|
Log-Analyse und Auswertung: Bundespolizei - weißer Bildschirm - TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
18.04.2013, 05:27 | #1 |
| Bundespolizei - weißer Bildschirm - Trojaner Hallo liebe Gemeinde, ich habe das Problem wie von vielen andern schonmal beschrieben. Ich war im Internet unterwegs und plötzlich wie aus dem Nichts taucht der Bildschirm von der Bundespolizei auf mit der Aufforderung, ich solle mich freikaufen über paysafe. Ich war schockiert, startete den PC erstmal neu, aber jedesmal erscheint der Bildschirm aufs Neue Jetzt hab ich mich schonmal ein bisschen hier durchgelesen und einen log mit Hilfe von Farbar-Recovery Scan Tool 64 Bit erstellt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-04-2013 (ATTENTION: FRST version is 6 days old) Ran by Stefan at 17-04-2013 22:09:42 Running from H:\ Service Pack 1 (X64) OS Language: German Standard Attention: Could not load system hive. ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY. ==================== One Month Created Files and Folders ======== 2013-04-17 22:09 - 2013-04-17 22:09 - 00000000 ____D C:\FRST 2013-04-16 21:35 - 2013-04-17 22:05 - 00000004 ____A C:\Users\Stefan\AppData\Roaming\skype.ini 2013-04-14 16:55 - 2013-02-21 12:30 - 01766912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-04-14 16:55 - 2013-02-21 12:30 - 01129984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 14323200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 13761024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 02046464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-04-14 16:55 - 2013-02-21 12:29 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-04-14 16:55 - 2013-02-21 12:15 - 02240512 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-04-14 16:55 - 2013-02-21 12:15 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-04-14 16:55 - 2013-02-21 12:14 - 19230208 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 02647040 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-04-14 16:55 - 2013-02-21 12:14 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-04-14 16:55 - 2013-02-19 14:01 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-04-14 16:55 - 2013-02-19 13:42 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-04-14 16:55 - 2013-02-19 13:10 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-04-14 16:55 - 2013-02-19 12:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-04-14 11:06 - 2013-03-19 08:04 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-04-14 11:06 - 2013-03-19 07:46 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2013-04-14 11:06 - 2013-03-19 07:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-04-14 11:06 - 2013-03-19 07:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-04-14 11:06 - 2013-03-19 06:47 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-04-14 11:06 - 2013-03-19 05:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe 2013-04-14 11:06 - 2013-03-01 05:36 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-04-14 11:06 - 2013-01-24 08:01 - 00223752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys 2013-04-10 06:17 - 2013-04-10 06:17 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Lexware 2013-04-09 07:07 - 2013-04-09 07:07 - 00002669 ____A C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk 2013-04-09 07:06 - 2013-04-14 11:39 - 00000000 ____D C:\ProgramData\lexware 2013-04-09 07:06 - 2006-06-26 14:58 - 01929216 ____A (Amyuni Technologies 2013-04-09 07:01 - 2013-04-10 06:17 - 00000000 ____D C:\Users\Stefan\AppData\Local\Lexware 2013-04-03 18:56 - 2013-04-03 18:56 - 00000000 ____D C:\Users\Stefan\Desktop\Verkauf Ebay 2013-04-03 07:17 - 2013-04-03 07:27 - 00000000 ____D C:\Users\Stefan\Desktop\Falaxy i 9000 2013-03-26 20:44 - 2013-04-04 22:02 - 00000000 ____D C:\Users\Stefan\Desktop\Depot 2013-03-22 20:03 - 2013-03-22 20:03 - 01267200 ____A C:\Users\Stefan\Downloads\Campus Konto.ppt 2013-03-19 08:45 - 2013-03-19 08:45 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-19 08:45 - 2013-03-19 08:45 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-03-19 08:45 - 2013-03-19 08:45 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-03-19 08:45 - 2013-03-19 08:45 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-19 08:45 - 2013-03-19 08:45 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-19 08:45 - 2013-03-19 08:45 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-03-19 08:45 - 2013-03-19 08:45 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-19 08:45 - 2013-03-19 08:45 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-03-19 08:45 - 2013-03-19 08:45 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-03-19 08:43 - 2013-03-19 08:48 - 00010359 ____A C:\Windows\IE10_main.log ==================== One Month Modified Files and Folders ======= 2013-04-17 22:09 - 2013-04-17 22:09 - 00000000 ____D C:\FRST 2013-04-17 22:05 - 2013-04-16 21:35 - 00000004 ____A C:\Users\Stefan\AppData\Roaming\skype.ini 2013-04-17 22:05 - 2013-01-08 18:09 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-04-17 