|
Plagegeister aller Art und deren Bekämpfung: Runtime Errror c:\windows\syswow64\rundll32.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
17.09.2013, 07:53 | #1 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo zusammen, ich bin neu hier und hoffe, dass ihr mir helfen könnt. Auf meinem Windows 8 Rechner öffnet sich nach dem Start ein Fenster mit der Überschrift Microsoft Visual C++ Runtime Libary. In dem Fenster steht folgender Warnhinweis: Programm C:\Windows\SysWOW64\rundll32.exe. This application has requested to terminate it in an unusual way.Please contact the application´s support team for more information. Kann mir jemand sagen, ob das ein Virus ist oder wie ich diese lästige Fehlermeldung wegbekommen. Ach ja, unter Windows 8 habe ich keinen weiteren Virenscanner installiert. Es läuft die Microsoft Firewall und Microsoft Essentials. Vielen Dank für eure Hilfe Charly |
17.09.2013, 08:45 | #2 |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exe hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
17.09.2013, 19:33 | #3 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo Schrauber,
__________________danke, dass du so fix geantwortest hast. Hier die beiden Dateien. Gruß Charly |
17.09.2013, 20:28 | #4 |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exeSo funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.09.2013, 11:05 | #5 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo Schrauber, ich hoffe, so ist es etwas einfacher für dich. Ich habe die Dateien hintereinander in den Editor gestellt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-09-2013 03 Ran by Thomas at 2013-09-17 20:28:23 Running from C:\Users\Thomas\Documents Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Ashampoo Burning Studio 2013 v.11.0.6 (x32 Version: 11.0.6) BitGuard (x32) Brother Driver Deployment Wizard (x32 Version: 1.09.000) Brother MFL-Pro Suite MFC-J5910DW (x32 Version: 1.1.1.0) CCleaner (Version: 4.01) Classic Shell (Version: 3.6.5) Delta toolbar (x32 Version: 1.8.10.0) DriverAgent by eSupport.com DVR-Compress (x32) DVR-Studio Pro 2 (x32) Freemake Video Downloader (x32 Version: 3.5.0) GIMP 2.8.4 (Version: 2.8.4) LibreOffice 4.0.2.2 (x32 Version: 4.0.2.2) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) NVIDIA 3D Vision Controller-Treiber 320.18 (Version: 320.18) NVIDIA 3D Vision Treiber 320.18 (Version: 320.18) NVIDIA GeForce Experience 1.5 (Version: 1.5) NVIDIA Grafiktreiber 320.18 (Version: 320.18) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (x32 Version: 9.12.1031) NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2018) NVIDIA Systemsteuerung 320.18 (Version: 320.18) NVIDIA Update 4.11.9 (Version: 4.11.9) NVIDIA Update Components (Version: 4.11.9) Opera 12.16 (x32 Version: 12.16.1860) PDF-Viewer (Version: 2.5.210.0) PeaZip 4.9.1 (x32) Picasa 3 (x32 Version: 3.9) Sprachtrainer Fonts (x32 Version: 1.00.01) VLC media player 2.0.5 (Version: 2.0.5) VR-NetWorld (x32) WinPcap 4.1.2 (x32 Version: 4.1.0.2001) ==================== Restore Points ========================= 25-08-2013 07:28:56 Windows Update 02-09-2013 10:08:19 Geplanter Prüfpunkt 14-09-2013 07:19:23 Windows Update ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {07AFD900-A629-42B0-A684-4A5ABA7805F6} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall Task: {0A185AD5-28A8-4C5D-A63D-C7ABBCC8706C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\MpCmdRun.exe [2013-07-02] (Microsoft Corporation) Task: {0E3808ED-E85B-465B-8315-342284C4E42E} - System32\Tasks\BitGuard => Sc.exe start BitGuard Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation) Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\System32\sysmain.dll [2013-05-04] (Microsoft Corporation) Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\WSClient.dll [2013-08-16] (Microsoft Corporation) Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update Task: {36BD73B9-E60F-42F2-B341-EF7E9D7C08B0} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => Sc.exe start wuauserv Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator Task: {37AA16E2-771B-4901-9088-26941D5EF87B} - \AdobeFlashPlayerUpdate 2 No Task File Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance Task: {43592E82-55C3-403C-BA05-DF1E40E76C5E} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1303693457-2561116457-2898103115-1005 Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation) Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required Task: {6135F4D4-14FC-4C8F-BC02-9D5AA6F0717F} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation) Task: {6C2DB0D1-B993-4682-A1B9-F9DDF174BA15} - \AdobeFlashPlayerUpdate No Task File Task: {6CD136E0-17AF-492A-92FA-608498D49105} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1303693457-2561116457-2898103115-1001 Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation) Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update Task: {7BD646EB-3404-4A33-87F5-BC75513C3699} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2013-08-16] (Microsoft Corporation) Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode) Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\WSClient.dll [2013-08-16] (Microsoft Corporation) Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask Task: {A8CF5AA7-9A33-43D0-8D14-C0D2DA4AEF64} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\MpCmdRun.exe [2013-07-02] (Microsoft Corporation) Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan Task: {C391A8D1-7229-4E06-A074-47DE6094FE89} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\MpCmdRun.exe [2013-07-02] (Microsoft Corporation) Task: {C3C22889-18E2-4138-92F7-A5CCCFDD60D7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\MpCmdRun.exe [2013-07-02] (Microsoft Corporation) Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\System32\Windows.Storage.ApplicationData.dll [2012-07-26] (Microsoft Corporation) Task: {C932A0C6-F8F0-4C66-8BC3-0181D7944931} - System32\Tasks\EPUpdater => C:\Users\Thomas\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork Task: {D0A131D8-FD5B-4701-BDEF-E36E0691717B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd) Task: {D26B7E29-965C-4F5E-A7C5-CEC4D33FC892} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1303693457-2561116457-2898103115-1005 => C:\Windows\System32\portabledeviceapi.dll [2012-07-26] (Microsoft Corporation) Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical Task: {DE2DC6D1-26B3-4675-BE7F-6D350B87DCDA} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation) Task: {EAD237E7-D276-4257-9F16-51DF41548733} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\System32\Startupscan.dll [2012-07-26] (Microsoft Corporation) Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM Task: {F457401F-9859-48BF-A319-CE3841387B21} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect Task: {FFE3FD50-646E-4A64-913B-23C4187E6025} - System32\Tasks\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync ==================== Loaded Modules (whitelisted) ============= 2012-12-29 09:56 - 2012-12-29 09:56 - 01989632 _____ (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenuDLL.dll 2012-07-25 22:22 - 2013-05-12 23:42 - 15910736 _____ (NVIDIA Corporation) C:\Windows\SYSTEM32\nvwgf2umx.dll 2013-09-14 08:28 - 2013-09-13 17:00 - 02700768 _____ () C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll 2013-04-08 21:08 - 2013-07-11 22:05 - 16192864 _____ (Opera Software) C:\Program Files (x86)\Opera\Opera.dll ==================== Alternate Data Streams (whitelisted) ========== ==================== Faulty Device Manager Devices ============= Name: Coprozessor Description: Coprozessor Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-09-2013 03 Ran by Thomas (administrator) on PAPA on 17-09-2013 20:27:54 Running from C:\Users\Thomas\Documents Windows 8 Pro (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe () C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.) AppInit_DLLs-x32: c:\progra~3\bitguard\261673~1.238\{c16c1~1\bitguard.dll [2700768 2013-09-13] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?babsrc=HP_def_din2g HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x77EA5E02A133CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://search.babylon.com/?babsrc=HP_def_din2g HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=121562&babsrc=SP_ss&mntrId=B01F00306715B473 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com) BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com) Tcpip\..\Interfaces\{253C83E4-C468-4C51-86E7-5F366C63DD40}: [NameServer]192.168.2.1 ==================== Services (Whitelisted) ================= R2 BitGuard; C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3029472 2013-09-13] () R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2012-12-29] (IvoSoft) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-04-01] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-04-01] (Ellora Assets Corp.) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST 2013-09-17 20:22 - 2013-09-17 20:22 - 01950524 _____ (Farbar) C:\Users\Thomas\Documents\FRST64.exe 2013-09-15 08:34 - 2013-09-17 07:33 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-14 08:28 - 2013-09-14 08:28 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-09-14 08:28 - 2013-09-14 08:28 - 00000000 ____D C:\ProgramData\BitGuard 2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso 2013-09-12 21:55 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-09-12 21:55 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2013-09-12 21:55 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-12 21:55 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2013-09-12 21:55 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2013-09-12 21:55 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 21:55 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-12 21:55 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-09-12 21:55 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-09-12 21:55 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2013-09-12 21:55 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll 2013-09-12 21:54 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 21:54 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 21:54 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 21:54 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 21:54 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 21:54 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 21:54 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 21:54 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 21:54 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-09-12 21:54 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 21:54 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys 2013-09-12 21:54 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2013-09-12 21:54 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe 2013-09-12 21:54 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll 2013-09-12 21:54 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll 2013-09-12 21:54 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-09-12 21:54 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-09-12 21:54 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll 2013-09-12 21:54 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2013-09-12 21:54 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-09-12 21:54 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-09-12 21:54 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-09-12 21:54 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2013-09-12 21:54 - 2013-07-02 00:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml 2013-09-12 21:54 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe 2013-09-12 21:54 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe 2013-09-12 21:54 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-09-12 21:54 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-09-12 21:54 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2013-09-12 21:54 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-09-12 21:54 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys 2013-09-12 21:54 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys 2013-09-12 21:54 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-09-12 21:54 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll 2013-09-12 21:54 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll 2013-09-12 21:54 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll 2013-09-12 21:54 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll 2013-09-12 21:54 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll 2013-09-12 21:54 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll 2013-09-12 21:54 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll 2013-09-12 21:54 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2013-09-12 