|
Plagegeister aller Art und deren Bekämpfung: Auf seltsamen Link geklicktWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.06.2013, 20:54 | #1 |
| Auf seltsamen Link geklickt Hallo, Ich habe mich gerade auf einer Seite anmelden wollen und mir wurde die Bestätigungsmail geschickt, nur in meiner Hektik habe ich gar nicht darauf geachtet ob es die richtige war und habe direkt auf den dortigen Link geklickt. Erst als eine suspekte Seite kam, habe ich bemerkt das die Mail angeblich von Paypal sein soll, jedoch war sie das sicher nicht und, noch dazu, ich habe gar kein Paypal. Jetzt habe ich natürlich die Befürchtung, dass es Malware, etc. war. Bitte keine Kommentare wie: warum klickst du auch auf den Link, etc. denn das weiß ich selbst... Danke, schon mal ! |
03.06.2013, 20:56 | #2 | |
/// the machine /// TB-Ausbilder | Auf seltsamen Link geklicktZitat:
Scherz Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32bit oder FRST 64bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ |
03.06.2013, 21:02 | #3 |
| Auf seltsamen Link geklickt Danke, für die schnelle Antwort!
__________________Geändert von Bun (03.06.2013 um 21:09 Uhr) |
03.06.2013, 21:07 | #4 |
| Auf seltsamen Link geklicktCode:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2013 03 Ran by Sarah (administrator) on 03-06-2013 21:59:29 Running from C:\Users\Sarah\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe () C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\schtasks.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe () C:\Program Files (x86)\Orange Mobiles Internet\UIExec.exe () C:\Program Files (x86)\Bamboo Dock\BambooCore.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\Program Files (x86)\Orange Mobiles Internet\UIMain.exe () C:\Program Files (x86)\Orange Mobiles Internet\CMUpdater.exe () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\Bluetooth Headset Helper.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated) HKLM\...\Run: [SynLenovoGestureMgr] "%ProgramFiles%\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m [665400 2012-08-27] (Synaptics) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12921488 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 [1214608 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [OnekeyStudio] C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo) HKLM\...\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-10-20] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-10-20] (Lenovo(beijing) Limited) HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-16] () HKCU\...\Run: [GoogleChromeAutoLaunch_3AA6F76B1F039D21D0A8ED450CE79138] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window [825808 2013-05-23] (Google Inc.) MountPoints2: {3cc730bf-4c58-11e2-be76-20689d7b2506} - "F:\AutoRun.exe" HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 [277504 2012-08-16] (Intel Corporation) HKLM-x32\...\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE [548864 2012-05-02] (Vimicro) HKLM-x32\...\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart [508656 2012-07-25] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe" [136488 2012-07-27] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s [167024 2012-07-27] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" [217088 2012-04-18] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe" [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4 [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [UIExec] "C:\Program Files (x86)\Orange Mobiles Internet\UIExec.exe" [153424 2012-02-11] () HKLM-x32\...\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] () HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-05-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll [250504 2013-02-10] (NVIDIA Corporation) Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== ProxyServer: proxy:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-search.com/?affID=119528&babsrc=HP_ss&mntrId=36d0ada6000000000000024bffb3753b HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKCU SearchScopes: DefaultScope {72066460-5C40-4AE7-A020-48DB00411009} URL = hxxp://search.softonic.com/MOY00006/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=906 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119528&babsrc=SP_ss&mntrId=36d0ada6000000000000024bffb3753b SearchScopes: HKCU - {72066460-5C40-4AE7-A020-48DB00411009} URL = hxxp://search.softonic.com/MOY00006/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=906 SearchScopes: HKCU - {B4001FFC-49CA-4047-BA64-2DA345FE8A83} URL = BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.8.8.11\bh\Softonic.dll (Softonic.com) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.8.8.11\SoftonicTlbr.dll (Softonic.com) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 213.94.78.26 213.94.78.27 Chrome: ======= CHR HomePage: hxxp://www.delta-search.com/?affID=119528&babsrc=HP_ss&mntrId=36d0ada6000000000000024bffb3753b CHR RestoreOnStartup: "hxxp://www.google.at/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File CHR Extension: (Google Docs) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: () - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf\1.0_0 CHR Extension: () - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.3_0 CHR Extension: (Nuvi Collection) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbjcghmcibkemiabpnofapahcpjjpefe\5_0 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0 CHR Extension: (Gmail) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-04-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-04-02] (Avira Operations GmbH & Co. KG) R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252088 2012-08-25] (Broadcom Corporation.) R2 BrowserProtect; C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe [2787280 2013-03-22] () R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [957304 2012-09-06] (Broadcom Corporation.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] () S2 UI Assistant Service; C:\Program Files (x86)\Orange Mobiles Internet\AssistantServices.exe [270672 2012-02-11] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [165688 2012-08-25] (Broadcom Corporation.) