013-12-01 21:12 - 01110034 _____ C:\Users\PC\Desktop\adwcleaner.exe
2013-12-01 16:58 - 2013-12-01 16:58 - 00000000 ____D C:\Users\PC\AppData\Roaming\Malwarebytes
2013-12-01 16:58 - 2013-12-01 16:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-01 16:57 - 2013-12-01 16:57 - 00001105 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-01 16:57 - 2013-12-01 16:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-01 16:55 - 2013-12-01 16:51 - 00001918 _____ C:\Users\PC\Desktop\Rkill.txt
2013-12-01 16:51 - 2013-12-01 16:51 - 00000000 ____D C:\Users\PC\Desktop\rkill
2013-12-01 15:43 - 2013-12-01 15:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-12-01 15:43 - 2013-12-01 15:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-12-01 15:43 - 2013-10-15 20:59 - 00000000 ____D C:\ProgramData\Oracle
2013-12-01 15:39 - 2010-01-14 17:56 - 00000000 ___RD C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-01 15:11 - 2010-01-14 17:56 - 00001641 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-01 01:17 - 2011-04-08 19:42 - 00000000 ____D C:\Users\PC\Desktop\Fotos
2013-12-01 01:13 - 2010-11-30 19:39 - 00000000 ____D C:\Users\PC\Desktop\Lehre
2013-11-30 14:05 - 2009-07-14 18:58 - 00654150 _____ C:\Windows\system32\perfh007.dat
2013-11-30 14:05 - 2009-07-14 18:58 - 00130022 _____ C:\Windows\system32\perfc007.dat
2013-11-30 14:05 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-26 03:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-11-26 03:09 - 2013-11-26 03:01 - 00011300 _____ C:\Windows\IE11_main.log
2013-11-26 03:05 - 2013-11-26 03:05 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 03:05 - 2013-11-26 03:05 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-11-26 03:05 - 2013-11-26 03:05 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-26 03:05 - 2013-11-26 03:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2013-11-26 03:05 - 2013-11-26 03:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2013-11-26 03:05 - 2013-11-26 03:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2013-11-26 03:05 - 2013-11-26 03:05 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2013-11-26 03:05 - 2013-11-26 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-23 01:54 - 2013-11-23 01:54 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll
2013-11-22 23:36 - 2012-08-12 11:24 - 00000000 ____D C:\Users\PC\AppData\Roaming\Skype
2013-11-22 14:01 - 2012-10-19 14:00 - 00000000 ____D C:\Users\PC\AppData\Roaming\.minecraft
2013-11-19 15:10 - 2013-11-19 15:10 - 00000000 ____D C:\Windows\Sun
2013-11-19 13:35 - 2013-08-07 10:58 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-19 13:35 - 2013-08-06 22:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-17 21:44 - 2010-03-22 03:29 - 00000000 ____D C:\Users\PC\Desktop\Wallpaper
2013-11-16 22:57 - 2013-02-25 00:42 - 00000000 ____D C:\Users\PC\Desktop\TS 3 Icons
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files\Google
2013-11-16 13:10 - 2012-08-17 16:56 - 00000000 ____D C:\Program Files (x86)\Google
2013-11-15 14:55 - 2012-08-17 16:56 - 00000000 ____D C:\Users\PC\AppData\Local\Google
2013-11-15 14:54 - 2013-04-04 20:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-11-15 14:54 - 2013-04-04 20:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-11-15 14:54 - 2013-04-04 20:32 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-11-15 14:54 - 2010-03-22 03:53 - 00000000 ____D C:\Users\PC\AppData\Local\Adobe
2013-11-15 03:13 - 2010-03-22 03:57 - 00000000 ____D C:\Users\PC\Desktop\Musik
2013-11-14 02:46 - 2013-07-14 01:17 - 00000000 ____D C:\Windows\system32\MRT
2013-11-14 02:45 - 2010-03-22 03:11 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-12 12:48 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-11 05:50 - 2010-03-22 02:59 - 00267936 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-07 22:06 - 2013-11-07 22:06 - 00000000 ____D C:\Users\PC\AppData\Local\Deployment
2013-11-07 22:06 - 2012-08-10 14:59 - 00000000 ____D C:\Users\PC\AppData\Local\Apps\2.0
2013-11-06 21:02 - 2012-12-12 01:41 - 00000000 ___RD C:\Users\PC\Desktop\Movie Maker

Some content of TEMP:
====================
C:\Users\PC\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-02 22:07

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---



Addition Log:

Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-12-2013
Ran by PC at 2013-12-06 14:07:16
Running from C:\Users\PC\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.152)
Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8)
AION Free-to-Play Version 1.0 (x32 Version: 1.0)
AMD Catalyst Install Manager (Version: 8.0.903.0)
Assassin's Creed Brotherhood (x32 Version: 1.03)
ATI AVIVO64 Codecs (Version: 10.10.0.40918)
ATI Problem Report Wizard (Version: 3.0.745.0)
Avira Free Antivirus (x32 Version: 14.0.1.759)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Core Implementation (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Full New (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Light (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center HydraVision Full (x32 Version: 2009.0918.2132.36825)
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485)
Catalyst Control Center Localization All (x32 Version: 2009.0918.2132.36825)
CCC Help Chinese Standard (x32 Version: 2009.0918.2131.36825)
CCC Help Chinese Traditional (x32 Version: 2009.0918.2131.36825)
CCC Help Czech (x32 Version: 2009.0918.2131.36825)
CCC Help Danish (x32 Version: 2009.0918.2131.36825)
CCC Help Dutch (x32 Version: 2009.0918.2131.36825)
CCC Help English (x32 Version: 2009.0918.2131.36825)
CCC Help Finnish (x32 Version: 2009.0918.2131.36825)
CCC Help French (x32 Version: 2009.0918.2131.36825)
CCC Help German (x32 Version: 2009.0918.2131.36825)
CCC Help Greek (x32 Version: 2009.0918.2131.36825)
CCC Help Hungarian (x32 Version: 2009.0918.2131.36825)
CCC Help Italian (x32 Version: 2009.0918.2131.36825)
CCC Help Japanese (x32 Version: 2009.0918.2131.36825)
CCC Help Korean (x32 Version: 2009.0918.2131.36825)
CCC Help Norwegian (x32 Version: 2009.0918.2131.36825)
CCC Help Polish (x32 Version: 2009.0918.2131.36825)
CCC Help Portuguese (x32 Version: 2009.0918.2131.36825)
CCC Help Russian (x32 Version: 2009.0918.2131.36825)
CCC Help Spanish (x32 Version: 2009.0918.2131.36825)
CCC Help Swedish (x32 Version: 2009.0918.2131.36825)
CCC Help Thai (x32 Version: 2009.0918.2131.36825)
CCC Help Turkish (x32 Version: 2009.0918.2131.36825)
ccc-core-static (x32 Version: 2009.0918.2132.36825)
ccc-utility64 (Version: 2009.0918.2132.36825)
D3DX10 (x32 Version: 15.4.2368.0902)
Drachenkrieg (with media and plugins), version 1.1.27 (x32)
FlatOut2 (x32 Version: 1.00.0000)
Free YouTube Download version 3.1.39.1015 (x32 Version: 3.1.39.1015)
Free YouTube to MP3 Converter version 3.11.34.1015 (x32 Version: 3.11.34.1015)
Gameforge Live 1.9.0 "Legend" (x32 Version: 1.9.0)
Google Chrome (x32 Version: 31.0.1650.63)
Google Update Helper (x32 Version: 1.3.21.165)
GRID (x32 Version: 1.00.0000)
HydraVision (x32 Version: 4.2.114.0)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
League of Legends (x32 Version: 1.3)
LogMeIn Hamachi (x32 Version: 2.2.0.109)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mesh Runtime (x32 Version: 15.4.5722.2)
Messenger Companion (x32 Version: 15.4.3502.0922)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
Need For Speed™ World (x32 Version: 1.0.0.131)
NVIDIA PhysX (x32 Version: 9.09.0203)
OpenAL (x32)
OpenOffice.org 3.0 (x32 Version: 3.0.9358)
Overwolf (x32 Version: 0.44.256)
Pando Media Booster (x32 Version: 2.6.0.8)
PDF24 Creator 5.2.0 (x32)
PlanetSide 2 (HKCU Version: 1.0.3.183)
PunkBuster Services (x32 Version: 0.990)
Rapture3D 2.4.4 Game (x32)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5821)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.2300.0)
Skype™ 6.9 (x32 Version: 6.9.106)
TeamSpeak 3 Client (x32 Version: 3.0.13.1)
Ubisoft Game Launcher (x32 Version: 1.0.0.0)
Unity Web Player (HKCU Version: )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Warcraft III (x32)
Warcraft III: All Products (HKCU)
WAV To MP3 V2 (x32)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
WinRAR archiver