21:54 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys 2013-09-12 21:54 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-09-12 21:54 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-09-12 21:54 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2013-09-12 21:54 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-09-12 21:54 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-09-12 21:54 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-09-12 21:54 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2013-08-26 23:19 - 2013-08-26 23:19 - 00000850 _____ C:\Users\Thomas\AppData\Local\recently-used.xbel 2013-08-26 23:18 - 2013-08-26 23:18 - 00000000 ____D C:\Users\Thomas\.thumbnails 2013-08-26 23:17 - 2013-08-26 23:20 - 00000000 ____D C:\Users\Thomas\.gimp-2.8 2013-08-26 23:17 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\gegl-0.2 2013-08-25 09:29 - 2013-09-14 09:27 - 00000000 ____D C:\Windows\system32\MRT 2013-08-20 14:06 - 2013-07-09 08:07 - 02233168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-20 14:06 - 2013-07-02 02:44 - 00036288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2013-08-20 14:06 - 2013-07-02 00:08 - 00247216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2013-08-20 14:06 - 2013-05-24 01:02 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-20 14:06 - 2013-05-24 00:25 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-20 14:03 - 2013-07-13 08:18 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-20 14:03 - 2013-07-13 08:16 - 01889280 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-20 14:03 - 2013-07-13 08:16 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-20 14:03 - 2013-07-13 08:15 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll 2013-08-20 14:03 - 2013-07-13 08:15 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll 2013-08-20 14:03 - 2013-07-13 06:24 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-20 14:03 - 2013-07-13 06:23 - 01568256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-20 14:03 - 2013-07-13 06:23 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll 2013-08-20 14:03 - 2013-07-13 06:23 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll 2013-08-20 13:51 - 2013-09-14 11:04 - 00011738 _____ C:\Windows\PFRO.log ==================== One Month Modified Files and Folders ======= 2013-09-17 20:28 - 2013-07-02 22:41 - 01272071 _____ C:\Windows\WindowsUpdate.log 2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST 2013-09-17 20:22 - 2013-09-17 20:22 - 01950524 _____ (Farbar) C:\Users\Thomas\Documents\FRST64.exe 2013-09-17 20:04 - 2013-04-07 16:59 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1303693457-2561116457-2898103115-1001 2013-09-17 19:54 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-09-17 07:33 - 2013-09-15 08:34 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2013-09-17 07:21 - 2012-07-26 12:27 - 00714240 _____ C:\Windows\system32\perfh007.dat 2013-09-17 07:21 - 2012-07-26 12:27 - 00147840 _____ C:\Windows\system32\perfc007.dat 2013-09-17 07:21 - 2012-07-26 09:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-15 23:54 - 2013-04-08 21:16 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-15 23:54 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-14 23:25 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-09-14 13:10 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-14 11:04 - 2013-08-20 13:51 - 00011738 _____ C:\Windows\PFRO.log 2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-14 11:03 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-09-14 09:27 - 2013-08-25 09:29 - 00000000 ____D C:\Windows\system32\MRT 2013-09-14 09:25 - 2013-04-08 23:50 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-14 08:28 - 2013-09-14 08:28 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-09-14 08:28 - 2013-09-14 08:28 - 00000000 ____D C:\ProgramData\BitGuard 2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso 2013-09-12 21:48 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-09-05 22:09 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-05 22:09 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-02 08:49 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-08-26 23:20 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\.gimp-2.8 2013-08-26 23:19 - 2013-08-26 23:19 - 00000850 _____ C:\Users\Thomas\AppData\Local\recently-used.xbel 2013-08-26 23:18 - 2013-08-26 23:18 - 00000000 ____D C:\Users\Thomas\.thumbnails 2013-08-26 23:18 - 2013-04-07 16:50 - 00000000 ____D C:\Users\Thomas 2013-08-26 23:17 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\gegl-0.2 2013-08-21 06:12 - 2013-09-12 21:54 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-21 06:12 - 2013-09-12 21:54 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-21 06:11 - 2013-09-12 21:54 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-21 06:11 - 2013-09-12 21:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-21 04:34 - 2013-09-12 21:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-21 04:06 - 2013-09-12 21:54 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-21 04:06 - 2013-09-12 21:54 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-21 04:06 - 2013-09-12 21:54 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-21 04:05 - 2013-09-12 21:54 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-21 03:43 - 2013-09-12 21:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-21 01:52 - 2013-09-12 21:54 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-14 09:25 ==================== End Of Log ============================ ][/CODE] |
19.09.2013, 16:56 | #6 | |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exeCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ --> Runtime Errror c:\windows\syswow64\rundll32.exe |
22.09.2013, 08:40 | #7 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo Schrauber, ich habe die Anweisungen gemäß der Beschreibung genau befolgt. Defender und Firewall hatte ich deaktiviert. Leider ist beim Neustart folgendes passiert: Es öffnete sich ein Fenster mit dem Hinweis: Bereite LOG Datei vor. Nach ca. 5 Minuten öffnete sich ein neues Fenster mit dem Hinweis: Hilfsprogramm Findstring "QGREP" funktioniert nicht mehr. Ich habe danach die Combofix.txt gesucht, die natürlich auch nicht da war. Danach habe ich meinen Rechner neu gestartet, der dnach keine Netztzwerkverbindung herstellen konnte, weil DHCP ein Problem macht. Das hat aber das Hilfsprogamm von Windows 8 reparieren können. Ich habe im Verlauf des Scan ablesen können, dass 3 Dateien mit der Namensbeszeichung SYWOW.dll etc gelöscht wurden. Die Fehlermeldung ist bis jetzt auch nicht mehr aufgetreten. Was soll ich nun tun? Und bin ich mit dem Windows Dfender in Zukunft ausreichend geschützt? |