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-19] (Intel Corporation) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated) S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Windows (R) Win 7 DDK provider) R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [975104 2012-08-24] (Vimicro Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) R3 WUDFSensorLP; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) R3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider) R3 zte_cdc_acm; C:\Windows\system32\DRIVERS\zte_cdc_acm.sys [79872 2011-05-23] (ZTE) R3 zte_cdc_ecm; C:\Windows\system32\DRIVERS\zte_cdc_ecm.sys [36864 2011-05-23] (ZTE) S3 zte_cpo; C:\Windows\system32\DRIVERS\zte_cpo.sys [14336 2011-05-23] (ZTE) R3 zte_ecm_enum; C:\Windows\System32\drivers\zte_ecm_enum.sys [56320 2011-05-23] (ZTE) R3 zte_ecm_enum_filter; C:\Windows\System32\drivers\zte_ecm_enum_filter.sys [56320 2011-05-23] (ZTE) R2 avgntflt; system32\DRIVERS\avgntflt.sys [x] R1 avipbb; \SystemRoot\system32\DRIVERS\avipbb.sys [x] R1 avkmgr; \SystemRoot\system32\DRIVERS\avkmgr.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-03 21:58 - 2013-06-03 21:58 - 01916716 ____A (Farbar) C:\Users\Sarah\Desktop\FRST64.exe 2013-06-03 21:58 - 2013-06-03 21:58 - 00000000 ____D C:\FRST 2013-06-03 21:57 - 2013-06-03 21:57 - 01356197 ____A (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-06-02 15:27 - 2013-06-02 15:27 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-05-28 18:51 - 2013-05-28 18:51 - 00008454 ____A C:\Users\Sarah\AppData\Local\recently-used.xbel 2013-05-27 13:59 - 2013-05-27 13:59 - 00009565 ____A C:\Users\Sarah\Documents\songs.zip 2013-05-27 13:59 - 2013-05-27 13:59 - 00000000 ____D C:\Users\Sarah\Documents\songs 2013-05-24 20:08 - 2013-05-24 20:08 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-05-22 22:33 - 2013-05-23 19:20 - 00027999 ____A C:\Users\Sarah\Documents\Handout-Referat-Deutsch.odt 2013-05-22 21:06 - 2013-05-22 21:09 - 00009511 ____A C:\Users\Sarah\Documents\Unbenannt 1.odt 2013-05-22 20:40 - 2013-05-22 20:40 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone (1).ppt 2013-05-21 17:16 - 2013-05-21 17:16 - 00009688 ____A C:\Users\Sarah\Documents\song.tg 2013-05-21 16:35 - 2013-05-21 16:35 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Users\Sarah\.tuxguitar-1.2 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\ProgramData\Sun 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Program Files (x86)\Java 2013-05-21 16:31 - 2013-05-21 16:31 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (2).exe 2013-05-21 16:27 - 2013-05-21 16:27 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (1).exe 2013-05-21 16:26 - 2013-05-21 16:26 - 00008299 ____A C:\Users\Sarah\Documents\Untitled.tg 2013-05-21 16:19 - 2013-05-21 16:19 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21.exe 2013-05-21 16:19 - 2013-05-21 16:19 - 00000960 ____A C:\Users\Public\Desktop\TuxGuitar.lnk 2013-05-21 16:19 - 2013-05-21 16:19 - 00000000 ____D C:\Program Files (x86)\TuxGuitar 2013-05-21 16:17 - 2013-05-21 16:18 - 07715210 ____A (Herac) C:\Users\Sarah\Downloads\tuxguitar-1.2-windows-x86-installer.exe 2013-05-21 12:41 - 2013-05-21 12:41 - 00309752 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-20 17:30 - 2013-04-10 01:17 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-20 17:29 - 2013-04-10 01:16 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-20 17:29 - 2013-04-10 01:16 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-20 17:29 - 2013-04-10 01:16 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-20 17:29 - 2013-04-10 01:16 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-20 17:29 - 2013-04-10 00:30 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-20 17:29 - 2013-04-10 00:30 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-20 16:29 - 2013-05-20 16:29 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone.ppt 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\WebApp 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Lenovo 2013-05-19 14:42 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\Documents\CyberLink 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\Users\Sarah\Documents\Lenovo 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\ProgramData\Lenovo 2013-05-19 14:22 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-18 16:44 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-18 16:44 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-18 16:43 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-18 16:43 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-18 16:43 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-18 16:43 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-18 16:09 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys 2013-05-18 13:08 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-05-18 13:08 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll 2013-05-18 08:58 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll 2013-05-18 08:58 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll 2013-05-18 08:58 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll 2013-05-18 08:58 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll 2013-05-18 08:58 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-05-18 08:58 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2013-05-18 08:58 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-05-18 08:58 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-05-18 08:57 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll 2013-05-18 08:57 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll 2013-05-18 08:57 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe 2013-05-18 08:57 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys 2013-05-18 08:57 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll 2013-05-18 08:57 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll 2013-05-18 08:57 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll 2013-05-18 08:57 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2013-05-18 