Hallo Aneri,
vielen Dank für Deine Prüfung.
Leider "verhaken" sich Dinge, wenn mehrere Prüfungen durchzuführen sind.
Deshalb gebe ich sie jetzt als
einzelne postings, insgesamt 1-4.
1.)AdwCleaner Logfile:
Code:
# AdwCleaner v3.023 - Bericht erstellt am 07/04/2014 um 07:55:18
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : GHM - PC
# Gestartet von : C:\Users\GHM\Downloads\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gefunden C:\ProgramData\uniblue
Ordner Gefunden C:\ProgramData\Uniblue\DriverScanner
Ordner Gefunden C:\Users\GHM\AppData\Local\BrowserSafeguard
Ordner Gefunden C:\Users\GHM\AppData\Local\Temp\OCS
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\45914InstEnd
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKLM\Software\Uniblue
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Google Chrome v
[ Datei : C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [11231 octets] - [19/01/2014 12:07:59]
AdwCleaner[R1].txt - [1236 octets] - [26/03/2014 09:19:35]
AdwCleaner[R2].txt - [1306 octets] - [28/03/2014 18:54:18]
AdwCleaner[R3].txt - [1358 octets] - [07/04/2014 07:51:23]
AdwCleaner[R4].txt - [1217 octets] - [07/04/2014 07:55:18]
AdwCleaner[S0].txt - [10072 octets] - [19/01/2014 12:09:00]
########## EOF - C:\AdwCleaner\AdwCleaner[R4].txt - [1338 octets] ##########
--- --- ---
Jetzt:
2.)
Malwarebytes Anti-Malware 1.75.0.1300
Malwarebytes | Free Anti-Malware & Internet Security Software
Datenbank Version: v2014.04.07.04
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16521
GHM :: PC [Administrator]
07.04.2014 12:06:06
mbam-log-2014-04-07 (12-06-06).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 238816
Laufzeit: 6 Minute(n), 4 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende)
3.
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=a6e03170a2db53479130eb19fc27f124
# engine=17775
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-07 08:11:54
# local_time=2014-04-07 10:11:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3591 16777213 100 90 668428 159454899 0 0
# compatibility_mode=5893 16776574 100 94 17936321 148489505 0 0
# scanned=141527
# found=0
# cleaned=0
# scan_time=3914
Jetzt der letzte Teil.
Wenn hier alles ok sein sollte, dann könnte es ja fast sein, daß die "unendliche Geschichte" abgeschlossen werden könnte.
Wir waren/sind wohl beide offensichtlich in "zeitlichen/privaten" Problemen, aber es macht ja nichtsd, es ist nichts "angebrannt"!
Jetzt würde ich Dich nur gerne bitten, wenn Du keine Probleme finden solltest, daß ich abschließend noch 2-3 Fragen stellen dürfte.
Hier jetzt
4.)
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by GHM (administrator) on PC on 07-04-2014 12:15:54
Running from C:\Users\GHM\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ROL4EP7S
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\KMWDSrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\21.2.0.38\NIS.exe
(Protexis Inc.) c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
(Data Perceptions / PowerProgrammer) C:\Windows\system32\WebUpdateSvc4.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Symantec Corporation) C:\Program Files\Norton Internet Security\Engine\21.2.0.38\NIS.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(X10) C:\Program Files\Common Files\X10\Common\X10nets.exe
(Wistron) C:\Program Files\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files\Launch Manager\OSD.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WButton.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\StartAutorun.exe
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\KMConfig.exe
(UASSOFT.COM) C:\Program Files\Silvercrest NM1005 driver\KMProcess.exe
(Wistron Corp.) C:\Program Files\Launch Manager\WisLMSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_77_ActiveX.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-10-02] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8546848 2010-03-17] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [686624 2010-03-17] (Realtek Semiconductor)
HKLM\...\Run: [HotkeyApp] - C:\Program Files\Launch Manager\HotkeyApp.exe [200704 2009-12-14] (Wistron)
HKLM\...\Run: [LMgrVolOSD] - C:\Program Files\Launch Manager\OSD.exe [348960 2009-12-12] (Wistron Corp.)