22.09.2013, 13:34 | #8 |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exe Wir sind noch nit fertig Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.09.2013, 09:01 | #9 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo Schrauber, hier das Logfile von Malewarebytes: 2013/09/23 20:55:42 +0200 PAPA Thomas MESSAGE Executing scheduled update: Daily 2013/09/23 20:55:45 +0200 PAPA Thomas MESSAGE Starting protection 2013/09/23 20:55:45 +0200 PAPA Thomas MESSAGE Protection started successfully 2013/09/23 20:55:45 +0200 PAPA Thomas MESSAGE Starting IP protection 2013/09/23 20:56:07 +0200 PAPA Thomas MESSAGE IP Protection started successfully 2013/09/23 20:56:30 +0200 PAPA Thomas MESSAGE Starting database refresh 2013/09/23 20:56:30 +0200 PAPA Thomas MESSAGE Stopping IP protection 2013/09/23 20:56:32 +0200 PAPA Thomas MESSAGE IP Protection stopped successfully 2013/09/23 20:56:35 +0200 PAPA Thomas MESSAGE Database refreshed successfully 2013/09/23 20:56:35 +0200 PAPA Thomas MESSAGE Starting IP protection 2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE IP Protection started successfully 2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE Starting database refresh 2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE Stopping IP protection 2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE IP Protection stopped successfully 2013/09/23 20:56:39 +0200 PAPA Thomas MESSAGE Scheduled update executed successfully: database updated from version v2013.04.04.07 to version v2013.09.23.10 2013/09/23 20:56:43 +0200 PAPA Thomas MESSAGE Database refreshed successfully 2013/09/23 20:56:43 +0200 PAPA Thomas MESSAGE Starting IP protection 2013/09/23 20:56:46 +0200 PAPA Thomas MESSAGE IP Protection started successfully 2013/09/23 21:04:42 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:04:50 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:05:00 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:36:46 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:36:54 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:36:57 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:38:04 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:38:12 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:38:56 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:39:00 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:40:08 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:44:30 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:44:32 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\uninstall.exe PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:44:33 +0200 PAPA Thomas DETECTION C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll PUP.Optional.Delta QUARANTINE 2013/09/23 21:44:33 +0200 PAPA Thomas DETECTION C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll PUP.Optional.Delta QUARANTINE 2013/09/23 21:44:42 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:44:47 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:44:59 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:45:03 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:45:06 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:45:10 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:47:30 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:48:38 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:48:44 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:56:37 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:57:46 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:57:51 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:59:04 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:59:08 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:59:23 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE 2013/09/23 21:59:51 +0200 PAPA Thomas DETECTION C:\ProgramData\BitGuard\2.6.1673.238\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.dll PUP.Optional.PerformerSoft.A QUARANTINE Hier die Ergebnisse vom AdwCleanerAdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.005 - Bericht erstellt am 24/09/2013 um 09:40:32 # Updated 22/09/2013 von Xplode # Betriebssystem : Windows 8 Pro (64 bits) # Benutzername : Thomas - PAPA # Gestartet von : C:\Users\Thomas\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : BitGuard ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\BitGuard Ordner Gelöscht : C:\Program Files (x86)\delta Ordner Gelöscht : C:\Users\Thomas\AppData\LocalLow\delta Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\file scout Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\OpenCandy Ordner Gelöscht : C:\Users\Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard Datei Gelöscht : C:\Windows\System32\Tasks\BitGuard ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKCU\Software\96df8fb23ae546 Schlüssel Gelöscht : HKLM\SOFTWARE\96df8fb23ae546 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}] [#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\filescout Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16688 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] ************************* AdwCleaner[R0].txt - [6170 octets] - [24/09/2013 09:38:43] AdwCleaner[S0].txt - [5707 octets] - [24/09/2013 09:40:32] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5767 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.2 (09.22.2013:1) OS: Windows 8 Pro x64 Ran by Thomas on 24.09.2013 at 9:45:41,85 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1303693457-2561116457-2898103115-1001\Software\SweetIM ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.09.2013 at 9:49:15,26 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2013 Ran by Thomas (administrator) on PAPA on 24-09-2013 10:00:23 Running from C:\Users\Thomas\Desktop Windows 8 Pro (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Opera Software) C:\Program Files (x86)\Opera\Opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.) AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\261673~1.238\{C16C1~1\BitGuard.dll [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x77EA5E02A133CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 ==================== Services (Whitelisted) ================= R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2012-12-29] (IvoSoft) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-04-01] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-04-01] (Ellora Assets Corp.