22:05 - 2012-08-18 13:38 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Dropbox 2013-04-17 22:04 - 2012-06-18 21:19 - 00000000 ____D C:\ProgramData\NVIDIA 2013-04-17 22:04 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-17 22:04 - 2009-07-14 06:51 - 04740659 ____A C:\Windows\setupact.log 2013-04-17 06:38 - 2013-01-08 18:18 - 00000000 ____D C:\Users\Stefan\.rainlendar2 2013-04-17 06:38 - 2012-08-18 13:40 - 00000000 ___RD C:\Users\Stefan\Dropbox 2013-04-16 22:04 - 2012-06-18 21:41 - 01196817 ____A C:\Windows\WindowsUpdate.log 2013-04-16 22:04 - 2009-07-14 06:45 - 00025680 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-16 22:04 - 2009-07-14 06:45 - 00025680 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-16 21:50 - 2012-06-19 07:12 - 00653928 ____A C:\Windows\System32\perfh007.dat 2013-04-16 21:50 - 2012-06-19 07:12 - 00129800 ____A C:\Windows\System32\perfc007.dat 2013-04-16 21:50 - 2009-07-14 07:13 - 01498506 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-16 21:19 - 2013-01-08 18:09 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-04-16 20:52 - 2012-06-26 07:10 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-04-15 06:41 - 2009-07-14 06:45 - 00418448 ____A C:\Windows\System32\FNTCACHE.DAT 2013-04-14 16:56 - 2012-06-19 17:38 - 72702784 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-04-14 16:56 - 2012-06-18 21:18 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-04-14 11:39 - 2013-04-09 07:06 - 00000000 ____D C:\ProgramData\lexware 2013-04-10 06:17 - 2013-04-10 06:17 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Lexware 2013-04-10 06:17 - 2013-04-09 07:01 - 00000000 ____D C:\Users\Stefan\AppData\Local\Lexware 2013-04-09 07:07 - 2013-04-09 07:07 - 00002669 ____A C:\Users\Public\Desktop\TAXMAN 2013 spezial.lnk 2013-04-04 22:02 - 2013-03-26 20:44 - 00000000 ____D C:\Users\Stefan\Desktop\Depot 2013-04-03 18:56 - 2013-04-03 18:56 - 00000000 ____D C:\Users\Stefan\Desktop\Verkauf Ebay 2013-04-03 07:27 - 2013-04-03 07:17 - 00000000 ____D C:\Users\Stefan\Desktop\Falaxy i 9000 2013-03-26 20:42 - 2012-11-14 20:17 - 00000000 ____D C:\Users\Stefan\Desktop\Kreissparkasse Köln 2013-03-26 20:41 - 2012-06-11 07:31 - 00000000 ____D C:\Users\Stefan\Desktop\Tandem Studium 2013-03-22 20:03 - 2013-03-22 20:03 - 01267200 ____A C:\Users\Stefan\Downloads\Campus Konto.ppt 2013-03-21 21:40 - 2013-01-08 09:46 - 00000000 ____D C:\Users\Stefan\Desktop\Steuererklärung 2013-03-21 20:53 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-03-19 21:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\zh-HK 2013-03-19 21:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\tr-TR 2013-03-19 21:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\zh-HK 2013-03-19 21:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\tr-TR 2013-03-19 21:46 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-03-19 08:48 - 2013-03-19 08:43 - 00010359 ____A C:\Windows\IE10_main.log 2013-03-19 08:45 - 2013-03-19 08:45 - 02776576 ____A (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 02284544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 01682432 ____A (Microsoft Corporation) C:\Windows\System32\XpsPrint.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 01509376 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-19 08:45 - 2013-03-19 08:45 - 01441280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-03-19 08:45 - 2013-03-19 08:45 - 01400416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-03-19 08:45 - 2013-03-19 08:45 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-19 08:45 - 2013-03-19 08:45 - 01158144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 01054720 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00905728 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00762368 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00719360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00629248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00599552 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00523264 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00522752 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00465920 ____A (Microsoft Corporation) C:\Windows\System32\WMPhoto.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00452096 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00441856 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-19 08:45 - 2013-03-19 08:45 - 00417792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-03-19 08:45 - 2013-03-19 08:45 - 00357888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00281600 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00270848 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00242200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00235008 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00232960 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00226816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00226304 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00216064 