HKLM\...\Run: [Wbutton] - C:\Program Files\Launch Manager\Wbutton.exe [413696 2010-01-13] (Wistron Corp.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-11] (Synaptics Incorporated)
HKLM\...\Run: [KMCONFIG] - C:\Program Files\Silvercrest NM1005 driver\StartAutorun.exe KMConfig.exe
AppInit_DLLs: C:\Windows\Jaksta\AC\x86\jaudcap.dll => C:\Windows\Jaksta\AC\x86\jaudcap.dll [264480 2013-10-31] (Jaksta Technologies Pty Ltd)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.medion.com
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {E5C4ECBB-88B4-40A1-B8E0-0220F5DD43A3} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - DefaultScope {C4C2BA6A-B414-4A4C-B39B-87AF0CC54637} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {57F74961-D98B-46A0-9E3F-26E321617D3B} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms}
SearchScopes: HKCU - {C4C2BA6A-B414-4A4C-B39B-87AF0CC54637} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {E5C4ECBB-88B4-40A1-B8E0-0220F5DD43A3} URL =
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\IPS\IPSBHO.DLL (Symantec Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-19]
CHR Extension: (Google Drive) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-19]
CHR Extension: (YouTube) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-19]
CHR Extension: (Google-Suche) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-19]
CHR Extension: (Google Wallet) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-19]
CHR Extension: (Google Mail) - C:\Users\GHM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-19]
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton Internet Security\Engine\21.2.0.38\Exts\Chrome.crx [2014-03-22]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 KMWDSERVICE; C:\Program Files\Silvercrest NM1005 driver\KMWDSrv.exe [208896 2007-06-16] (UASSOFT.COM)
R2 NIS; C:\Program Files\Norton Internet Security\Engine\21.2.0.38\NIS.exe [276376 2014-03-12] (Symantec Corporation)
S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435008 2011-12-23] (TuneUp Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1052480 2011-11-21] (TuneUp Software)
R2 WebUpdate4; C:\Windows\system32\WebUpdateSvc4.exe [262360 2009-01-08] (Data Perceptions / PowerProgrammer)
R3 WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.)
R2 x10nets; C:\Program Files\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx86; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140319.001\BHDrvx86.sys [1098968 2014-03-19] (Symantec Corporation)
R1 ccSet_NIS; C:\Windows\system32\drivers\NIS\1502000.026\ccSetx86.sys [127064 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [376920 2013-11-23] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [108120 2013-11-23] (Symantec Corporation)
R1 IDSVix86; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140404.001\IDSvix86.sys [395992 2014-03-26] (Symantec Corporation)
R3 KMWDFilter; C:\Windows\System32\Drivers\KMWDFilter.SYS [17280 2007-06-13] (Windows (R) Codename Longhorn DDK provider)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-04-07] (Malwarebytes Corporation)
S3 mod7700; C:\Windows\System32\DRIVERS\mod7700.sys [786400 2009-08-13] (DiBcom SA)
R3 NAVENG; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140406.003\NAVENG.SYS [93272 2014-02-08] (Symantec Corporation)
R3 NAVEX15; C:\Program Files\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140406.003\NAVEX15.SYS [1612376 2014-02-08] (Symantec Corporation)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [12288 2008-09-08] ()