08:57 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe 2013-05-18 08:57 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe 2013-05-18 08:57 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll 2013-05-18 08:57 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-18 08:57 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll 2013-05-18 08:57 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl 2013-05-18 08:57 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll 2013-05-18 08:57 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-18 08:57 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys 2013-05-18 08:57 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys 2013-05-18 08:57 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys 2013-05-18 08:57 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys 2013-05-18 08:57 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys 2013-05-18 08:57 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys 2013-05-18 08:57 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys 2013-05-18 08:57 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys 2013-05-18 08:57 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll 2013-05-18 08:57 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-05-18 08:57 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2013-05-18 08:57 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2013-05-18 08:57 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-05-18 08:57 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-05-18 08:57 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-05-18 08:57 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-05-18 08:57 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2013-05-18 08:57 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl 2013-05-18 08:57 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2013-05-18 08:57 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll 2013-05-18 08:57 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml 2013-05-18 08:57 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi 2013-05-18 08:57 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe 2013-05-18 08:57 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi 2013-05-18 08:57 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe 2013-05-18 08:57 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll 2013-05-18 08:57 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll 2013-05-18 08:57 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2013-05-18 08:57 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-05-15 19:21 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-05-15 15:09 - 2013-05-15 15:09 - 00013658 ____A C:\Users\Sarah\Documents\In The Mourning.odt 2013-05-14 20:09 - 2013-01-15 23:06 - 03662237 ____A C:\Users\Sarah\Documents\Dublin pp.pptx 2013-05-14 20:09 - 2012-11-21 18:29 - 01249251 ____A C:\Users\Sarah\Documents\Die spätbyzantinische Zeit-PPP.pptx 2013-05-14 18:50 - 2013-05-14 20:05 - 03351024 ____A C:\Users\Sarah\Documents\Geburten.odp 2013-05-14 18:33 - 2013-05-14 18:33 - 00222253 ____A C:\Users\Sarah\Downloads\Geburten.pptx 2013-05-14 18:20 - 2013-05-14 20:08 - 00023905 ____A C:\Users\Sarah\Documents\BIUK-Geburt.odt 2013-05-13 12:43 - 2013-05-13 21:02 - 00021118 ____A C:\Users\Sarah\Documents\Frankreich- Jahresbericht!.odt 2013-05-13 08:05 - 2013-05-13 08:05 - 00021195 ____A C:\Users\Sarah\Documents\GWK.odt 2013-05-12 21:12 - 2013-05-13 08:03 - 00018534 ____A C:\Users\Sarah\Documents\GWK Handout.odt 2013-05-12 20:59 - 2013-05-12 21:42 - 01952043 ____A C:\Users\Sarah\Documents\GWK PPP.odp 2013-05-12 20:39 - 2013-05-13 08:05 - 00021195 ____A C:\Users\Sarah\Downloads\GWK.odt 2013-05-12 19:48 - 2013-05-12 19:48 - 00164636 ____A C:\Users\Sarah\Downloads\Alte Industrieregionen.pptx 2013-05-09 21:37 - 2013-05-09 21:37 - 00010094 ____A C:\Users\Sarah\Downloads\Unbenannt 1.odt 2013-05-09 21:13 - 2013-05-09 21:13 - 00049103 ____A C:\Users\Sarah\Downloads\Daydreamer.odt 2013-05-08 21:23 - 2013-05-08 21:23 - 00083160 ____A (Avira GmbH) C:\Windows\System32\Drivers\avnetflt.sys 2013-05-05 17:12 - 2013-05-05 17:12 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-05-05 17:11 - 2012-03-14 05:00 - 00385024 ____A (CANON INC.) C:\Windows\System32\CNMLMAR.DLL 2013-05-05 17:11 - 2011-04-27 11:01 - 00373248 ____A (CANON INC.) C:\Windows\System32\CNC_ARL.dll 2013-05-05 17:11 - 2011-04-27 11:00 - 00323584 ____A (CANON INC.) C:\Windows\SysWOW64\CNC_ARL.dll 2013-05-05 17:11 - 2011-03-31 10:07 - 00302080 ____A (CANON INC.) C:\Windows\System32\CNC_ARC.dll 2013-05-05 17:11 - 2011-03-31 10:07 - 00114688 ____A (CANON INC.) C:\Windows\SysWOW64\CNC_ARU.dll 2013-05-05 17:11 - 2011-03-31 10:06 - 00112128 ____A (CANON INC.) C:\Windows\System32\CNC_ARI.dll 2013-05-05 17:11 - 2010-11-29 09:17 - 00063744 ____A C:\Windows\SysWOW64\CNC1752D.TBL 2013-05-05 17:11 - 2008-08-25 18:02 - 00017920 ____A (CANON INC.) C:\Windows\System32\CNHMCA6.dll 2013-05-05 17:11 - 2008-08-25 18:02 - 00015872 ____A (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll 2013-05-05 15:59 - 2013-05-05 15:59 - 00012684 ____A C:\Users\Sarah\Documents\English Presentation.odt 2013-05-04 00:43 - 2013-05-04 00:43 - 00001250 ____A C:\Users\Sarah\Desktop\League of Legends.lnk ==================== One Month Modified Files and Folders ======= 2013-06-03 21:58 - 2013-06-03 21:58 - 01916716 ____A (Farbar) C:\Users\Sarah\Desktop\FRST64.exe 2013-06-03 21:58 - 2013-06-03 21:58 - 00000000 ____D C:\FRST 2013-06-03 21:57 - 2013-06-03 21:57 - 01356197 ____A (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-06-03 21:56 - 2013-02-18 19:49 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Skype 2013-06-03 21:30 - 2012-10-20 02:10 - 01165327 ____A C:\Windows\WindowsUpdate.log 2013-06-03 21:20 - 2012-10-20 11:17 - 00754172 ____A C:\Windows\System32\perfh007.dat 2013-06-03 21:20 - 2012-10-20 11:17 - 00156362 ____A C:\Windows\System32\perfc007.dat 2013-06-03 21:20 - 2012-07-26 09:28 - 01748838 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-03 21:15 - 2013-02-16 16:33 - 00000000 ____D C:\Users\Sarah\AppData\Local\PMB