==================== Restore Points  =========================

22-11-2013 11:51:44 Windows Update
26-11-2013 02:00:18 Windows Update
29-11-2013 15:58:46 Windows Update
01-12-2013 14:38:11 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
01-12-2013 14:40:00 Removed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
01-12-2013 14:41:41 Removed Java 7 Update 45
01-12-2013 14:42:56 Installed Java 7 Update 45
03-12-2013 12:00:06 Windows Update
05-12-2013 13:59:36 Installed Microsoft Fix it 50195
05-12-2013 14:32:23 Installed Microsoft Fix it 50195

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {06B433D2-FB99-42C0-BFF0-C61715C3089D} - System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector => Rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
Task: {088482FA-65B8-4E17-9ABF-1DCD48E8D373} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
Task: {09F06BFE-A3C8-40E3-846A-6E6F4000C238} - System32\Tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 => Rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
Task: {2A6ED1F6-5671-4112-9207-09A80106B246} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => Rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
Task: {A5269147-4A7F-4748-A8B4-ACCAC317D04F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-13] (Google Inc.)
Task: {A7C73732-9F11-4281-8D19-764D4EC9D94D} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe aepdu.dll,AePduRunUpdate
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent => aitagent.exe
Task: {AD3248AA-E511-4EEE-BD9D-4F102787AD6B} - System32\Tasks\{FABC27FC-E434-42E9-9434-9A87C4604791} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?source=lightinstaller&amp;page=tsMain
Task: {C1362E88-A3A2-443D-8F27-C95A4D73AC60} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-13] (Google Inc.)
Task: {CAD0B32F-C8F3-4155-8B82-9A23F3104DE4} - System32\Tasks\{368995C6-CB26-4D45-9BC0-7A1BEBBF06CF} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/abandoninstall?page=tsBing
Task: {D555A0BC-7A38-46F4-8511-70C3A6F00A38} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-15] (Adobe Systems Incorporated)
Task: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} - System32\Tasks\Microsoft\Windows\Autochk\Proxy => Rundll32.exe /d acproxy.dll,PerformAutochkOperations
Task: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} - System32\Tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange => Rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => BthUdTask.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-10-12 11:21 - 2009-12-12 14:12 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2009-08-28 16:08 - 2009-08-28 16:08 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-01-14 20:48 - 2010-01-14 20:48 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-08-06 22:32 - 2013-08-06 22:20 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/03/2013 04:12:36 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (12/03/2013 02:25:58 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (12/02/2013 03:26:04 PM) (Source: Application Hang) (User: )
Description: Programm NOTEPAD.EXE, Version 6.1.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 8fc

Startzeit: 01ceef6a64bd418b

Endzeit: 2

Anwendungspfad: C:\Windows\system32\NOTEPAD.EXE

Berichts-ID: a91bfa3e-5b5d-11e3-b955-002618d6a2bf


System errors:
=============
Error: (12/05/2013 04:18:35 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (12/05/2013 03:12:26 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (12/05/2013 01:27:07 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (12/04/2013 00:18:03 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (12/04/2013 01:58:30 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (12/04/2013 01:58:30 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (12/04/2013 00:29:11 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (12/04/2013 00:28:47 AM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (12/03/2013 09:37:52 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (12/03/2013 09:13:15 PM) (Source: Service Control Manager) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================
Error: (12/03/2013 04:12:36 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

Error: (12/03/2013 02:25:58 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NIMR25FZ\esetsmartinstaller_enu.exe

Error: (12/02/2013 03:26:04 PM) (Source: Application Hang)(User: )
Description: NOTEPAD.EXE6.1.7600.163858fc01ceef6a64bd418b2C:\Windows\system32\NOTEPAD.EXEa91bfa3e-5b5d-11e3-b955-002618d6a2bf


==================== Memory info ===========================

Percentage of memory in use: 33%
Total physical RAM: 4095.12 MB
Available physical RAM: 2708.32 MB
Total Pagefile: 8188.41 MB
Available Pagefile: 6182.45 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:272.61 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: DACBA7AD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Du, hab ne Frage, habe eben mal nachgeforscht. Würde gerne Probieren ob es so funktioniert wie in dem Video beschrieben:
Zitat:

hxxp://www.youtube.com/watch?v=KMjtqfy8dUY
Wenn du sagst ja das ist eine Idee, könntest du mir dann bitte kurz erklären wie ich in den "Save Mode" komme, wie in dem Video :)

Lg

Chiara

cosinus 06.12.2013 16:01

Das Zeug ist bei dir aber auch noch im IE aktiv oder nicht.
Und wir haben über Systemlook keine Objekte mehr mit Nationzoom in der Registry finden können.

Wenn du die Anleitung unbedingt probieren willst, dann mach es.




Abgesicherter Modus zur Bereinigung
  • Windows mit F8-Taste beim Start in den abgesicherten Modus bringen.
  • Starte den Rechner in den abgesicherten Modus mit Netzwerktreibern:

    Windows im abgesicherten Modusstarten

Sigrowon 06.12.2013 19:07

Nein nein, stimmt du hast recht. Ich sollte ja EIGENTLICH nichts mehr von Nation Zoom auf dem PC haben.

Gut dann bringt das ja garnüscht.

Was nu, hat dir das FRST log und das Addition Log was gebracht?

cosinus 06.12.2013 22:23

Nein, nix mehr von nationzoom oder andere Auffälligkeiten zu sehen.
Hast du denn wirklich immer noch nationzoom drin :confused:

Sigrowon 07.12.2013 02:42

Also ich habe nach wie vor Nation Zoom als Startseite. Wenn du magst mach ich dir nen Screenshot oder nen Video mit meim Handy als Beweis :)

cosinus 07.12.2013 15:45

Erstell dir mal über Systemsteuerung / Benutzerkonten ein neues Windows-Benutzerkonto und teste damit was Nationzoom angeht.

Sigrowon 07.12.2013 16:11

Ist erstellt und es ist bei meinem IE auch wieder alles normal. aber bei Google Chrome ist Nation Zoome nach wie vor vorhanden. hm

bin auch gerade mit meinem neuen Benutzerkonto hier drin.

cosinus 07.12.2013 16:20

Dann seh ich keine Möglichkeit das Ding mehr zu entfernen.
adwCleaner, JRT und der Avast Browser Cleanup finden nichts, auch systemlook findet rein garnix mehr wenn man nach nationzoom sucht und FRST zeigt ebenfalls NIX an

Mach mal ein Log mit OTL, eigentlich wollten wir das Tool nicht mehr verwenden, aber es funktioniert noch:

OTL
  • Download => OTL.exe bitte auf den Desktop, starten per Doppelklick
  • Windows Vista/7/8: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen
  • Setze oben mittig den Haken bei Scanne alle Benutzer
  • Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output
  • Unter Extra Registry, wähle bitte Use SafeList
  • Klicke nun auf Run Scan links oben
  • Wenn der Scan beendet wurde werden 2 Logfiles erstellt
  • Poste die Logfiles hier in CODE-Tags in den Thread.

Sigrowon 07.12.2013 16:21

Egal auf welches Benutzerkonto oder auf mein Neues oder Altes?

cosinus 07.12.2013 16:23

Ist im Prinzip egal, da du ja den Haken bei "Scanne alle Benutzer" setzen sollst.
Mach das aber erstmal bei deinem alten User, mit dem haben wir ja bisher auch immer die Scans gemacht.