R3 SRTSP; C:\Windows\System32\Drivers\NIS\1502000.026\SRTSP.SYS [664280 2014-02-13] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NIS\1502000.026\SRTSPX.SYS [32344 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\NIS\1502000.026\SYMDS.SYS [367704 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\NIS\1502000.026\SYMEFA.SYS [936152 2014-03-04] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2013-11-24] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NIS\1502000.026\Ironx86.SYS [206936 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NIS\1502000.026\SYMNETS.SYS [447704 2014-02-18] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [13720 2009-05-13] (X10 Wireless Technology, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27160 2009-05-13] (X10 Wireless Technology, Inc.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-07 12:06 - 2014-04-07 12:06 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-04-07 08:21 - 2014-04-07 08:21 - 00000000 ____D () C:\Program Files\ESET
2014-04-07 07:57 - 2014-04-07 07:57 - 00016057 _____ () C:\Users\GHM\Desktop\AdwCleaner Ergebn. Mo.odt
2014-04-07 07:49 - 2014-04-07 07:49 - 01426178 _____ () C:\Users\GHM\Downloads\adwcleaner.exe
2014-04-06 09:07 - 2014-04-07 12:15 - 00000000 ____D () C:\FRST
2014-04-05 08:05 - 2014-04-05 08:05 - 00021618 _____ () C:\Users\GHM\Desktop\Katja Eichinger - Auftakt in ein neues Leben.odt
2014-04-04 08:49 - 2014-04-04 08:49 - 00016298 _____ () C:\Users\GHM\Desktop\Sara.odt
2014-04-03 17:19 - 2014-04-03 17:22 - 00017902 _____ () C:\Users\GHM\Desktop\Das „goldene Zeitalter“ Roms.odt
2014-03-24 20:38 - 2014-04-04 12:08 - 00000000 ____D () C:\Program Files\Recuva
2014-03-24 20:38 - 2014-03-24 20:38 - 00001803 _____ () C:\Users\Public\Desktop\Recuva.lnk
2014-03-24 20:27 - 2014-03-24 20:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-24 18:14 - 2014-03-24 18:14 - 00029068 _____ () C:\Users\GHM\Desktop\Die Wald-Kiefer.odt
2014-03-23 14:01 - 2014-03-23 14:01 - 00021348 _____ () C:\Users\GHM\Desktop\Katja Eichinger.odt
2014-03-20 22:44 - 2014-03-20 22:44 - 00016600 _____ () C:\Users\GHM\Desktop\Extinktion (Astronomie).odt
2014-03-20 21:47 - 2014-03-20 21:47 - 00024559 _____ () C:\Users\GHM\Desktop\Äquinoktium - J2000.0.odt
2014-03-19 11:33 - 2014-03-19 11:33 - 00000020 ___SH () C:\Users\DefaultAppPool\ntuser.ini
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Startmenü
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Netzwerkumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Druckumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Musik
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Bilder
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Local\Verlauf
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 ____D () C:\Users\DefaultAppPool
2014-03-19 11:33 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-19 11:33 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-19 09:20 - 2014-03-19 09:20 - 00014304 _____ () C:\Users\GHM\Desktop\Kukident.odt
2014-03-19 08:53 - 2014-03-19 08:53 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-19 08:53 - 2013-04-04 15:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-19 08:52 - 2014-03-19 08:52 - 00012699 _____ () C:\Users\GHM\Desktop\Malwarebytes.odt
2014-03-17 15:53 - 2014-03-17 17:00 - 00017422 _____ () C:\Users\GHM\Desktop\Rühlings.odt
2014-03-17 10:23 - 2014-03-17 11:31 - 00017658 _____ () C:\Users\GHM\Desktop\Buch - Kraftort Alpen.odt
2014-03-14 09:28 - 2014-03-14 09:28 - 00025993 _____ () C:\Users\GHM\Desktop\Psychisch oder psychiatrisch.odt
2014-03-12 09:32 - 2014-03-12 09:32 - 00024528 _____ () C:\Users\GHM\Desktop\Die besten Deuserband Übungen.odt