Files 2013-06-03 21:01 - 2013-02-03 18:41 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-03 21:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru 2013-06-03 20:41 - 2013-02-03 18:41 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-02 16:01 - 2012-12-25 14:44 - 00000000 ____D C:\Users\Sarah\Documents\Fortsetzungsstorys 2013-06-02 15:27 - 2013-06-02 15:27 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-06-02 12:20 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-06-01 13:23 - 2012-07-26 09:21 - 00051373 ____A C:\Windows\setupact.log 2013-05-28 18:51 - 2013-05-28 18:51 - 00008454 ____A C:\Users\Sarah\AppData\Local\recently-used.xbel 2013-05-27 16:41 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-05-27 16:40 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI 2013-05-27 13:59 - 2013-05-27 13:59 - 00009565 ____A C:\Users\Sarah\Documents\songs.zip 2013-05-27 13:59 - 2013-05-27 13:59 - 00000000 ____D C:\Users\Sarah\Documents\songs 2013-05-26 17:14 - 2013-02-16 16:33 - 00000000 ____D C:\ProgramData\PMB Files 2013-05-26 15:12 - 2013-05-03 14:26 - 00001082 ____A C:\Users\Public\Desktop\Gameforge Live.lnk 2013-05-26 15:12 - 2013-05-03 14:26 - 00000000 ____D C:\Users\Sarah\Downloads\Gameforge Live 2013-05-26 15:12 - 2013-05-03 14:26 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-05-24 20:08 - 2013-05-24 20:08 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-05-24 19:32 - 2013-02-20 21:58 - 00000000 ____D C:\Users\Sarah\Documents\Story-Ib 2013-05-24 18:11 - 2013-02-03 18:45 - 00002194 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-05-23 19:20 - 2013-05-22 22:33 - 00027999 ____A C:\Users\Sarah\Documents\Handout-Referat-Deutsch.odt 2013-05-22 21:09 - 2013-05-22 21:06 - 00009511 ____A C:\Users\Sarah\Documents\Unbenannt 1.odt 2013-05-22 20:40 - 2013-05-22 20:40 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone (1).ppt 2013-05-22 19:50 - 2013-01-11 17:41 - 00000000 ____D C:\Users\Sarah\.gimp-2.8 2013-05-21 17:16 - 2013-05-21 17:16 - 00009688 ____A C:\Users\Sarah\Documents\song.tg 2013-05-21 16:35 - 2013-05-21 16:35 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Users\Sarah\.tuxguitar-1.2 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\ProgramData\Sun 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Program Files (x86)\Java 2013-05-21 16:35 - 2013-02-03 18:22 - 00000000 ____D C:\users\Sarah 2013-05-21 16:31 - 2013-05-21 16:31 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (2).exe 2013-05-21 16:27 - 2013-05-21 16:27 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (1).exe 2013-05-21 16:26 - 2013-05-21 16:26 - 00008299 ____A C:\Users\Sarah\Documents\Untitled.tg 2013-05-21 16:19 - 2013-05-21 16:19 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21.exe 2013-05-21 16:19 - 2013-05-21 16:19 - 00000960 ____A C:\Users\Public\Desktop\TuxGuitar.lnk 2013-05-21 16:19 - 2013-05-21 16:19 - 00000000 ____D C:\Program Files (x86)\TuxGuitar 2013-05-21 16:18 - 2013-05-21 16:17 - 07715210 ____A (Herac) C:\Users\Sarah\Downloads\tuxguitar-1.2-windows-x86-installer.exe 2013-05-21 12:41 - 2013-05-21 12:41 - 00309752 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-20 19:47 - 2013-01-05 19:07 - 00000000 ____D C:\Users\Sarah\Documents\Youcam 2013-05-20 16:29 - 2013-05-20 16:29 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone.ppt 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\WebApp 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Lenovo 2013-05-19 14:43 - 2013-05-19 14:42 - 00000000 ____D C:\Users\Sarah\Documents\CyberLink 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\Users\Sarah\Documents\Lenovo 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\ProgramData\Lenovo 2013-05-19 14:42 - 2013-02-15 17:07 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\CyberLink 2013-05-19 14:25 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData 2013-05-19 14:25 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-05-17 19:52 - 2013-02-18 19:49 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-05-17 19:52 - 2013-02-18 19:49 - 00000000 ____D C:\ProgramData\Skype 2013-05-17 19:06 - 2013-02-21 20:28 - 00000000 ____D C:\ProgramData\BrowserProtect 2013-05-17 19:06 - 2012-09-13 20:32 - 00106688 ____A C:\Windows\PFRO.log 2013-05-17 18:09 - 2013-02-08 17:11 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-05-15 15:09 - 2013-05-15 15:09 - 00013658 ____A C:\Users\Sarah\Documents\In The Mourning.odt 2013-05-14 20:08 - 2013-05-14 18:20 - 00023905 ____A C:\Users\Sarah\Documents\BIUK-Geburt.odt 2013-05-14 20:05 - 2013-05-14 18:50 - 03351024 ____A C:\Users\Sarah\Documents\Geburten.odp 2013-05-14 18:33 - 2013-05-14 18:33 - 00222253 ____A C:\Users\Sarah\Downloads\Geburten.pptx 2013-05-13 21:02 - 2013-05-13 12:43 - 00021118 ____A C:\Users\Sarah\Documents\Frankreich- Jahresbericht!.odt 2013-05-13 08:05 - 2013-05-13 08:05 - 00021195 ____A C:\Users\Sarah\Documents\GWK.odt 2013-05-13 08:05 - 2013-05-12 20:39 - 00021195 ____A C:\Users\Sarah\Downloads\GWK.odt 2013-05-13 08:03 - 2013-05-12 21:12 - 00018534 ____A C:\Users\Sarah\Documents\GWK Handout.odt 2013-05-12 21:42 - 2013-05-12 20:59 - 01952043 ____A C:\Users\Sarah\Documents\GWK PPP.odp 2013-05-12 19:48 - 2013-05-12 19:48 - 00164636 ____A C:\Users\Sarah\Downloads\Alte Industrieregionen.pptx 2013-05-09 21:37 - 2013-05-09 21:37 - 00010094 ____A C:\Users\Sarah\Downloads\Unbenannt 1.odt 2013-05-09 21:13 - 2013-05-09 21:13 - 00049103 ____A C:\Users\Sarah\Downloads\Daydreamer.odt 2013-05-08 21:23 - 2013-05-08 21:23 - 00083160 ____A (Avira GmbH) C:\Windows\System32\Drivers\avnetflt.sys 2013-05-07 22:07 - 2013-03-03 08:06 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-05-07 22:07 - 2013-03-03 08:06 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-05-05 17:12 - 2013-05-05 17:12 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-05-05 17:11 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media 2013-05-05 15:59 - 2013-05-05 15:59 - 00012684 ____A C:\Users\Sarah\Documents\English Presentation.odt 2013-05-04 00:43 - 2013-05-04 00:43 - 00001250 ____A C:\Users\Sarah\Desktop\League of