Sigrowon 07.12.2013 16:44

Ok bei dem OTL.exe auf das ich bei deinem Kommentar klicken konnte, steht das ich jeweils einen Haken in "LOP Prüfung" und "Purity Prüfung" machen soll. Da du mir das nicht angegeben hast, frag ich lieber, soll ich die Haken da rein machen oder draußen lassen?

cosinus 07.12.2013 16:45

Ja mach die mal rein die Haken

Sigrowon 07.12.2013 16:57

OTL.Txt Log:

Code:

OTL logfile created on: 07.12.2013 16:47:59 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\PC\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,72 Gb Available Physical Memory | 67,93% Memory free
8,00 Gb Paging File | 6,12 Gb Available in Paging File | 76,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 272,31 Gb Free Space | 58,48% Space Free | Partition Type: NTFS
 
Computer Name: ---- | User Name: PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\PC\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
 
 
========== Modules (No Company Name) ==========
 
MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (LMIGuardianSvc) -- C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (OverwolfUpdaterService) -- C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe (Overwolf Ltd)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (TFsExDisk) -- C:\Windows\SysNative\drivers\TFsExDisk.sys (Teruten Inc)
DRV:64bit: - (dgderdrv) -- C:\Windows\SysNative\drivers\dgderdrv.sys (Devguru Co., Ltd)
DRV:64bit: - (sscemdm) -- C:\Windows\SysNative\drivers\sscemdm.sys (MCCI Corporation)
DRV:64bit: - (ssceserd) -- C:\Windows\SysNative\drivers\ssceserd.sys (MCCI Corporation)
DRV:64bit: - (sscebus) -- C:\Windows\SysNative\drivers\sscebus.sys (MCCI Corporation)
DRV:64bit: - (sscemdfl) -- C:\Windows\SysNative\drivers\sscemdfl.sys (MCCI Corporation)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (KMWDFILTER) -- C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows (R) Codename Longhorn DDK provider)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (Lycosa) -- C:\Windows\SysNative\drivers\Lycosa.sys (Razer USA Ltd.)
DRV - (TFsExDisk) -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys (Teruten Inc)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
 
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
 
IE - HKU\S-1-5-21-117103499-559527324-418011613-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-117103499-559527324-418011613-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
IE - HKU\S-1-5-21-117103499-559527324-418011613-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-117103499-559527324-418011613-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-117103499-559527324-418011613-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKU\S-1-5-21-117103499-559527324-418011613-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
 
 
[2013.12.01 21:16:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\PC\AppData\Roaming\mozilla\Firefox\Profiles\extensions
[2013.10.09 03:13:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\PC\AppData\Roaming\mozilla\Firefox\Profiles\extensions\extensions
[2013.06.26 18:40:28 | 000,228,503 | ---- | M] () (No name found) -- C:\Users\PC\AppData\Roaming\mozilla\firefox\profiles\extensions\ftd@ftd.com.xpi
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U17 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Uplay PC (Enabled) = C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\PC\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Java Deployment Toolkit 7.0.170.2 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Colorfull Sun Set = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\iknflcjkkahjgichcidlfcalplplegii\1_0\
CHR - Extension: Google Wallet = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Google Mail = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-117103499-559527324-418011613-1000\..\Toolbar\WebBrowser: (no name) - {434D452D-5637-006A-76A7-7A786E7484D7} - No CLSID value found.
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Programme\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Programme\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-117103499-559527324-418011613-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-117103499-559527324-418011613-1000\..Trusted Domains: clonewarsadventures.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-117103499-559527324-418011613-1000\..Trusted Domains: freerealms.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-117103499-559527324-418011613-1000\..Trusted Domains: soe.com ([]* in Vertrauenswürdige Sites)
O15 - HKU\S-1-5-21-117103499-559527324-418011613-1000\..Trusted Domains: sony.com ([]* in Vertrauenswürdige Sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FCC68DFC-46FB-4C8C-B4EF-3FCC5764EAD5}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) -  File not found
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2a8763ce-c1a6-11df-9d01-002618d6a2bf}\Shell - "" = AutoRun
O33 - MountPoints2\{2a8763ce-c1a6-11df-9d01-002618d6a2bf}\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\{4d126ea1-d5e6-11df-b593-002618d6a2bf}\Shell - "" = AutoRun
O33 - MountPoints2\{4d126ea1-d5e6-11df-b593-002618d6a2bf}\Shell\AutoRun\command - "" = G:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2013.12.07 16:39:42 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\PC\Desktop\OTL.exe
[2013.12.06 14:04:51 | 001,925,820 | ---- | C] (Farbar) -- C:\Users\PC\Desktop\FRST64.exe
[2013.12.05 14:49:44 | 002,753,344 | ---- | C] (AVAST Software) -- C:\Users\PC\Desktop\avast-browser-cleanup_90.exe
[2013.12.04 00:28:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013.12.04 00:28:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2013.12.03 21:11:22 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\PC\Desktop\TFC.exe
[2013.12.02 17:07:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013.12.02 16:58:29 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013.12.02 16:58:26 | 000,000,000 | ---D | C] -- C:\Users\PC\Desktop\mbar
[2013.12.02 16:56:05 | 012,576,792 | ---- | C] (Malwarebytes Corp.) -- C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
[2013.12.01 22:11:58 | 000,000,000 | ---D | C] -- C:\FRST
[2013.12.01 21:28:05 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013.12.01 21:27:05 | 001,034,531 | ---- | C] (Thisisu) -- C:\Users\PC\Desktop\JRT.exe
[2013.12.01 21:12:34 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.12.01 16:58:19 | 000,000,000 | ---D | C] -- C:\Users\PC\AppData\Roaming\Malwarebytes
[2013.12.01 16:57:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.12.01 16:57:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.12.01 16:57:51 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.12.01 16:57:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.12.01 16:51:21 | 000,000,000 | ---D | C] -- C:\Users\PC\Desktop\rkill
[2013.12.01 15:43:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013.12.01 15:43:22 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.12.01 15:43:15 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.12.01 15:43:15 | 000,174,504 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.12.01 15:43:15 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.12.01 15:43:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013.12.01 15:11:19 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013.11.26 03:09:22 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2013.11.26 03:05:25 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013.11.26 03:05:25 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013.11.26 03:05:19 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013.11.26 03:05:19 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.11.26 03:05:19 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013.11.26 03:05:19 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013.11.26 03:05:19 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.11.26 03:05:18 | 001,926,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.11.26 03:05:18 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013.11.26 03:05:18 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013.11.26 03:05:18 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013.11.26 03:05:18 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013.11.26 03:05:18 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.11.26 03:05:18 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013.11.26 03:05:18 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013.11.26 03:05:18 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013.11.26 03:05:18 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.11.26 03:05:18 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013.11.26 03:05:18 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013.11.26 03:05:18 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.11.26 03:05:18 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013.11.26 03:05:18 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.11.26 03:05:18 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013.11.26 03:05:17 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.11.26 03:05:17 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013.11.26 03:05:17 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013.11.26 03:05:17 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013.11.26 03:05:17 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.11.26 03:05:17 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013.11.26 03:05:17 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.11.26 03:05:17 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013.11.26 03:05:17 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013.11.26 03:05:17 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013.11.26 03:05:17 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013.11.26 03:05:17 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013.11.26 03:05:17 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013.11.26 03:05:16 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013.11.26 03:05:16 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013.11.26 03:05:16 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013.11.26 03:05:16 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013.11.26 03:05:16 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.11.26 03:05:16 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013.11.26 03:05:15 | 005,765,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.11.26 03:05:15 | 001,993,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.11.26 03:05:15 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013.11.26 03:05:15 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013.11.26 03:05:15 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013.11.26 03:05:15 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.11.26 03:05:15 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013.11.26 03:05:15 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.11.26 03:05:15 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.11.26 03:05:15 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013.11.26 03:05:15 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013.11.26 03:05:15 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013.11.26 03:05:15 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.11.26 03:05:15 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.11.26 03:05:15 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013.11.26 03:05:15 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013.11.26 03:05:15 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013.11.26 03:05:15 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.11.26 03:05:15 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.11.26 03:05:15 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013.11.26 03:05:15 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013.11.26 03:05:15 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.11.26 03:05:15 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013.11.26 03:05:15 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013.11.26 03:05:15 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.11.26 03:05:15 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013.11.26 03:05:15 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013.11.26 03:05:15 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.11.26 03:05:15 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013.11.26 03:05:14 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.11.26 03:05:14 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013.11.26 03:05:14 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013.11.26 03:05:14 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013.11.26 03:05:14 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013.11.26 03:05:14 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013.11.26 03:05:14 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013.11.26 03:05:14 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013.11.26 03:05:14 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013.11.23 01:54:26 | 000,178,800 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2013.11.19 15:10:25 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2013.11.14 02:40:20 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013.11.14 02:40:09 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2013.11.14 02:40:09 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013.11.14 02:40:08 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2013.11.14 02:40:08 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2013.11.14 02:40:08 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2013.11.14 02:40:02 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2013.11.14 02:40:02 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2013.11.14 02:40:02 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2013.11.14 02:40:02 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2013.11.14 02:40:02 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2013.11.14 02:40:00 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2013.11.14 02:39:59 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2013.11.14 02:39:58 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2013.11.14 02:39:58 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2013.11.14 02:39:58 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2013.11.07 22:06:00 | 000,000,000 | ---D | C] -- C:\Users\PC\AppData\Local\Deployment
 