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-24 09:57 - 2013-09-24 09:57 - 01955802 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe 2013-09-24 09:54 - 2013-09-24 09:54 - 00000617 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-09-24 09:45 - 2013-09-24 09:45 - 00000000 ____D C:\Windows\ERUNT 2013-09-24 09:44 - 2013-09-24 09:44 - 01030038 _____ (Thisisu) C:\Users\Thomas\Desktop\JRT.exe 2013-09-24 09:36 - 2013-09-24 09:40 - 00000000 ____D C:\AdwCleaner 2013-09-24 09:36 - 2013-09-24 09:36 - 01042066 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-09-23 20:55 - 2013-09-23 20:55 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes 2013-09-23 20:54 - 2013-09-23 20:54 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-22 08:57 - 2013-09-22 09:21 - 00000000 ____D C:\ComboFix 2013-09-22 08:57 - 2013-09-22 09:15 - 00000000 ____D C:\Windows\erdnt 2013-09-22 08:57 - 2013-09-22 09:04 - 00000000 ____D C:\Qoobox 2013-09-22 08:57 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-22 08:57 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-22 08:57 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-22 08:49 - 2013-09-22 08:50 - 05128554 ____R (Swearware) C:\Users\Thomas\Desktop\ComboFix.exe 2013-09-22 08:49 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-09-17 20:34 - 2013-09-17 20:34 - 00000188 _____ C:\Users\Thomas\Desktop\Trojaner Board.url 2013-09-17 20:29 - 2013-09-17 20:29 - 00025221 _____ C:\Users\Thomas\Desktop\Addition.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00028372 _____ C:\Users\Thomas\Documents\FRST.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00025221 _____ C:\Users\Thomas\Documents\Addition.txt 2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST 2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso 2013-09-12 21:55 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-09-12 21:55 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2013-09-12 21:55 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-12 21:55 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2013-09-12 21:55 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2013-09-12 21:55 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 21:55 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-12 21:55 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-09-12 21:55 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-09-12 21:55 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2013-09-12 21:55 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll 2013-09-12 21:54 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 21:54 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 21:54 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 21:54 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 21:54 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 21:54 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 21:54 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 21:54 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 21:54 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-09-12 21:54 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 21:54 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys 2013-09-12 21:54 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2013-09-12 21:54 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe 2013-09-12 21:54 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll 2013-09-12 21:54 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll 2013-09-12 21:54 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-09-12 21:54 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-09-12 21:54 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll 2013-09-12 21:54 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2013-09-12 21:54 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-09-12 21:54 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-09-12 21:54 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-09-12 21:54 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2013-09-12 21:54 - 2013-07-02 00:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml 2013-09-12 21:54 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe 2013-09-12 21:54 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe 2013-09-12 21:54 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-09-12 21:54 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-09-12 21:54 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2013-09-12 21:54 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-09-12 21:54 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys 2013-09-12 21:54 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys 2013-09-12 21:54 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-09-12 21:54 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll 2013-09-12 21:54 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll 2013-09-12 21:54 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll 2013-09-12 21:54 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll 2013-09-12 21:54 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll 2013-09-12 21:54 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll 2013-09-12 21:54 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll 2013-09-12 21:54 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2013-09-12 21:54 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys 2013-09-12 21:54 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-09-12 21:54 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-09-12 21:54 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2013-09-12 21:54 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-09-12 21:54 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-09-12 21:54 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-09-12 21:54 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2013-08-26 23:19 - 2013-08-26 23:19 - 00000850 _____ C:\Users\Thomas\AppData\Local\recently-used.xbel 2013-08-26 23:18 - 2013-08-26 23:18 - 00000000 ____D C:\Users\Thomas\.thumbnails 2013-08-26 23:17 - 2013-08-26 23:20 - 00000000 ____D C:\Users\Thomas\.gimp-2.8 