Legends.lnk ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit Last Boot: 2013-06-02 08:11 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-06-2013 03 Ran by Sarah at 2013-06-03 22:00:13 Run: Running from C:\Users\Sarah\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 Adobe AIR (Version: 2.6.0.19140) AION Free-to-Play Version 1.0 (Version: 1.0) Amazon Browser App (Version: 1.0.0.0) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: 2.1.0.7) Avira Free Antivirus (Version: 13.0.0.3640) Bamboo Dock (Version: 4.1) Bamboo Dock (Version: 4.1.0) Benutzerhandbuch (Version: 1.0.0.9) BrowserProtect Delta Chrome Toolbar (Version: 1.0.0.0) Delta toolbar (Version: 1.8.10.0) Dolby Home Theater v4 (Version: 7.2.8000.16) Energy Management (Version: 8.0.2.4) Free YouTube to MP3 Converter version 3.12.0.128 (Version: 3.12.0.128) Gameforge Live 1.2.1734 "Legend" (Version: 1.2.1734) GIMP 2.8.4 (Version: 2.8.4) Google Chrome (Version: 27.0.1453.94) Google Update Helper (Version: 1.3.21.145) Inkscape 0.48.4 (Version: 0.48.4) Intel AppUp(SM) center (Version: 3.6.1.33057.10) Intel PROSet Wireless Intel(R) Control Center (Version: 1.2.1.1008) Intel(R) Management Engine Components (Version: 8.1.0.1252) Intel(R) Processor Graphics (Version: 9.17.10.2843) Intel(R) Rapid Storage Technology (Version: 11.5.4.1001) Intel(R) SDK for OpenCL - CPU Only Runtime Package (Version: 2.0.0.37149) Intel(R) WiDi (Version: 3.5.34.0) Intel® PROSet/Wireless WiFi-Software (Version: 15.05.2000.1462) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Intelligent Touchpad (Version: 2.00.0012.0723) Java 7 Update 21 (Version: 7.0.210) Java Auto Updater (Version: 2.1.9.5) JMicron Flash Media Controller Driver (Version: 1.0.71.1) Lenovo Bluetooth with Enhanced Data Rate Software (Version: 12.0.0.2200) Lenovo EasyCamera (Version: 13.12.824.1) Lenovo OneKey Recovery (Version: 8.0.0.0828) Lenovo PowerDVD10 (Version: 10.0.4331.52) Lenovo YouCam (Version: 4.1.3127) Microsoft Office (Version: 14.0.6120.5004) Microsoft PowerPoint Viewer (Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) NVIDIA Grafiktreiber 314.07 (Version: 314.07) NVIDIA Install Application (Version: 2.1002.109.706) NVIDIA Optimus 1.12.12 (Version: 1.12.12) NVIDIA PhysX (Version: 9.12.1031) NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031) NVIDIA Systemsteuerung 314.07 (Version: 314.07) NVIDIA Update 1.12.12 (Version: 1.12.12) NVIDIA Update Components (Version: 1.12.12) Onekey Theater (Version: 3.0.0.9) OpenOffice.org 3.4.1 (Version: 3.41.9593) Orange Mobiles Internet (Version: 1.0.0.1) PaintTool SAI Ver.1 Pando Media Booster (Version: 2.6.0.8) Power2Go (Version: 5.6.0.9109) Realtek High Definition Audio Driver (Version: 6.0.1.6680) Shared C Run-time for x64 (Version: 10.0.0) Skype™ 6.3 (Version: 6.3.107) Softonic toolbar on IE and Chrome (Version: 1.8.8.11) SugarSync Manager (Version: 1.9.61.90905) Synaptics Pointing Device Driver (Version: 16.2.10.13) TuxGuitar (Version: 1.2) UserGuide (Version: 1.0.0.9) Wacom (Version: 5.3.2-1) WebTablet FB Plugin 32 bit (Version: 2.1.0.2) WebTablet FB Plugin 64 bit (Version: 2.1.0.2) Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733) ==================== Restore Points ========================= 15-05-2013 18:10:02 Windows Update 19-05-2013 12:21:06 Windows Update 21-05-2013 14:18:32 Installed TuxGuitar 02-06-2013 10:43:18 Geplanter Prüfpunkt ==================== Faulty Device Manager Devices ============= Name: USB-IF xHCI USB Host Controller Description: USB-IF xHCI USB Host Controller Class Guid: {8a2edc79-c759-46f2-88af-9d4efe3b5eee} Manufacturer: Intel Corporation Service: XHCIPort Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: UMDF HID minidriver Device Description: UMDF HID minidriver Device Class Guid: {177b1d2a-679c-4093-98bf-fd6999695d3b} Manufacturer: Lenovo Service: mshidumdf Problem: : Windows has stopped this device because it has reported problems. (Code 43) Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation. ==================== Event log errors: ========================= Application errors: ================== Error: (06/03/2013 08:42:12 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (06/02/2013 04:46:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (06/02/2013 04:25:33 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AssistantServices.exe, Version: 0.0.0.0, Zeitstempel: 0x4f34e4ff Name des fehlerhaften Moduls: AssistantServices.exe, Version: 0.0.0.0, Zeitstempel: 0x4f34e4ff Ausnahmecode: 0xc0000417 Fehleroffset: 0x0000f4ca ID des fehlerhaften Prozesses: 0x958 Startzeit der fehlerhaften Anwendung: 0xAssistantServices.exe0 Pfad der fehlerhaften Anwendung: AssistantServices.exe1 Pfad des fehlerhaften Moduls: AssistantServices.exe2 Berichtskennung: AssistantServices.exe3 Vollständiger Name des fehlerhaften Pakets: AssistantServices.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AssistantServices.exe5 Error: (06/02/2013 04:02:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (06/02/2013 11:51:08 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (06/02/2013 07:56:09 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (06/01/2013 07:34:52 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (06/01/2013 01:23:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (05/31/2013 09:54:31 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (05/31/2013 09:27:29 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Moonpie) Description: Die App „DefaultBrowser_NOPUBLISHERID!Chrome“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. System errors: ============= Error: (06/03/2013 09:01:18 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/03/2013 04:51:28 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/02/2013 04:51:09 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/02/2013 04:25:37 PM) (Source: Service Control Manager) (User: ) Description: Dienst "UI Assistant Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/02/2013 03:47:05 PM) (Source: JMCR) (User: ) Description: Das Gerät \Device\Scsi\JMCR1 ist für den Zugriff noch nicht bereit. Error: (06/02/2013 02:15:15 