========== Files - Modified Within 30 Days ==========
 
[2013.12.07 16:45:00 | 000,001,102 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.12.07 16:44:46 | 000,014,800 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.12.07 16:44:46 | 000,014,800 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.12.07 16:39:43 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\PC\Desktop\OTL.exe
[2013.12.07 16:37:26 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.12.07 16:37:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.12.07 16:36:55 | 3220,529,152 | -HS- | M] () -- C:\hiberfil.sys
[2013.12.07 15:37:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.12.06 14:04:51 | 001,925,820 | ---- | M] (Farbar) -- C:\Users\PC\Desktop\FRST64.exe
[2013.12.05 15:05:26 | 000,286,283 | ---- | M] () -- C:\Users\PC\Desktop\Unbenannt.png
[2013.12.05 14:49:44 | 002,753,344 | ---- | M] (AVAST Software) -- C:\Users\PC\Desktop\avast-browser-cleanup_90.exe
[2013.12.04 00:17:57 | 000,000,565 | ---- | M] () -- C:\Users\PC\Desktop\62681d1386108610-nation-zoom-entfernbar-nationzoom.reg
[2013.12.03 22:31:06 | 000,165,376 | ---- | M] () -- C:\Users\PC\Desktop\SystemLook_x64.exe
[2013.12.03 21:11:23 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\PC\Desktop\TFC.exe
[2013.12.03 12:59:48 | 000,107,416 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013.12.02 17:04:43 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013.12.02 16:56:06 | 012,576,792 | ---- | M] (Malwarebytes Corp.) -- C:\Users\PC\Desktop\mbar-1.07.0.1007.exe
[2013.12.01 21:27:05 | 001,034,531 | ---- | M] (Thisisu) -- C:\Users\PC\Desktop\JRT.exe
[2013.12.01 21:12:25 | 001,110,034 | ---- | M] () -- C:\Users\PC\Desktop\adwcleaner.exe
[2013.12.01 16:57:58 | 000,001,105 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.12.01 15:43:06 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013.12.01 15:43:06 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013.12.01 15:43:06 | 000,174,504 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013.12.01 15:43:06 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013.11.30 14:05:19 | 001,498,742 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.11.30 14:05:19 | 000,654,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.11.30 14:05:19 | 000,616,032 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.11.30 14:05:19 | 000,130,022 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.11.30 14:05:19 | 000,106,412 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.11.30 13:09:38 | 000,039,681 | -HS- | M] () -- C:\Users\PC\Desktop\Folder.jpg
[2013.11.30 13:09:38 | 000,007,329 | -HS- | M] () -- C:\Users\PC\Desktop\AlbumArtSmall.jpg
[2013.11.26 03:05:26 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013.11.26 03:05:25 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013.11.26 03:05:19 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013.11.26 03:05:19 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.11.26 03:05:19 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013.11.26 03:05:19 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013.11.26 03:05:19 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.11.26 03:05:18 | 001,926,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.11.26 03:05:18 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013.11.26 03:05:18 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013.11.26 03:05:18 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013.11.26 03:05:18 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013.11.26 03:05:18 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.11.26 03:05:18 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013.11.26 03:05:18 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013.11.26 03:05:18 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013.11.26 03:05:18 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.11.26 03:05:18 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013.11.26 03:05:18 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013.11.26 03:05:18 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.11.26 03:05:18 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013.11.26 03:05:18 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.11.26 03:05:18 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013.11.26 03:05:18 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.11.26 03:05:17 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.11.26 03:05:17 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013.11.26 03:05:17 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013.11.26 03:05:17 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013.11.26 03:05:17 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.11.26 03:05:17 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013.11.26 03:05:17 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.11.26 03:05:17 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013.11.26 03:05:17 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013.11.26 03:05:17 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013.11.26 03:05:17 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013.11.26 03:05:17 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013.11.26 03:05:17 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013.11.26 03:05:16 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013.11.26 03:05:16 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013.11.26 03:05:16 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013.11.26 03:05:16 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013.11.26 03:05:16 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.11.26 03:05:16 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013.11.26 03:05:15 | 005,765,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.11.26 03:05:15 | 001,993,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.11.26 03:05:15 | 001,228,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013.11.26 03:05:15 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013.11.26 03:05:15 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013.11.26 03:05:15 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.11.26 03:05:15 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013.11.26 03:05:15 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.11.26 03:05:15 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.11.26 03:05:15 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013.11.26 03:05:15 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013.11.26 03:05:15 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013.11.26 03:05:15 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.11.26 03:05:15 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.11.26 03:05:15 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013.11.26 03:05:15 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013.11.26 03:05:15 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013.11.26 03:05:15 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.11.26 03:05:15 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.11.26 03:05:15 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013.11.26 03:05:15 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013.11.26 03:05:15 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.11.26 03:05:15 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013.11.26 03:05:15 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013.11.26 03:05:15 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.11.26 03:05:15 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013.11.26 03:05:15 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013.11.26 03:05:15 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.11.26 03:05:15 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013.11.26 03:05:15 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013.11.26 03:05:14 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.11.26 03:05:14 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013.11.26 03:05:14 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013.11.26 03:05:14 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013.11.26 03:05:14 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013.11.26 03:05:14 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013.11.26 03:05:14 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013.11.26 03:05:14 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013.11.26 03:05:14 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013.11.23 01:54:26 | 000,178,800 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2013.11.19 13:35:27 | 000,132,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013.11.19 13:35:27 | 000,083,160 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013.11.19 13:35:27 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013.11.15 14:54:17 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.11.15 14:54:17 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
 
========== Files Created - No Company Name ==========
 
[2013.12.05 15:05:26 | 000,286,283 | ---- | C] () -- C:\Users\PC\Desktop\Unbenannt.png
[2013.12.04 00:17:57 | 000,000,565 | ---- | C] () -- C:\Users\PC\Desktop\62681d1386108610-nation-zoom-entfernbar-nationzoom.reg
[2013.12.03 22:31:06 | 000,165,376 | ---- | C] () -- C:\Users\PC\Desktop\SystemLook_x64.exe
[2013.12.01 21:12:25 | 001,110,034 | ---- | C] () -- C:\Users\PC\Desktop\adwcleaner.exe
[2013.12.01 16:57:58 | 000,001,105 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013.11.29 16:59:06 | 000,039,681 | -HS- | C] () -- C:\Users\PC\Desktop\Folder.jpg
[2013.11.29 16:59:06 | 000,007,329 | -HS- | C] () -- C:\Users\PC\Desktop\AlbumArtSmall.jpg
[2013.11.26 03:05:18 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.11.26 03:05:15 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012.12.19 20:52:22 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.12.19 20:52:22 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011.12.25 20:08:23 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011.12.25 20:08:21 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
 
========== ZeroAccess Check ==========
 
[2009.07.14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2013.12.07 16:33:33 | 000,000,000 | ---D | M] -- C:\Users\Chiara\AppData\Roaming\LolClient
[2013.12.07 16:34:24 | 000,000,000 | ---D | M] -- C:\Users\Chiara\AppData\Roaming\TS3Client
[2013.11.22 14:01:11 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\.minecraft
[2010.10.12 11:18:09 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\DAEMON Tools Lite
[2012.11.13 22:43:08 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\DVDVideoSoft
[2013.07.30 19:27:54 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\ITTerritory
[2010.10.12 11:28:43 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\Leadertech
[2012.10.30 23:27:46 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\LolClient
[2010.10.26 15:34:03 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\Need for Speed World
[2010.09.09 16:13:49 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\OpenOffice.org
[2011.12.25 20:08:20 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\PunkBuster
[2012.03.29 08:15:57 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\Samsung
[2013.12.07 16:02:44 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\TS3Client
[2013.06.15 14:55:01 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\ts3overlay
[2013.05.10 15:03:56 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\Unity
[2012.10.05 16:44:57 | 000,000,000 | ---D | M] -- C:\Users\PC\AppData\Roaming\Windows Live Writer
 
========== Purity Check ==========
 
 

< End of report >




Exrtas.Txt Log

Code:

OTL Extras logfile created on: 07.12.2013 16:47:59 - Run 1
OTL by OldTimer - Version 3.2.69.0    Folder = C:\Users\PC\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
4,00 Gb Total Physical Memory | 2,72 Gb Available Physical Memory | 67,93% Memory free
8,00 Gb Paging File | 6,12 Gb Available in Paging File | 76,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465,66 Gb Total Space | 272,31 Gb Free Space | 58,48% Space Free | Partition Type: NTFS
 
Computer Name: ---- | User Name: PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.reg [@ = regfile] -- regedit.exe "%1"
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [open] -- regedit.exe "%1"
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{087BF802-4E3E-4942-8485-73E8130B6A27}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0EA1582A-3387-4A9D-8433-C715E864CBB7}" = rport=138 | protocol=17 | dir=out | app=system |
"{18E16507-68CD-42C6-80F3-4B2703468E1C}" = rport=445 | protocol=6 | dir=out | app=system |
"{34611FDA-6B22-4475-B5D4-84BB13143206}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{37C0AED1-7271-4AF6-9778-098137098B83}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{498A97D8-31B9-4165-87AD-1072D008BB15}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4A594FAF-51C2-47DC-81DC-2AF80317FDD9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50E9CBCC-E251-44FA-8EFD-E1FDABCDC351}" = lport=138 | protocol=17 | dir=in | app=system |
"{5211E02E-0699-48F5-8CCF-63C527A4B547}" = lport=137 | protocol=17 | dir=in | app=system |
"{547E6D5E-8E39-4329-AC8B-10D45BFEAEA7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6266EA6C-EB18-4B28-B3B0-B95930CDAEE9}" = rport=10243 | protocol=6 | dir=out | app=system |
"{632C5165-AA78-4B1D-B5A5-BED5FA958334}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{72C22FEB-06A6-4B10-ADA2-8EA388CF2A14}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{76BCF304-37EB-4218-96A2-2355B441FD69}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{84BA69B1-A23F-4F95-9281-E72889341ADC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{8BA24E30-E6F7-4FD6-B325-0384FC298EE8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8EF1625A-E41F-4FF8-B3E7-CD7470D244FF}" = rport=139 | protocol=6 | dir=out | app=system |
"{938EDA4A-C005-44AA-A394-42C069C2543B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{ACFEF2F5-43DB-4B00-B13A-C61278BB0F15}" = lport=445 | protocol=6 | dir=in | app=system |
"{BB60BDD7-EE61-4632-A0D4-15CBEE6132D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C21C864B-FAA2-48A2-86A6-15E66ECAF7B2}" = rport=137 | protocol=17 | dir=out | app=system |
"{D4FEE3B7-5488-4C97-AD9D-737D5CC92B4F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F9BA43E7-EC3E-4D3D-A016-754521DFD82F}" = lport=139 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01460DD8-EA77-40D9-9D58-D4A1A1927E12}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\f1 2010\f1_2010_game.exe |
"{0165CA65-8B82-48B6-A9C8-84A8E756EA22}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{024A2578-5B2C-4791-9149-E9E6EE679109}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{067C2AF0-181B-4FA6-AE7D-69C035196130}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{081A213A-9AD5-466C-B0C3-B6DB574ADB69}" = protocol=58 | dir=in | app=system |
"{12C26CF4-A127-4297-A6A6-DA3C877F4498}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{196EC933-E47F-4AF4-830D-D42154796138}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1D2A8E08-A64E-4420-BABF-5964AA9ED606}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1DC7A64C-21E3-45AB-BB9D-D2576220D125}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe |
"{2F60A24E-39E1-4D28-AE43-594DEAF02ADA}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{30B313E1-136C-4CCB-A92A-E216183B4E99}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\assassinscreedbrotherhood.exe |
"{3A5CB73D-DEA6-4A70-8F37-D1E2DA2FE433}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\bionic commando\support\cap1-0101.exe |
"{3A980085-D3BF-43EE-8E49-1B53AD50EE82}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{47B54E39-2B5A-45BB-A510-46C90C281717}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\f1 2010\f1_2010_game.exe |
"{5268E701-B729-4886-96CC-40033C7DE5DE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{543ADC56-7351-48ED-8604-5B80CCA99F79}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{54FD7E60-F75E-41F0-B16D-7AEBB2097B0B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{59F30376-51AB-4AC9-8257-A4EDD876CAE5}" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"{5C68CC7E-081C-4259-99BB-C8E063E7E903}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\acbmp.exe |
"{62071E0E-37CC-44DD-93DF-14F15DE57C58}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{65AF7193-D45D-4761-A695-A105536D8AD8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{696A1ED7-D246-43A5-BB80-D6060314BFDA}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{7C6BC617-FADB-4731-810F-C215611D0F32}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{80CF90A9-1E1D-42AC-AEB7-FC3529B2A3BD}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{83E04A05-6BA3-4705-A126-8ABB0D12DD24}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\bionic commando\support\cap1-0101.exe |
"{8952F94C-A248-4270-AED1-0CDA5822B6CC}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\uplaybrowser.exe |
"{89F9931A-49D7-4B93-B460-A747A7E4ECBA}" = protocol=6 | dir=in | app=c:\programdata\esafe\egdpsvc.exe |
"{8BD7877B-A4F3-4A28-BFBF-4B433B614B1B}" = protocol=17 | dir=in | app=c:\program files (x86)\capcom\bionic commando\bionic_commando.exe |
"{93021B91-61EF-4314-80BB-38DE5B2876B7}" = dir=out | app=%userprofile%\desktop\minecraft.exe |
"{9B60FC40-6A13-4B39-8B80-908B010B1FA4}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{9BA316E2-6D40-4C51-A543-6FFC94489F89}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe |
"{9CD817B8-6599-4DDC-B549-DD44F8B16624}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9D88C0AE-08B5-4727-BE61-6F0A43828F2C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A08466C9-8C53-48B9-9F90-23D84A6A4007}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\assassinscreedbrotherhood.exe |
"{A6F3FDE0-2E95-4E25-95AD-5507DF5F8991}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{A974253D-E158-4AB2-B54A-A379F5574CDF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{AB710DD2-C0D1-4B7B-8B59-B3CC7428E4D6}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B4713ED4-2552-4CF8-86E4-CBF7A047B81A}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"{B52F3A91-9D5A-4077-9C62-D50DA8852DCC}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B5574168-668A-42AC-8204-4C4F40F3B55E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{B6A7DDCB-2ECC-4EF1-9B6C-0BCD237BC9CB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B95AE5FF-846F-4758-9824-174727F39D08}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\acbmp.exe |
"{BB9EFBCF-4E65-499D-AA26-7F754312D630}" = protocol=6 | dir=out | app=system |
"{BCBFC10A-8C3A-4AEA-B5C7-BBC6D3D1A9FF}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"{C120C843-E5AE-4B9E-8F35-1744F45C15D4}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{C238F2A4-669F-4256-890D-BC079C819414}" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"{C6DAD2BF-A49A-410F-A394-F491F731A2C0}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{C71A705E-FA11-48B4-828F-12F095613CCD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CA31D0B8-779F-4596-82A3-45E9DACC0EE6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CC6C4400-1535-42B1-A7BC-D7B2EF73CB2E}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\uplaybrowser.exe |
"{CF825A25-C892-4BB6-9056-9985D5BD64B2}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{D51769C0-D4B0-4AD2-AC77-24F562972D8D}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{DA6A04C0-92AF-4330-BBD4-DFAE3148F87E}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{DC090AE6-1613-4025-B4C0-FEB1E723C5C2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DEB625E5-80F4-41F2-BCEA-B3F18E0C96CF}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{E09468E8-71D7-414E-93BA-0759680A7DCA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EAD5A031-977C-43FE-BC0E-C8388B4C3F4A}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"{ECD746C2-1804-4C70-B1F7-8CA2CACFDD07}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EDE063D0-4B2B-4B4B-A7BD-1BD3D6F8EB2B}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"{F297CEDC-D73D-483A-AD01-E65B2944DE79}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{F6663309-2C52-4062-AEF2-CC2BEC4F9F55}" = protocol=6 | dir=in | app=c:\program files (x86)\capcom\bionic commando\bionic_commando.exe |
"TCP Query User{0832FE70-F7CC-4E4C-A562-9569133F52D1}C:\program files (x86)\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe |
"TCP Query User{0B08F7F3-E16D-47FF-8DBC-8E1F843B27AB}C:\users\pc\desktop\urbanterror\iourbanterror.exe" = protocol=6 | dir=in | app=c:\users\pc\desktop\urbanterror\iourbanterror.exe |
"TCP Query User{26D141BF-D3CC-4852-BCBE-1B9A67E62C1C}C:\program files (x86)\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe |
"TCP Query User{3258B9E6-9B72-441D-BC5B-0984F6C7CE82}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{39F5D870-A43F-4ABE-B1D6-A91FADE2AEFB}C:\program files (x86)\ea sports\fifa 11\game\fifa.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ea sports\fifa 11\game\fifa.exe |
"TCP Query User{43D507A5-4148-4AD3-8B78-BD06A3ED8A7B}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe |
"TCP Query User{4DA83B8B-3FB1-499D-A9A1-24225684CF78}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"TCP Query User{5197BC85-FD0C-49E5-ACD1-4733D0B2A668}C:\program files (x86)\codemasters\grid\grid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"TCP Query User{6482DF87-6D29-405D-B850-9E9BA5511EF6}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=6 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe |
"TCP Query User{6B7EAAD2-B391-43C8-95FA-F9446D9E9846}C:\program files (x86)\empire interactive\flatout2\flatout2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\empire interactive\flatout2\flatout2.exe |
"TCP Query User{6E415BF9-FB6E-4EF8-8409-8F1167E3C9C6}C:\program files (x86)\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=c:\program files (x86)\counter-strike 1.6\hl.exe |
"TCP Query User{81A97E58-3F38-4842-B47B-8B6A3669493C}C:\program files (x86)\counter-strike 1.6\hl.exe" = protocol=6 | dir=in | app=c:\program files (x86)\counter-strike 1.6\hl.exe |
"TCP Query User{9AF70125-2507-4BA6-979B-91599DD9BE71}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{DA13F3EC-AF60-47E1-8AB1-B4656ABE942E}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"UDP Query User{095AAACF-9C25-4FA3-9FE0-E78BD9ACAE30}C:\program files (x86)\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=c:\program files (x86)\counter-strike 1.6\hl.exe |
"UDP Query User{198946A4-CC16-48E2-AD73-2B58192C47F1}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"UDP Query User{396CEDEB-7598-4651-871F-EAB1853463A3}C:\program files (x86)\counter-strike 1.6\hl.exe" = protocol=17 | dir=in | app=c:\program files (x86)\counter-strike 1.6\hl.exe |
"UDP Query User{3ACDFF2F-DE2A-48CA-8079-8C24D38E16B3}C:\program files (x86)\empire interactive\flatout2\flatout2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\empire interactive\flatout2\flatout2.exe |
"UDP Query User{52CD440A-1CCB-41E5-9DAA-B3F7D8C4111A}C:\users\pc\desktop\urbanterror\iourbanterror.exe" = protocol=17 | dir=in | app=c:\users\pc\desktop\urbanterror\iourbanterror.exe |
"UDP Query User{71F42FB1-0EA4-4790-960C-874B788BE34F}C:\programdata\electronic arts\need for speed world\data\nfsw.exe" = protocol=17 | dir=in | app=c:\programdata\electronic arts\need for speed world\data\nfsw.exe |
"UDP Query User{948C395E-3D45-45A4-936B-7875833813AA}C:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed brotherhood\acbsp.exe |
"UDP Query User{97F39BFA-0900-4FC5-854C-F6B29A0CAA87}C:\program files (x86)\codemasters\grid\grid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\grid\grid.exe |
"UDP Query User{BB844C81-E248-4027-B001-7B10CA7ECE4C}C:\program files (x86)\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe |
"UDP Query User{BDCD773C-22A2-477E-B29A-93828E0C2195}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
"UDP Query User{C1C7A889-7DE7-4EB8-882E-EBEF278F82D5}C:\program files (x86)\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\warcraft iii\war3.exe |
"UDP Query User{C2EF5D13-CD67-421A-AA6A-F33B6B8934B6}C:\program files (x86)\ea sports\fifa 11\game\fifa.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ea sports\fifa 11\game\fifa.exe |
"UDP Query User{D5D84368-5629-421B-AC24-8EEC63A62EF2}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"UDP Query User{F91F7158-FFA0-49BB-BB7E-675879FFADEE}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{0E3DAF3D-FF69-345A-A99E-1FED304CA083}" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"{19BDBFE9-0B6A-37F2-80F6-48AFD1EA582D}" = ATI AVIVO64 Codecs
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{2128559D-BBCD-4744-87F0-7C0CD5CFB464}" = Windows Live Family Safety
"{38145F6E-041F-69AE-59B4-37CA06F33D67}" = ccc-utility64
"{53A19094-2C04-A9B9-7309-3E92152D4845}" = AMD Catalyst Install Manager
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6245BC35-F4BE-1995-BB2E-7847D758504E}" = ATI Problem Report Wizard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
"{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile DEU Language Pack" = Microsoft .NET Framework 4 Client Profile DEU Language Pack
"WinRAR archiver" = WinRAR archiver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion
"{04B45310-A5FE-4425-BFCA-1A6D8920DE74}" = OpenOffice.org 3.0
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EA7F867-D362-2E76-77B8-9396B9245B66}" = CCC Help Finnish
"{16CF7BB1-672E-BC9F-E5CE-5854112E2C35}" = CCC Help Japanese
"{1700FEE9-EB3D-35C8-28ED-0BE7860BA710}" = CCC Help Portuguese
"{190CCE82-4867-B16E-F96A-3F21A058ED9B}" = CCC Help Korean
"{1BA1DBDC-5431-46FD-A66F-A17EB1C439EE}" = Windows Live Messenger
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 45
"{280E47E4-4EFB-D268-B042-F793EB2D8E4E}" = CCC Help Italian
"{2A7D1710-31EB-3B24-BF52-1755099CE2C0}" = CCC Help Chinese Traditional
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
"{3A6B7222-A439-1BBE-58DD-76D1B632EEA8}" = CCC Help Turkish
"{3AC02D87-274C-BAE6-ACFA-B64B714A0083}" = Catalyst Control Center Core Implementation
"{3F7BBDE9-79B4-4E77-B878-7E6B36F3A766}" = CCC Help French
"{48615A7B-F026-4F62-A3F1-49001B8E21CB}" = Overwolf
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.9
"{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
"{605DDD7B-1521-423B-A654-E9A963573D82}" = Catalyst Control Center Graphics Light
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{6CF37701-7E02-873F-9543-183116AC905C}" = CCC Help Danish
"{6F1891DD-CEFE-4349-CFB3-172ED6C94A18}" = ccc-core-static
"{75CFBC87-1B8A-2DA8-4575-F50BD61E9368}" = Catalyst Control Center Graphics Previews Vista
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A587AD7-EDEF-BD63-C054-5E5FBC47105C}" = CCC Help Russian
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7E641E46-81DB-4D1D-906A-48342523051C}" = FlatOut2
"{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1" = PDF24 Creator 5.2.0
"{82130914-DF2E-4AD3-BC73-5DC2A180924C}" = CCC Help Thai
"{82E73E8D-E1E7-45A4-A311-6D31492AA913}_is1" = AION Free-to-Play Version 1.0
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{88F066D3-5662-95C4-AE4E-D39174ED8F43}" = CCC Help Dutch
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C49AB5C-A457-DEF0-0436-AADEB2062296}" = Catalyst Control Center Graphics Previews Common
"{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1" = Gameforge Live 1.9.0 "Legend"
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DFC3864-1C52-E552-B039-09AE59F35801}" = CCC Help Swedish
"{9FCBD98D-F8B3-6ECC-5293-9C28817E3269}" = Catalyst Control Center InstallProxy
"{A43C0289-EE84-FEC7-595D-A6F8489B2C44}" = CCC Help Polish
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A77B5C97-77AD-54E9-FB97-52F0A9EF72AC}" = CCC Help Spanish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA2E2EA3-D999-D8A0-7C6F-DF451DF9135C}" = CCC Help Greek
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.8) - Deutsch
"{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
"{B08201F3-AE80-58C6-E832-7DF5B87795FB}" = CCC Help Hungarian
"{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
"{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
"{B569ACCD-8F95-53CE-AF51-70CB8EA34656}" = CCC Help German
"{B9BDD486-EF12-B0BC-1C88-B3046092A8BD}" = CCC Help Chinese Standard
"{BE4BA698-8533-4F77-9559-C7F3F78C0B05}" = Assassin's Creed Brotherhood
"{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
"{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
"{C54AE051-35E6-A421-164B-FDF2C3A8EE4E}" = Catalyst Control Center Graphics Full Existing
"{CA5290FD-1C71-D40D-E0B9-D44FF41007FA}" = Catalyst Control Center HydraVision Full
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CED2C398-A03E-A70D-6894-78C79C501296}" = CCC Help Czech
"{CF929EEB-CE39-4F06-B1BF-F51FC617A2B2}" = Catalyst Control Center - Branding
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.4 Game
"{D3CF1241-B6B9-C0F1-8D69-96A01360A07A}" = Catalyst Control Center Graphics Full New
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D7410A39-66CA-C554-CB1D-EB53A6B8A289}" = HydraVision
"{D84F41A8-33E6-402A-8DD6-D2244235BCB8}" = LogMeIn Hamachi
"{DD7851B2-C277-204C-C414-797649FBFCAA}" = CCC Help English
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
"{E4F4CB1F-5319-EECB-F758-A651DAF87D02}" = Catalyst Control Center Localization All
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F175273F-6F15-23E2-1DF9-D2A8DD477502}" = CCC Help Norwegian
"{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Avira AntiVir Desktop" = Avira Free Antivirus
"Drachenkrieg_is1" = Drachenkrieg (with media and plugins), version 1.1.27
"Free YouTube Download_is1" = Free YouTube Download version 3.1.39.1015
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.34.1015
"Google Chrome" = Google Chrome
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version 1.75.0.1300
"OpenAL" = OpenAL
"PunkBusterSvc" = PunkBuster Services
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Warcraft III" = Warcraft III
"WAV To MP3_is1" = WAV To MP3 V2
"WinLiveSuite" = Windows Live Essentials
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-117103499-559527324-418011613-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"soe-PlanetSide 2 PSG" = PlanetSide 2
"UnityWebPlayer" = Unity Web Player
"Warcraft III" = Warcraft III: All Products
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 02.12.2013 10:26:04 | Computer Name = ---- | Source = Application Hang | ID = 1002
Description = Programm NOTEPAD.EXE, Version 6.1.7600.16385 kann nicht mehr unter
 Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf
in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem
 zu suchen.    Prozess-ID: 8fc    Startzeit: 01ceef6a64bd418b    Endzeit: 2    Anwendungspfad: C:\Windows\system32\NOTEPAD.EXE