2014-03-12 08:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 08:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 08:25 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 08:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 08:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 08:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 08:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 08:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 08:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 08:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 08:25 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 08:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 08:25 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 08:25 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 08:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 08:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 08:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 08:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 08:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 08:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 08:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 08:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 08:25 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 08:25 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-12 08:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 08:25 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-12 08:25 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-11 21:03 - 2014-03-11 21:03 - 05128584 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-03-10 18:27 - 2014-03-11 17:02 - 00021343 _____ () C:\Users\GHM\Desktop\Für Dr. Geberth.odt
2014-03-10 13:30 - 2014-03-10 13:46 - 00018114 _____ () C:\Users\GHM\Desktop\Alles, Was Gut Tut.odt
2014-03-10 09:00 - 2014-04-07 06:48 - 00003584 _____ () C:\Windows\setupact.log
2014-03-10 09:00 - 2014-03-10 09:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-09 12:39 - 2014-03-09 12:37 - 00014666 _____ () C:\Users\GHM\Desktop\Was soll ich künftig tun, um den PC ''sauber'' zu halten, zu reinigen.odt
==================== One Month Modified Files and Folders =======
2014-04-07 12:15 - 2014-04-06 09:07 - 00000000 ____D () C:\FRST
2014-04-07 12:06 - 2014-04-07 12:06 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-04-07 12:03 - 2013-11-22 18:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-07 11:26 - 2010-09-18 18:25 - 01269105 _____ () C:\Windows\WindowsUpdate.log
2014-04-07 08:21 - 2014-04-07 08:21 - 00000000 ____D () C:\Program Files\ESET
2014-04-07 07:57 - 2014-04-07 07:57 - 00016057 _____ () C:\Users\GHM\Desktop\AdwCleaner Ergebn. Mo.odt
2014-04-07 07:55 - 2014-01-19 12:07 - 00000000 ____D () C:\AdwCleaner
2014-04-07 07:50 - 2010-10-03 12:15 - 00000000 ____D () C:\Users\GHM\Desktop\Reinigung
2014-04-07 07:49 - 2014-04-07 07:49 - 01426178 _____ () C:\Users\GHM\Downloads\adwcleaner.exe
2014-04-07 07:48 - 2014-02-28 20:27 - 00000000 ____D () C:\Users\GHM\Desktop\TAGTÄGLICH ROUTINE-1
2014-04-07 06:55 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-07 06:55 - 2009-07-14 06:34 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-07 06:53 - 2010-06-11 00:37 - 01729694 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-07 06:48 - 2014-03-10 09:00 - 00003584 _____ () C:\Windows\setupact.log
2014-04-07 06:48 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-05 13:36 - 2010-06-11 19:01 - 00000000 ____D () C:\ProgramData\X10 Settings
2014-04-05 08:05 - 2014-04-05 08:05 - 00021618 _____ () C:\Users\GHM\Desktop\Katja Eichinger - Auftakt in ein neues Leben.odt
2014-04-04 12:08 - 2014-03-24 20:38 - 00000000 ____D () C:\Program Files\Recuva
2014-04-04 08:49 - 2014-04-04 08:49 - 00016298 _____ () C:\Users\GHM\Desktop\Sara.odt
2014-04-03 17:22 - 2014-04-03 17:19 - 00017902 _____ () C:\Users\GHM\Desktop\Das „goldene Zeitalter“ Roms.odt
2014-03-31 09:04 - 2010-10-02 19:55 - 00000000 ___RD () C:\Users\GHM\Desktop\Programme