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/02/2013 10:08:47 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/02/2013 07:28:00 AM) (Source: DCOM) (User: Moonpie) Description: Windows.Networking.BackgroundTransfer.Internal.NetworkChangeTask.ClassId.1 Error: (06/02/2013 07:27:54 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/01/2013 09:10:50 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Microsoft Office Sessions: ========================= Error: (06/03/2013 08:42:12 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (06/02/2013 04:46:25 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (06/02/2013 04:25:33 PM) (Source: Application Error)(User: ) Description: AssistantServices.exe0.0.0.04f34e4ffAssistantServices.exe0.0.0.04f34e4ffc00004170000f4ca95801ce5ae8493ca737C:\Program Files (x86)\Orange Mobiles Internet\AssistantServices.exeC:\Program Files (x86)\Orange Mobiles Internet\AssistantServices.exe4848d605-cb90-11e2-be9b-20689d7b2506 Error: (06/02/2013 04:02:45 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: Microsoft.ZuneVideo_8wekyb3d8bbwe!Microsoft.ZuneVideo Error: (06/02/2013 11:51:08 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (06/02/2013 07:56:09 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (06/01/2013 07:34:52 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (06/01/2013 01:23:42 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (05/31/2013 09:54:31 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome Error: (05/31/2013 09:27:29 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Moonpie) Description: DefaultBrowser_NOPUBLISHERID!Chrome CodeIntegrity Errors: =================================== Date: 2013-06-03 21:19:59.157 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-03 15:54:19.198 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-02 08:33:35.012 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-02 06:59:17.102 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-01 20:53:30.780 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-01 20:01:31.502 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-30 08:35:01.125 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-28 15:51:32.302 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 18:48:08.380 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 16:49:27.624 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 51% Total physical RAM: 8057.77 MB Available physical RAM: 3934.82 MB Total Pagefile: 9273.77 MB Available Pagefile: 4769.4 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:884.18 GB) (Free:764.92 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.97 GB) NTFS Drive f: (Mobiles Internet) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 6D4E643B) Partition: GPT Partition Type ==================== End Of Log ============================ Oh mann, glatt vergessen es so zu posten. Ich werde die erste Antwort mal löschen ... Das Danke gilt trotzdem noch ^^ |
03.06.2013, 21:08 | #5 |
/// the machine /// TB-Ausbilder | Auf seltsamen Link geklickt Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade dir bitte Farbar's MiniToolBox auf deinen Desktop und starte das Tool Setze einen Haken bei folgenden Einträgen
Downloade dir bitte Farbar's Service Scanner
Und ein frisches FRST Logfile.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2013, 21:19 | #6 |
| Auf seltsamen Link geklickt Hier die Datei von ADW: Code:
ATTFilter # AdwCleaner v2.301 - Datei am 03/06/2013 um 22:12:50 erstellt # Aktualisiert am 16/05/2013 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzer : Sarah - MOONPIE # Bootmodus : Normal # Ausgeführt unter : C:\Users\Sarah\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : BrowserProtect ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data Datei Gelöscht : C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences Datei Gelöscht : C:\Users\Sarah\AppData\Roaming\BabMaint.exe Ordner Gelöscht : C:\Program Files (x86)\Delta Ordner Gelöscht : C:\Program Files (x86)\Softonic Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\BrowserProtect Ordner Gelöscht : C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Ordner Gelöscht : C:\Users\Sarah\AppData\LocalLow\Delta Ordner Gelöscht : C:\Users\Sarah\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\Delta Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Sarah\AppData\Roaming\Softonic ***** [Registrierungsdatenbank] ***** Daten Gelöscht : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\261249~1.132\{c16c1~1\browse~1.dll Schlüssel Gelöscht : HKCU\Software\BabylonToolbar Schlüssel Gelöscht : HKCU\Software\DataMngr Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E87806B5-E908-45FD-AF5E-957D83E58E68} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E87806B5-E908-45FD-AF5E-957D83E58E68} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\5808ad9e568bd47 Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1 Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\7E685771E24E83F4381D1DB5A45F7B41 Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\7E685771E24E83F4381D1DB5A45F7B41 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Softonic.dskBnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Softonic.dskBnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Softonic.SoftonicHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SoftonicApp.appCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SoftonicApp.appCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\srv.SoftonicSrvc.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B15F118E-AF21-45E8-A809-29FDD7362565} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\Software\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\5808ad9e568bd47 Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{177586E7-E42E-4F38-83D1-D15B4AF5B714} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8DBCDED5-08AD-41A2-9BBC-235D84F4FE06} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{5018CFD2-804D-4C99-9F81-25EAEA2769DE}] Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}] ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16537 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.delta-search.com/?affID=119528&babsrc=HP_ss&mntrId=36d0ada6000000000000024bffb3753b --> hxxp://www.google.com Ersetzt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.softonic.com/MOY00006/tb_v1?SearchSource=15&cc= --> hxxp://www.google.com -\\ Google Chrome v27.0.1453.94 Datei : C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.2355] : homepage = "hxxp://www.delta-search.com/?affID=119528&babsrc=HP_ss&mntrId=36d0ada600000000000002[...] ************************* AdwCleaner[S1].txt - [16190 octets] - [03/06/2013 22:12:50] ########## EOF - C:\AdwCleaner[S1].txt - [16251 octets] ########## |