Berichts-ID:
 a91bfa3e-5b5d-11e3-b955-002618d6a2bf 
 
Error - 03.12.2013 09:25:58 | Computer Name = ---- | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Users\PC\AppData\Local\Microsoft\Windows\Temporary
 Internet Files\Content.IE5\NIMR25FZ\esetsmartinstaller_enu.exe". Fehler in  Manifest-
 oder Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
Error - 03.12.2013 11:12:36 | Computer Name = ---- | Source = SideBySide | ID = 16842832
Description = Fehler beim Generieren des Aktivierungskontexts für "C:\Program Files
 (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe". Fehler in  Manifest- oder
 Richtliniendatei "" in Zeile .  Eine für die Anwendung erforderliche Komponentenversion
 steht in Konflikt mit  einer anderen, bereits aktiven Komponentenversion.  In Konflikt
 stehende Komponenten:.  Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente
 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
 
[ System Events ]
Error - 03.12.2013 19:28:47 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
Error - 03.12.2013 19:29:11 | Computer Name = ---- | Source = Service Control Manager | ID = 7030
Description = Der Dienst "LogMeIn Hamachi Tunneling Engine" ist als interaktiver
 Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive
 Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
 
Error - 03.12.2013 20:58:30 | Computer Name = ---- | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus
 lautet: 252.
 
Error - 03.12.2013 20:58:30 | Computer Name = ---- | Source = Schannel | ID = 36888
Description = Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus
 lautet: 252.
 
Error - 04.12.2013 07:18:03 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
Error - 05.12.2013 08:27:07 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
Error - 05.12.2013 10:12:26 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
Error - 05.12.2013 11:18:35 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
Error - 07.12.2013 08:01:01 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
Error - 07.12.2013 11:38:22 | Computer Name = ---- | Source = DCOM | ID = 10016
Description =
 
 
< End of report >


cosinus 07.12.2013 17:18

Nix von Nationzoom zu sehen....

Sigrowon 07.12.2013 17:39

D.h. ganz klar, hoffnungsloser Fall?

Dann meine letzte Frage, wenn ich nichts mehr von N. Zoom auf dem PC habe, es auch bei einem Benutzerkontenwechsel auf Google Chrome ist, doch nicht bei Internet Explorer, ist der Virus den trotzdem schädlich? Also kann er mir Nachteile bringen, z.B: Dateien wie Bilder oder Fotos von meinem PC löschen oder sonst was? Oder behindert er nur die Startseite, damit könnte ich leben.

cosinus 07.12.2013 18:15

Für Firefox und Chrome hätte ich noch diese Idee: beide Browser deinstallieren, frische Setups von den beiden von mozilla und Google runterladen und neu installieren und testen...

cosinus 07.12.2013 18:24

Falls das auch nicht hilft, hab grad was von meinen Kollegen gesehen, ein Tool, das nationzoom hoffentlich vollständig erkennt: http://loaris.com/download.php?trojanremover

Sigrowon 08.12.2013 04:10

ok versuche ich Morgen bzw. später aus.

Wie gesagt, das Angebot steht noch^^ wenn das funktioniert gibt's geküsste Füße :D

Lg

Chiara :zunge::lach:

Sigrowon 10.12.2013 13:46

Sieht nicht so aus als ob es was gefunden hat mit Nation Zoom. Nur Sachen die ich manchmal benutzt habe hat es gelöscht :D

LTR Logfile:

Code:

Loaris Trojan Remover v.1.3.0.3
Report file date: 10.12.2013 13:04:21
Last update : 10.12.2013 13:04:05

Scanning for 1449306 virus strains and unwanted programs.

Licensed:        UNREGISTERED
Windows version:  Windows 7 Home Premium (version 6.1)
Username:        PC
Computer name:    ----

Starting the file scan:

Standard Scan started
Current IE path: iexplore.exe
Recommended IE path: c:\program files\internet explorer\iexplore.exe
Internet Explorer path - fixed
Hijack.EnableLUA - fixed
Startup objects checked
BHO plugins checked
Services checked
ActiveX objects checked
Files checked
Scanning process...
----- C:\Users\PC\AppData\Local\Temp\is1104650885\10107539_stp\wajam_validate.exe ---- General
        HW32.CDB.99d9.vp!f0
        MD5: 46F5C497F96E733176B010FF0EE56DE3:11264
        SUBS: Win32 Console
        FUZ: 192:YucR8gniwHla15UMi9q9bEBOrwic65Is6UqcnZuTgtnH3faOdaD7G1IpI:kRfniwHlZRBMKbKu+nXf5IS1AX
        PE: x86
        EPSEC: 1
        EPRVA: 000092B0
        IBASE: 00400000
        EP:60BE007040008DBE00A0FFFF5783CDFFEB109090909090908A064688074701DB75078B1E83EEFC11DB72EDB80100000001DB75078B1E83EEFC11DB11C001DB73EF
        SEC:
                UPX0:E0000080:00000000000000000000000000000000:0
                UPX1:E0000040:EFB528484CCCF5F73D60541B9440F0FC:9728
                UPX2:C0000040:E3FBD20EC5DE98527D0F1DD86275A416:512


----- C:\Users\PC\AppData\Local\Temp\is1104650885\3944985_stp\wajam_validate.exe ---- General
        HW32.CDB.99d9.vp!f0
        MD5: 46F5C497F96E733176B010FF0EE56DE3:11264
        SUBS: Win32 Console
        FUZ: 192:YucR8gniwHla15UMi9q9bEBOrwic65Is6UqcnZuTgtnH3faOdaD7G1IpI:kRfniwHlZRBMKbKu+nXf5IS1AX
        PE: x86
        EPSEC: 1
        EPRVA: 000092B0
        IBASE: 00400000
        EP:60BE007040008DBE00A0FFFF5783CDFFEB109090909090908A064688074701DB75078B1E83EEFC11DB72EDB80100000001DB75078B1E83EEFC11DB11C001DB73EF
        SEC:
                UPX0:E0000080:00000000000000000000000000000000:0
                UPX1:E0000040:EFB528484CCCF5F73D60541B9440F0FC:9728
                UPX2:C0000040:E3FBD20EC5DE98527D0F1DD86275A416:512