2013-08-26 23:17 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\gegl-0.2 2013-08-25 09:29 - 2013-09-14 09:27 - 00000000 ____D C:\Windows\system32\MRT ==================== One Month Modified Files and Folders ======= 2013-09-24 10:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-09-24 09:57 - 2013-09-24 09:57 - 01955802 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe 2013-09-24 09:54 - 2013-09-24 09:54 - 00000617 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-09-24 09:52 - 2013-07-02 22:41 - 01534619 _____ C:\Windows\WindowsUpdate.log 2013-09-24 09:46 - 2013-04-07 16:59 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1303693457-2561116457-2898103115-1001 2013-09-24 09:46 - 2012-07-26 12:27 - 00714240 _____ C:\Windows\system32\perfh007.dat 2013-09-24 09:46 - 2012-07-26 12:27 - 00147840 _____ C:\Windows\system32\perfc007.dat 2013-09-24 09:46 - 2012-07-26 09:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-24 09:45 - 2013-09-24 09:45 - 00000000 ____D C:\Windows\ERUNT 2013-09-24 09:44 - 2013-09-24 09:44 - 01030038 _____ (Thisisu) C:\Users\Thomas\Desktop\JRT.exe 2013-09-24 09:41 - 2013-04-08 21:16 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-24 09:41 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-24 09:40 - 2013-09-24 09:36 - 00000000 ____D C:\AdwCleaner 2013-09-24 09:36 - 2013-09-24 09:36 - 01042066 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-09-24 09:33 - 2013-08-20 13:51 - 00069578 _____ C:\Windows\PFRO.log 2013-09-23 20:55 - 2013-09-23 20:55 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes 2013-09-23 20:54 - 2013-09-23 20:54 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-22 09:31 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-09-22 09:23 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-09-22 09:21 - 2013-09-22 08:57 - 00000000 ____D C:\ComboFix 2013-09-22 09:15 - 2013-09-22 08:57 - 00000000 ____D C:\Windows\erdnt 2013-09-22 09:07 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini 2013-09-22 09:06 - 2012-07-26 07:26 - 53215232 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 11010048 _____ C:\Windows\system32\config\SYSTEM.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-09-22 09:04 - 2013-09-22 08:57 - 00000000 ____D C:\Qoobox 2013-09-22 08:50 - 2013-09-22 08:49 - 05128554 ____R (Swearware) C:\Users\Thomas\Desktop\ComboFix.exe 2013-09-22 08:48 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-09-17 20:34 - 2013-09-17 20:34 - 00000188 _____ C:\Users\Thomas\Desktop\Trojaner Board.url 2013-09-17 20:29 - 2013-09-17 20:29 - 00025221 _____ C:\Users\Thomas\Desktop\Addition.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00028372 _____ C:\Users\Thomas\Documents\FRST.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00025221 _____ C:\Users\Thomas\Documents\Addition.txt 2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST 2013-09-14 13:10 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-14 11:03 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-09-14 09:27 - 2013-08-25 09:29 - 00000000 ____D C:\Windows\system32\MRT 2013-09-14 09:25 - 2013-04-08 23:50 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso 2013-09-05 22:09 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-05 22:09 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-02 08:49 - 2012-07-26 10:12 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-27 00:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-08-26 23:20 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\.gimp-2.8 2013-08-26 23:19 - 2013-08-26 23:19 - 00000850 _____ C:\Users\Thomas\AppData\Local\recently-used.xbel 2013-08-26 23:18 - 2013-08-26 23:18 - 00000000 ____D C:\Users\Thomas\.thumbnails 2013-08-26 23:18 - 2013-04-07 16:50 - 00000000 ____D C:\Users\Thomas 2013-08-26 23:17 - 2013-08-26 23:17 - 00000000 ____D C:\Users\Thomas\AppData\Local\gegl-0.2 ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-23 21:45 ==================== End Of Log ============================ --- --- --- |
24.09.2013, 18:38 | #10 |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exeESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.10.2013, 20:20 | #11 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo Schrauber, sorry, dass ich mich erst jetzt wieder melde. Ich war aber fleißig: Results of screen317's Security Check version 0.99.73 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 11.8.800.94 ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Eset.txt: F:\Dropad\BackupSD\App_Backup_Restore\com.androidlab.gpsfix-111119-1.11.apk Android/Adware.AirPush.A application und ein frisches FRST: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Thomas (administrator) on PAPA on 08-10-2013 21:15:38 Running from C:\Users\Thomas\Desktop Windows 8 Pro (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corp.) C:\Windows\system32\defrag.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM-x32\...\Run: [ControlCenter4] - C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.) AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\261673~1.238\{C16C1~1\BitGuard.dll [ ] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x77EA5E02A133CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) BHO: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_64.dll (IvoSoft) BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BHO-x32: ClassicIE9BHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIE9DLL_32.dll (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 ==================== Services (Whitelisted) ================= R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2012-12-29] (IvoSoft) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [101376 2013-04-01] (Freemake) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-04-01] (Ellora Assets Corp.) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-08 21:15 - 2013-10-08 21:15 - 01954124 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe 2013-10-07 21:56 - 2013-10-07 21:56 - 00000114 _____ C:\Users\Thomas\Desktop\eset.txt 2013-10-04 15:37 - 2013-10-04 15:37 - 00000000 _____ C:\Users\Thomas\Sti_Trace.log 2013-10-04 12:06 - 2013-10-04 12:07 - 00000245 _____ C:\Users\Thomas\Desktop\BEWITAL.url 2013-09-30 21:03 - 2013-09-30 21:03 - 00000641 _____ C:\Users\Thomas\Desktop\checkup.txt 2013-09-30 21:03 - 2013-09-30 21:03 - 00000000 ____D C:\Program Files (x86)\ESET 2013-09-30 21:01 - 2013-09-30 21:01 - 00891144 _____ C:\Users\Thomas\Desktop\SecurityCheck.exe 2013-09-29 21:58 - 2013-09-29 21:58 - 02347384 _____ (ESET) C:\Users\Thomas\Desktop\esetsmartinstaller_enu.exe 2013-09-24 09:54 - 2013-09-24 09:54 - 00000617 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-09-24 09:45 - 2013-09-24 09:45 - 00000000 ____D C:\Windows\ERUNT 2013-09-24 09:44 - 2013-09-24 09:44 - 01030038 _____ (Thisisu) C:\Users\Thomas\Desktop\JRT.exe 2013-09-24 09:36 - 2013-09-24 10:02 - 00000000 ____D C:\AdwCleaner 2013-09-24 09:36 - 2013-09-24 09:36 - 01042066 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-09-23 20:55 - 2013-09-23 20:55 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes 2013-09-23 20:54 - 2013-09-23 20:54 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-22 08:57 - 2013-09-22 09:21 - 00000000 ____D C:\ComboFix 2013-09-22 08:57 - 2013-09-22 09:15 - 00000000 ____D C:\Windows\erdnt 2013-09-22 08:57 - 2013-09-22 09:04 - 00000000 ____D C:\Qoobox 2013-09-22 08:57 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-22 08:57 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-22 08:57 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-22 08:57 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-22 08:49 - 2013-09-22 08:50 - 05128554 ____R (Swearware) C:\Users\Thomas\Desktop\ComboFix.exe 2013-09-22 08:49 - 2013-08-07 07:15 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-09-17 20:34 - 2013-09-17 20:34 - 00000188 _____ C:\Users\Thomas\Desktop\Trojaner Board.url 2013-09-17 20:29 - 2013-09-17 20:29 - 00025221 _____ C:\Users\Thomas\Desktop\Addition.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00028372 _____ C:\Users\Thomas\Documents\FRST.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00025221 _____ C:\Users\Thomas\Documents\Addition.txt 2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST 2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso 2013-09-12 21:55 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2013-09-12 21:55 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\Windows\system32\WSService.dll 2013-09-12 21:55 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2013-09-12 21:55 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2013-09-12 21:55 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2013-09-12 21:55 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2013-09-12 21:55 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\WSSync.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2013-09-12 21:55 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-09-12 21:55 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSSync.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00083968 _____ C:\Windows\SysWOW64\OEMLicense.dll 2013-09-12 21:55 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2013-09-12 21:55 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2013-09-12 21:55 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2013-09-12 21:55 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupcln.dll 2013-09-12 21:54 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-12 21:54 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-12 21:54 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-12 21:54 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-12 21:54 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-12 21:54 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-12 21:54 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-12 21:54 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-12 21:54 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-12 21:54 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-12 21:54 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2013-09-12 21:54 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-12 21:54 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpioclx.sys 2013-09-12 21:54 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2013-09-12 21:54 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe 2013-09-12 21:54 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll 2013-09-12 21:54 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Wwanadvui.dll 2013-09-12 21:54 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll 2013-09-12 21:54 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2013-09-12 21:54 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2013-09-12 21:54 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll 2013-09-12 21:54 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2013-09-12 21:54 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-09-12 21:54 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2013-09-12 21:54 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-09-12 21:54 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2013-09-12 21:54 - 2013-07-02 00:08 - 00387583 _____ C:\Windows\system32\ApnDatabase.xml 2013-09-12 21:54 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\openfiles.exe 2013-09-12 21:54 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\openfiles.exe 2013-09-12 21:54 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-09-12 21:54 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-09-12 21:54 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2013-09-12 21:54 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-09-12 21:54 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys 2013-09-12 21:54 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys 2013-09-12 21:54 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-09-12 21:54 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll 2013-09-12 21:54 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll 2013-09-12 21:54 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\winmmbase.dll 2013-09-12 21:54 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll 2013-09-12 21:54 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmmbase.dll 2013-09-12 21:54 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmm.dll 2013-09-12 21:54 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll 2013-09-12 21:54 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2013-09-12 21:54 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wfplwfs.sys 2013-09-12 21:54 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-09-12 21:54 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-09-12 21:54 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL 2013-09-12 21:54 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-09-12 