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00204800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00185344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00167424 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00163840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00158720 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00150528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00144896 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00137216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00136192 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00135680 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00125440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00117248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00110592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00102912 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00097280 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00092160 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00082432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00081408 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00079872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-19 08:45 - 2013-03-19 08:45 - 00073728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00069120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00061952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-03-19 08:45 - 2013-03-19 08:45 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00051200 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00048640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00038400 ____A (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00023040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00011776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-03-19 08:45 - 2013-03-19 08:45 - 00010752 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00010752 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00009728 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00009728 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00005632 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00004096 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003584 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00003072 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00002560 ___AH (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-19 08:45 - 2013-03-19 08:45 - 00002560 ___AH (Microsoft Corporation) C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 03928064 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 03419136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 02565120 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01988096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01643520 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01504768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01247744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01238528 ____A (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01175552 ____A (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 01080832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00648192 ____A (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00604160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00363008 ____A (Microsoft Corporation) C:\Windows\System32\dxgi.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00333312 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00296960 ____A (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00293376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00249856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00245248 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecsExt.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00221184 ____A (Microsoft Corporation) C:\Windows\System32\UIAnimation.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00220160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00207872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00194560 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00187392 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll 2013-03-19 08:44 - 2013-03-19 08:44 - 00161792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll 2013-03-19 08:04 - 2013-04-14 11:06 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-03-19 07:46 - 2013-04-14 11:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll 2013-03-19 07:04 - 2013-04-14 11:06 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-03-19 07:04 - 2013-04-14 11:06 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-03-19 06:47 - 2013-04-14 11:06 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-03-19 05:06 - 2013-04-14 11:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2013-04-07 19:00:11 Restore point made on: 2013-04-14 16:54:44 Restore point made on: 2013-04-15 06:51:14 Restore point made on: 2013-04-15 07:12:00 Restore point made on: 2013-04-15 23:45:19 Restore point made on: 2013-04-16 08:02:04 ==================== Memory info =========================== Percentage of memory in use: 13% Total physical RAM: 8161.2 MB Available physical RAM: 7026.97 MB Total Pagefile: 16320.58 MB Available Pagefile: 15202.21 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Partitions ============================= 1 Drive c: () (Fixed) (Total:97.66 GB) (Free:21.6 GB) NTFS 2 Drive d: () (Fixed) (Total:111.7 GB) (Free:10.37 GB) NTFS 3 Drive e: () (Fixed) (Total:976.56 GB) (Free:736 GB) NTFS 4 Drive f: () (Fixed) (Total:788.7 GB) (Free:565.73 GB) NTFS 6 Drive h: () (Removable) (Total:15.39 GB) (Free:12.07 GB) FAT32 Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 1863 GB 0 B Datentr„ger 1 Online 111 GB 0 B Datentr„ger 2 Online 15 GB 0 B Datentr„ger 3 Kein Medium 0 B 0 B Partitions of Disk 0: =============== Datentr„ger-ID: 67EE5AA2 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 100 MB 1024 KB Partition 2 Prim„r 97 GB 101 MB Partition 3 Prim„r 976 GB 97 GB Partition 4 Prim„r 788 GB 1074 GB ================================================================================== Disk: 0 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 System-rese NTFS Partition 100 MB Fehlerfre System (partition with boot components) ========================================================= Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 C NTFS Partition 97 GB Fehlerfre Startpar ========================================================= Disk: 0 Partition 3 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 E NTFS Partition 976 GB Fehlerfre ========================================================= Disk: 0 Partition 4 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 5 F NTFS Partition 788 GB Fehlerfre ========================================================= Partitions of Disk 1: =============== Datentr„ger-ID: 9DC96E9E Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 OEM 54 MB 31 KB Partition 2 Prim„r 111 GB 54 MB ================================================================================== Disk: 1 Partition 1 Typ : DE Versteckt: Ja Aktiv : Nein Dieser Partition ist kein Volume zugewiesen. ========================================================= Disk: 1 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 6 D NTFS Partition 111 GB Fehlerfre ========================================================= Partitions of Disk 2: =============== Datentr„ger-ID: D0606701 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 15 GB 596 KB ================================================================================== Disk: 2 Partition 1 Typ : 0B Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 7 H FAT32 Wechselmed 15 GB Fehlerfre ========================================================= ============================== MBR Partition Table ================== ============================== Partitions of Disk 0: =============== Disk ID: 67EE5AA2 Partition 1: ========= Hex: 8020210007DF130C0008000000200300 Active: YES Type: 07 (NTFS) Size: 100 MB Partition 2: ========= Hex: 00DF140C07FEFFFF002803000000350C Active: NO Type: 07 (NTFS) Size: 98 GB Partition 3: ========= Hex: 00FEFFFF07FEFFFF0028380C0000127A Active: NO Type: 07 (NTFS) Size: 977 GB Partition 4: ========= Hex: 00FEFFFF07FEFFFF00284A8600589662 Active: NO Type: 07 (NTFS) Size: 789 GB ============================== Partitions of Disk 1: =============== Disk ID: 9DC96E9E Partition 1: ========= Hex: 00010100DEFE3F063F00000008B70100 Active: NO Type: DE Size: 55 MB Partition 2: ========= Hex: 8000010707FEFFFF47B701007685F60D Active: YES Type: 07 (NTFS) Size: 112 GB ============================== Partitions of Disk 2: =============== Disk ID: D0606701 Partition 1: ========= Hex: 00123B000B69CEDBA8040000580BED01 Active: NO Type: 0B Size: 15 GB Last Boot: 2013-04-14 11:19 ==================== End Of Log ============================= Schöne Grüße NightLight88 |
18.04.2013, 09:07 | #2 | |
/// TB-Ausbilder | Bundespolizei - weißer Bildschirm - TrojanerZitat:
!! Hinweis an Mitlesende !! Dieses Thema und die Anweisungen sind nur für diesen speziellen Fall gedacht. Sie könnten andere Computer schwer beschädigen. Öffnet bitte euer eigenes Thema. Ich werde dir bei deinem Problem helfen. Die Bereinigung funktioniert nur, wenn du dich an die folgenden Regeln hälst: Bitte lesen: Regeln für die Bereinigung
Scan mit Farbar's Recovery Scan Tool
__________________ |
20.04.2013, 15:43 | #3 |
/// TB-Ausbilder | Bundespolizei - weißer Bildschirm - Trojaner Fehlende Rückmeldung
__________________Dieses Thema wurde aus den Abos gelöscht. Somit bekomm ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Keine Logfiles einsenden, nur kurzer Hinweis, nachdem du deine Logfiles hier eingestellt hast. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen
__________________ |
Themen zu Bundespolizei - weißer Bildschirm - Trojaner |
adobe, adobe flash player, appdata, attention, bildschirm, boot, desktop, explorer.exe, farbar recovery scan tool, flash player, free, internet, log, microsoft, neu, neue, online, problem, scan, services.exe, svchost.exe, system, system32, trojaner, windows, winlogon.exe |