----- C:\Users\PC\AppData\Local\Temp\is1104650885\5207654_stp\wajam_validate.exe ---- General
        HW32.CDB.99d9.vp!f0
        MD5: 46F5C497F96E733176B010FF0EE56DE3:11264
        SUBS: Win32 Console
        FUZ: 192:YucR8gniwHla15UMi9q9bEBOrwic65Is6UqcnZuTgtnH3faOdaD7G1IpI:kRfniwHlZRBMKbKu+nXf5IS1AX
        PE: x86
        EPSEC: 1
        EPRVA: 000092B0
        IBASE: 00400000
        EP:60BE007040008DBE00A0FFFF5783CDFFEB109090909090908A064688074701DB75078B1E83EEFC11DB72EDB80100000001DB75078B1E83EEFC11DB11C001DB73EF
        SEC:
                UPX0:E0000080:00000000000000000000000000000000:0
                UPX1:E0000040:EFB528484CCCF5F73D60541B9440F0FC:9728
                UPX2:C0000040:E3FBD20EC5DE98527D0F1DD86275A416:512


----- C:\Users\PC\AppData\Local\Temp\is1104650885\8215764_stp\wajam_validate.exe ---- General
        HW32.CDB.99d9.vp!f0
        MD5: 46F5C497F96E733176B010FF0EE56DE3:11264
        SUBS: Win32 Console
        FUZ: 192:YucR8gniwHla15UMi9q9bEBOrwic65Is6UqcnZuTgtnH3faOdaD7G1IpI:kRfniwHlZRBMKbKu+nXf5IS1AX
        PE: x86
        EPSEC: 1
        EPRVA: 000092B0
        IBASE: 00400000
        EP:60BE007040008DBE00A0FFFF5783CDFFEB109090909090908A064688074701DB75078B1E83EEFC11DB72EDB80100000001DB75078B1E83EEFC11DB11C001DB73EF
        SEC:
                UPX0:E0000080:00000000000000000000000000000000:0
                UPX1:E0000040:EFB528484CCCF5F73D60541B9440F0FC:9728
                UPX2:C0000040:E3FBD20EC5DE98527D0F1DD86275A416:512


----- C:\Users\PC\Desktop\JRT.exe ---- General
        TROJ_GEN.F47V1107.an!L
        ProdVer: 6.0.8
        FileVer:
        Company: Thisisu
        NAC: C8D0CC235CDDCCAC97C0426432703A61:32
        MD5: 86FB5E8D5D1E3E405C46CCBF991E6FD4:1034531
        SUBS: Win32 GUI
        RIC: Win32 GUI:3464
        RFH: 48:ybwJbBSgy+QmWHI45QIepexnvnGXkwnG4nuuIP6nKM:ybuzQmWXQIznuuXpS
        PE: x86
        EPSEC: 0
        EPRVA: 00014DA6
        IBASE: 00400000
        EP:558BEC6AFF68487C410068A04D410064A100000000506489250000000083EC685356578965E833DB895DFC6A02FF152871410059830DC4C84100FF830DC8C84100
        SEC:
                .text:60000020:614622E4762848A87131A09B6D207EF1:87040
                .rdata:40000040:680ECFB8DEFEFA631FA2679A05D047DF:15360
                .data:C0000040:832B3AE16685D72C45DDE5184F8C68C9:5120
                .rsrc:40000040:D0E01EBE65040CD7DCCB8674BC5CC5CF:5120


----- C:\Users\PC\Desktop\Mouseclick, Schneiden - Umwandeln\cbsidlm-cbsi134-Auto_Mouse_Bot-ORG-75683315.exe ---- General
        Win32.Virut.bn.mx!L
        ProdVer: 5, 4, 0, 134
        FileVer: 5, 4, 0, 134
        Name  : CNET Download.com
        Company: CNET Download.com
        NAC: 71BE280D1C00A5DB69310218EEE56939:32
        MD5: C3E04B7E8326EB118113CE175EFA86A9:894600
        SUBS: Win32 GUI
        RIC: Win32 GUI:14224
        RFH: 192:KvgD8j8tGVVYbUeXx5aWcy2fE6n66O+C5V6OON6eiWQ6o8N666WICKHQz95SUgrj:TDHSuZXx5axyKbOQz3O1N
        PE: x86
        EPSEC: 1
        EPRVA: 0020D8D0
        IBASE: 00400000
        EP:60BE009053008DBE0080ECFF57EB0B908A064688074701DB75078B1E83EEFC11DB72EDB80100000001DB75078B1E83EEFC11DB11C001DB730B75288B1E83EEFC11
        SEC:
                UPX0:E0000080:00000000000000000000000000000000:0
                UPX1:E0000040:58CBBA31FFE77D5AC8E0AA65BCF96970:871424
                .rsrc:C0000040:6DFB62490F8D41EFA9A10B06786BAE37:18432


Scan completed

Scan result:        6 detected items
Scan completed in:  Scan completed in 19 minute(s) 51 sec.
Files were scanned:  19397


cosinus 10.12.2013 15:29

Dann kannste den Rechner entweder komplett neu installieren oder warten und hoffen, dass neue Versionen von JRT und adwCleaner auch die "versteckten" Bestandteile von nationzoom findet....

Sigrowon 10.12.2013 15:45

Naja wenn ich alles neu mache ist ja eh alles weg, daher denke ich warte ich lieber und hoffe das was Neues kommt. Woran erkenn ich das? muss ich mir JRT oder so immer wieder neu downloaden oder updatet es sich einfach immer wenn ich es starte oder updaten lasse?

Danke nochmal für alles, schade das es nicht ganz weg ist aber scheinbar ist so ziehmlich das meiste von Nation Zoom von meinem PC weg^^

Vielen dank nochmal dafür. Echt lieb das du die Geduld mit mir hattest.

Man liest sich bestimmt wieder:bussi:

Lg

Chiara :dankeschoen: :abklatsch:

cosinus 10.12.2013 15:54

JRT und adwClaner musst du immer wieder neu runterladen. Mach nochmal bitte nen neuen Scan mit aktuellem Malwarebytes, mit etwas Glück findet der jetzt schon wieder mehr an Nationzoom.

Edit: frisch von meinem Kollegen Argus nen Tipp bekommen :D => http://www.bleepingcomputer.com/down...rtcut-cleaner/

Sigrowon 10.12.2013 18:26

Ahaaaa das ist also Argus mit dem ich geschrieben habe ^^ :D ok danke mach ich.

sc-cleaner Logfile:

Geil endlich glaub ich hat SC-Cleaner es komplett. Sieht jedenfalls danach aus.

Code:

Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
 hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/

Windows Version: Windows 7 Home Premium Service Pack 1
Program started at: 12/10/2013 06:04:26 PM.

Scanning for registry hijacks:

 * No issues found in the Registry.

Searching for Hijacked Shortcuts:

Searching C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\

  * Shortcut Cleaned: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

  * Shortcut Cleaned: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

Searching C:\ProgramData\Microsoft\Windows\Start Menu\

  * Shortcut Cleaned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

Searching C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\

  * Shortcut Cleaned: C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

  * Shortcut Cleaned: C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

  * Shortcut Cleaned: C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

  * Shortcut Cleaned: C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1385907078&from=tugs&uid=WDCXWD5000AAJS-55A8B2_WD-WCASY868118681186

Searching C:\Users\Public\Desktop\

Searching C:\Users\PC\Desktop


7 bad shortcuts found.

Program finished at: 12/10/2013 06:04:28 PM
Execution time: 0 hours(s), 0 minute(s), and 2 seconds(s)

Edit:
:abklatsch::dankeschoen:Es ist weg es ist weg jaaaaa

Danke diiiiiiirr, SC-Cleaner hats geschafft. Danke danke danke.

Hatte zwar, wie auch immer dann MySearchDial als Startseite, aber das bekam ich ja einfach wieder weg, 5 Minuten nachforschen und entfernen, das wars^^ nu alles wieder ok, danke euch zwei (Argus, Cosinus)

Lg

Chiara

PS: Straße und Hausnummer ich muss euch ja noch die Füße küssen :D *lach* :bussi: ihr 2 seit die besten.

cosinus 10.12.2013 18:35

Oh...jetzt weiß ich wo sicher der Scheiß eingeklinkt hat...in die Verknüpfungen :stirn: :pfui:


Dann wären wir durch! :daumenhoc


Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board

Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden.

Helfen kann dir dabei delfix:


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.






Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:30 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55