21:54 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-09-12 21:54 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-09-12 21:54 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS ==================== One Month Modified Files and Folders ======= 2013-10-08 21:15 - 2013-10-08 21:15 - 01954124 _____ (Farbar) C:\Users\Thomas\Desktop\FRST64.exe 2013-10-08 21:12 - 2013-04-07 16:59 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1303693457-2561116457-2898103115-1001 2013-10-08 21:08 - 2013-07-02 22:41 - 01160566 _____ C:\Windows\WindowsUpdate.log 2013-10-08 21:06 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-10-07 21:56 - 2013-10-07 21:56 - 00000114 _____ C:\Users\Thomas\Desktop\eset.txt 2013-10-07 06:52 - 2012-07-26 12:27 - 00714240 _____ C:\Windows\system32\perfh007.dat 2013-10-07 06:52 - 2012-07-26 12:27 - 00147840 _____ C:\Windows\system32\perfc007.dat 2013-10-07 06:52 - 2012-07-26 09:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-07 06:47 - 2013-04-08 21:16 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-07 06:47 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-07 06:42 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-10-06 18:52 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-10-04 15:47 - 2013-04-10 20:52 - 00144896 ___SH C:\Users\Thomas\Desktop\Thumbs.db 2013-10-04 15:37 - 2013-10-04 15:37 - 00000000 _____ C:\Users\Thomas\Sti_Trace.log 2013-10-04 15:37 - 2013-04-07 16:50 - 00000000 ____D C:\Users\Thomas 2013-10-04 12:07 - 2013-10-04 12:06 - 00000245 _____ C:\Users\Thomas\Desktop\BEWITAL.url 2013-10-03 20:05 - 2013-07-22 06:51 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\dvdcss 2013-10-03 20:05 - 2013-04-08 21:41 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\vlc 2013-09-30 21:03 - 2013-09-30 21:03 - 00000641 _____ C:\Users\Thomas\Desktop\checkup.txt 2013-09-30 21:03 - 2013-09-30 21:03 - 00000000 ____D C:\Program Files (x86)\ESET 2013-09-30 21:01 - 2013-09-30 21:01 - 00891144 _____ C:\Users\Thomas\Desktop\SecurityCheck.exe 2013-09-29 21:58 - 2013-09-29 21:58 - 02347384 _____ (ESET) C:\Users\Thomas\Desktop\esetsmartinstaller_enu.exe 2013-09-24 10:02 - 2013-09-24 09:36 - 00000000 ____D C:\AdwCleaner 2013-09-24 09:54 - 2013-09-24 09:54 - 00000617 _____ C:\Users\Thomas\Desktop\JRT.txt 2013-09-24 09:45 - 2013-09-24 09:45 - 00000000 ____D C:\Windows\ERUNT 2013-09-24 09:44 - 2013-09-24 09:44 - 01030038 _____ (Thisisu) C:\Users\Thomas\Desktop\JRT.exe 2013-09-24 09:36 - 2013-09-24 09:36 - 01042066 _____ C:\Users\Thomas\Desktop\adwcleaner.exe 2013-09-24 09:33 - 2013-08-20 13:51 - 00069578 _____ C:\Windows\PFRO.log 2013-09-23 20:55 - 2013-09-23 20:55 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Malwarebytes 2013-09-23 20:54 - 2013-09-23 20:54 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-22 09:31 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-09-22 09:21 - 2013-09-22 08:57 - 00000000 ____D C:\ComboFix 2013-09-22 09:15 - 2013-09-22 08:57 - 00000000 ____D C:\Windows\erdnt 2013-09-22 09:07 - 2012-07-26 07:26 - 00000215 _____ C:\Windows\system.ini 2013-09-22 09:06 - 2012-07-26 07:26 - 53215232 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 11010048 _____ C:\Windows\system32\config\SYSTEM.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 00524288 _____ C:\Windows\system32\config\DEFAULT.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-09-22 09:06 - 2012-07-26 07:26 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-09-22 09:04 - 2013-09-22 08:57 - 00000000 ____D C:\Qoobox 2013-09-22 08:50 - 2013-09-22 08:49 - 05128554 ____R (Swearware) C:\Users\Thomas\Desktop\ComboFix.exe 2013-09-19 01:26 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-09-19 01:26 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-17 20:34 - 2013-09-17 20:34 - 00000188 _____ C:\Users\Thomas\Desktop\Trojaner Board.url 2013-09-17 20:29 - 2013-09-17 20:29 - 00025221 _____ C:\Users\Thomas\Desktop\Addition.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00028372 _____ C:\Users\Thomas\Documents\FRST.txt 2013-09-17 20:28 - 2013-09-17 20:28 - 00025221 _____ C:\Users\Thomas\Documents\Addition.txt 2013-09-17 20:27 - 2013-09-17 20:27 - 00000000 ____D C:\FRST 2013-09-14 13:10 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache 2013-09-14 11:09 - 2013-09-14 11:09 - 00332632 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-09-14 11:03 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-09-14 11:03 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-09-14 09:27 - 2013-08-25 09:29 - 00000000 ____D C:\Windows\system32\MRT 2013-09-14 09:25 - 2013-04-08 23:50 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-12 22:09 - 2013-09-12 22:09 - 00169984 _____ C:\Users\Thomas\Documents\VideoFree.iso ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-07 06:49 ==================== End Of Log ============================ --- --- --- --- --- --- Hast du schon eine Empfehlung für mich, welchen Virenscanner und welche Firewall ich nutzten soll? Ich dachte an Comodo Security für die Zukunft. Taugt das was? |
09.10.2013, 08:36 | #12 |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exe Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\261673~1.238\{C16C1~1\BitGuard.dll [ ] () Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Ich empfehle immer Emsisoft
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.10.2013, 20:41 | #13 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2013 Ran by Thomas at 2013-10-09 21:41:02 Run:1 Running from C:\Users\Thomas\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** AppInit_DLLs-x32: c:\PROGRA~3\BitGuard\261673~1.238\{C16C1~1\BitGuard.dll [ ] () ***************** HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully. ==== End of Fixlog ==== |
10.10.2013, 08:57 | #14 |
/// the machine /// TB-Ausbilder | Runtime Errror c:\windows\syswow64\rundll32.exe Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.10.2013, 07:58 | #15 |
| Runtime Errror c:\windows\syswow64\rundll32.exe Hallo Schrauber, vielen vielen Dank für deine Hilfe. Alles ist erledigt. Ich hoffe es bleibt so. Gruß 67_charly P.S. Bist der Beste!!!! |
Themen zu Runtime Errror c:\windows\syswow64\rundll32.exe |
c:\windows, dll, essen, fehlermeldung, fenster, firewall, folge, hallo zusammen, hinweis, microsoft, neu, programm, rechner, rundll, rundll32.exe, scan, scanner, start, this, virenscan, virenscanner, virus, visual c++, warnhinweis, windows, öffnet |