2014-03-30 12:53 - 2012-12-03 10:53 - 00000000 ____D () C:\Windows\system32\Drivers\NIS
2014-03-29 18:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-24 23:18 - 2010-09-18 18:37 - 00000000 ____D () C:\Users\GHM
2014-03-24 21:00 - 2014-02-11 22:37 - 00000000 ____D () C:\Users\GHM\Desktop\A
2014-03-24 20:38 - 2014-03-24 20:38 - 00001803 _____ () C:\Users\Public\Desktop\Recuva.lnk
2014-03-24 20:27 - 2014-03-24 20:27 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-24 18:14 - 2014-03-24 18:14 - 00029068 _____ () C:\Users\GHM\Desktop\Die Wald-Kiefer.odt
2014-03-23 14:01 - 2014-03-23 14:01 - 00021348 _____ () C:\Users\GHM\Desktop\Katja Eichinger.odt
2014-03-23 13:06 - 2011-03-14 20:32 - 00000000 ____D () C:\Users\GHM\AppData\Local\Adobe
2014-03-21 08:25 - 2013-11-22 19:44 - 00000000 ____D () C:\Users\GHM\AppData\Roaming\Applian FLV and Media Player
2014-03-20 22:44 - 2014-03-20 22:44 - 00016600 _____ () C:\Users\GHM\Desktop\Extinktion (Astronomie).odt
2014-03-20 21:47 - 2014-03-20 21:47 - 00024559 _____ () C:\Users\GHM\Desktop\Äquinoktium - J2000.0.odt
2014-03-19 11:33 - 2014-03-19 11:33 - 00000020 ___SH () C:\Users\DefaultAppPool\ntuser.ini
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Startmenü
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Netzwerkumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Druckumgebung
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Musik
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\Documents\Eigene Bilder
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 _SHDL () C:\Users\DefaultAppPool\AppData\Local\Verlauf
2014-03-19 11:33 - 2014-03-19 11:33 - 00000000 ____D () C:\Users\DefaultAppPool
2014-03-19 09:20 - 2014-03-19 09:20 - 00014304 _____ () C:\Users\GHM\Desktop\Kukident.odt
2014-03-19 08:53 - 2014-03-19 08:53 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-19 08:52 - 2014-03-19 08:52 - 00012699 _____ () C:\Users\GHM\Desktop\Malwarebytes.odt
2014-03-17 17:00 - 2014-03-17 15:53 - 00017422 _____ () C:\Users\GHM\Desktop\Rühlings.odt
2014-03-17 11:31 - 2014-03-17 10:23 - 00017658 _____ () C:\Users\GHM\Desktop\Buch - Kraftort Alpen.odt
2014-03-16 14:02 - 2014-03-02 12:44 - 00012821 _____ () C:\Users\GHM\Desktop\Benzo-meine Daten+Diaz.-Umrechn..odt
2014-03-15 19:26 - 2013-09-11 18:41 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-15 19:24 - 2010-06-11 19:09 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-14 09:28 - 2014-03-14 09:28 - 00025993 _____ () C:\Users\GHM\Desktop\Psychisch oder psychiatrisch.odt
2014-03-13 18:13 - 2014-02-10 13:36 - 00028859 _____ () C:\Users\GHM\Desktop\Favoriten auf anderen PC bringen.odt
2014-03-12 18:52 - 2009-07-14 06:33 - 00320496 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-12 09:32 - 2014-03-12 09:32 - 00024528 _____ () C:\Users\GHM\Desktop\Die besten Deuserband Übungen.odt
2014-03-11 22:45 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-11 21:03 - 2014-03-11 21:03 - 05128584 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-03-11 21:03 - 2013-11-22 18:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-11 21:03 - 2012-01-03 11:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 17:02 - 2014-03-10 18:27 - 00021343 _____ () C:\Users\GHM\Desktop\Für Dr. Geberth.odt
2014-03-11 09:56 - 2010-06-11 18:16 - 00000000 ____D () C:\Program Files\Launch Manager
2014-03-10 13:46 - 2014-03-10 13:30 - 00018114 _____ () C:\Users\GHM\Desktop\Alles, Was Gut Tut.odt
2014-03-10 09:00 - 2014-03-10 09:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-03-09 12:37 - 2014-03-09 12:39 - 00014666 _____ () C:\Users\GHM\Desktop\Was soll ich künftig tun, um den PC ''sauber'' zu halten, zu reinigen.odt
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 09:27
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
Gruß
Frusti