03.06.2013, 21:30 | #7 |
/// the machine /// TB-Ausbilder | Auf seltsamen Link geklickt und weiter im Text
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2013, 21:33 | #8 |
| Auf seltsamen Link geklickt Dann JRT: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 8 x64 Ran by Sarah on 03.06.2013 at 22:24:34,05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{72066460-5C40-4AE7-A020-48DB00411009} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 03.06.2013 at 22:26:44,47 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter MiniToolBox by Farbar Version:21-04-2013 Ran by Sarah (administrator) on 03-06-2013 at 22:35:02 Running from "C:\Users\Sarah\Desktop" Windows 8 (X64) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. ========================= IE Proxy Settings: ============================== Proxy is not enabled. ProxyServer: proxy:8080 "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= ========================= IP Configuration: ================================ ZTE Mobile Connect Network Device = LAN-Verbindung (Connected) Intel(R) Centrino(R) Wireless-N 2200 = WiFi (Media disconnected) Qualcomm Atheros AR8161 PCI-E Gigabit Ethernet Controller (NDIS 6.30) = Ethernet (Media disconnected) Bluetooth-Gerät (PAN) = Bluetooth-Netzwerkverbindung (Media disconnected) # ---------------------------------- # IPv4-Konfiguration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled set interface interface="LAN-Verbindung* 9" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="WiFi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="Bluetooth-Netzwerkverbindung" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="LAN-Verbindung* 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="LAN-Verbindung" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="LAN-Verbindung 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set interface interface="LAN-Verbindung* 4" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled set subinterface interface=?V subinterface=ethernet_11 mtu=1477 popd # Ende der IPv4-Konfiguration Windows-IP-Konfiguration Hostname . . . . . . . . . . . . : Moonpie Prim„res DNS-Suffix . . . . . . . : Knotentyp . . . . . . . . . . . . : Hybrid IP-Routing aktiviert . . . . . . : Nein WINS-Proxy aktiviert . . . . . . : Nein Unbekannter Adapter LAN-Verbindung: Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : ZTE Mobile Connect Network Device Physische Adresse . . . . . . . . : 02-4B-FF-B3-75-3B DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Verbindungslokale IPv6-Adresse . : fe80::6589:4d09:c485:7c2a%19(Bevorzugt) IPv4-Adresse . . . . . . . . . . : 46.57.25.216(Bevorzugt) Subnetzmaske . . . . . . . . . . : 255.255.255.0 Lease erhalten. . . . . . . . . . : Montag, 03. Juni 2013 22:32:03 Lease l„uft ab. . . . . . . . . . : Dienstag, 04. Juni 2013 22:32:02 Standardgateway . . . . . . . . . : 46.57.25.217 DHCP-Server . . . . . . . . . . . : 46.57.25.217 DHCPv6-IAID . . . . . . . . . . . : 570575871 DHCPv6-Client-DUID. . . . . . . . : 00-01-00-01-18-13-99-0D-9C-4E-36-6C-38-B4 DNS-Server . . . . . . . . . . . : 213.94.78.26 213.94.78.27 NetBIOS ber TCP/IP . . . . . . . : Aktiviert Drahtlos-LAN-Adapter LAN-Verbindung* 2: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Virtueller Microsoft-Adapter fr direktes WiFi Physische Adresse . . . . . . . . : 9C-4E-36-6C-38-B5 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Ethernet-Adapter Bluetooth-Netzwerkverbindung: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Bluetooth-Ger„t (PAN) Physische Adresse . . . . . . . . : 20-68-9D-7B-25-06 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Ethernet-Adapter Ethernet: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Qualcomm Atheros AR8161 PCI-E Gigabit Ethernet Controller (NDIS 6.30) Physische Adresse . . . . . . . . : B8-88-E3-86-AD-D1 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Drahtlos-LAN-Adapter WiFi: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: bgstockerau.ac.at Beschreibung. . . . . . . . . . . : Intel(R) Centrino(R) Wireless-N 2200 Physische Adresse . . . . . . . . : 9C-4E-36-6C-38-B4 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Tunneladapter 6TO4 Adapter: Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-6zu4-Adapter Physische Adresse . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja IPv6-Adresse. . . . . . . . . . . : 2002:2e39:19d8::2e39:19d8(Bevorzugt) Standardgateway . . . . . . . . . : DNS-Server . . . . . . . . . . . : 213.94.78.26 213.94.78.27 NetBIOS ber TCP/IP . . . . . . . : Deaktiviert Tunneladapter Teredo Tunneling Pseudo-Interface: Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physische Adresse . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja IPv6-Adresse. . . . . . . . . . . : 2001:0:5ef5:79fd:20fa:68f:d1c6:e627(Bevorzugt) Verbindungslokale IPv6-Adresse . : fe80::20fa:68f:d1c6:e627%20(Bevorzugt) Standardgateway . . . . . . . . . : DHCPv6-IAID . . . . . . . . . . . : 637534208 DHCPv6-Client-DUID. . . . . . . . : 00-01-00-01-18-13-99-0D-9C-4E-36-6C-38-B4 NetBIOS ber TCP/IP . . . . . . . : Deaktiviert Tunneladapter isatap.{2E086ACB-FF14-4F6F-A825-3E4D618A46E0}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #2 Physische Adresse . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Server: pdnsvip1-optout.drei.com Address: 213.94.78.26 Name: google.com Addresses: 2a00:1450:4001:801::1002 173.194.112.33 173.194.112.35 173.194.112.32 173.194.112.41 173.194.112.40 173.194.112.39 173.194.112.46 173.194.112.34 173.194.112.37 173.194.112.36 173.194.112.38 Ping wird ausgefhrt fr google.com [173.194.112.33] mit 32 Bytes Daten: Antwort von 173.194.112.33: Bytes=32 Zeit=355ms TTL=54 Antwort von 173.194.112.33: Bytes=32 Zeit=304ms TTL=54 Ping-Statistik fr 173.194.112.33: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 304ms, Maximum = 355ms, Mittelwert = 329ms Server: pdnsvip1-optout.drei.com Address: 213.94.78.26 Name: yahoo.com Addresses: 98.139.183.24 206.190.36.45 98.138.253.109 Ping wird ausgefhrt fr yahoo.com [98.139.183.24] mit 32 Bytes Daten: Antwort von 98.139.183.24: Bytes=32 Zeit=649ms TTL=47 Antwort von 98.139.183.24: Bytes=32 Zeit=772ms TTL=47 Ping-Statistik fr 98.139.183.24: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 649ms, Maximum = 772ms, Mittelwert = 710ms Ping wird ausgefhrt fr 127.0.0.1 mit 32 Bytes Daten: Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128 Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128 Ping-Statistik fr 127.0.0.1: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms =========================================================================== Schnittstellenliste 19...02 4b ff b3 75 3b ......ZTE Mobile Connect Network Device 18...9c 4e 36 6c 38 b5 ......Virtueller Microsoft-Adapter fr direktes WiFi 17...20 68 9d 7b 25 06 ......Bluetooth-Ger„t (PAN) 13...b8 88 e3 86 ad d1 ......Qualcomm Atheros AR8161 PCI-E Gigabit Ethernet Controller (NDIS 6.30) 12...9c 4e 36 6c 38 b4 ......Intel(R) Centrino(R) Wireless-N 2200 1...........................Software Loopback Interface 1 15...00 00 00 00 00 00 00 e0 Microsoft-6zu4-Adapter 20...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface 22...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #2 =========================================================================== IPv4-Routentabelle =========================================================================== Aktive Routen: Netzwerkziel Netzwerkmaske Gateway Schnittstelle Metrik 0.0.0.0 0.0.0.0 46.57.25.217 46.57.25.216 25 46.57.25.0 255.255.255.0 Auf Verbindung 46.57.25.216 281 46.57.25.216 255.255.255.255 Auf Verbindung 46.57.25.216 281 46.57.25.255 255.255.255.255 Auf Verbindung 46.57.25.216 281 127.0.0.0 255.0.0.0 Auf Verbindung 127.0.0.1 306 127.0.0.1 255.255.255.255 Auf Verbindung 127.0.0.1 306 127.255.255.255 255.255.255.255 Auf Verbindung 127.0.0.1 306 224.0.0.0 240.0.0.0 Auf Verbindung 127.0.0.1 306 224.0.0.0 240.0.0.0 Auf Verbindung 46.57.25.216 281 255.255.255.255 255.255.255.255 Auf Verbindung 127.0.0.1 306 255.255.255.255 255.255.255.255 Auf Verbindung 46.57.25.216 281 =========================================================================== St„ndige Routen: Keine IPv6-Routentabelle =========================================================================== Aktive Routen: If Metrik Netzwerkziel Gateway 1 306 ::1/128 Auf Verbindung 20 306 2001::/32 Auf Verbindung 20 306 2001:0:5ef5:79fd:20fa:68f:d1c6:e627/128 Auf Verbindung 15 1030 2002::/16 Auf Verbindung 15 286 2002:2e39:19d8::2e39:19d8/128 Auf Verbindung 19 281 fe80::/64 Auf Verbindung 20 306 fe80::/64 Auf Verbindung 20 306 fe80::20fa:68f:d1c6:e627/128 Auf Verbindung 19 281 fe80::6589:4d09:c485:7c2a/128 Auf Verbindung 1 306 ff00::/8 Auf Verbindung 20 306 ff00::/8 Auf Verbindung 19 281 ff00::/8 Auf Verbindung =========================================================================== St„ndige Routen: Keine ========================= Winsock entries ===================================== Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation) Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [67584] (Microsoft Corporation) Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [55296] (Microsoft Corporation) Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [21504] (Microsoft Corporation) Catalog5 07 C:\WINDOWS\SysWOW64\wshbth.dll [50688] (Microsoft Corporation) Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [289280] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\napinsp.dll [66560] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [85504] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [72192] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [53760] (Microsoft Corporation) x64-Catalog5 07 C:\Windows\System32\wshbth.dll [64000] (Microsoft Corporation) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) x64-Catalog9 11 C:\Windows\System32\mswsock.dll [355328] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== System errors: ============= Error: (06/03/2013 10:32:59 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (06/03/2013 10:32:29 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (06/03/2013 10:31:59 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (06/03/2013 10:31:29 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-06-03 21:19:59.157 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-03 15:54:19.198 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-02 08:33:35.012 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-02 06:59:17.102 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-01 20:53:30.780 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-06-01 20:01:31.502 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-30 08:35:01.125 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-28 15:51:32.302 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 18:48:08.380 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 16:49:27.624 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. =========================== Installed Programs ============================ 7-Zip 9.20 Adobe AIR (Version: 2.6.0.19140) AION Free-to-Play Version 1.0 (Version: 1.0) Amazon Browser App (Version: 1.0.0.0) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: 2.1.0.7) Avira Free Antivirus (Version: 13.0.0.3640) Bamboo Dock (Version: 4.1) Bamboo Dock (Version: 4.1.0) Benutzerhandbuch (Version: 1.0.0.9) Dolby Home Theater v4 (Version: 7.2.8000.16) Energy Management (Version: 8.0.2.4) Free YouTube to MP3 Converter version 3.12.0.128 (Version: 3.12.0.128) Gameforge Live 1.2.1734 "Legend" (Version: 1.2.1734) GIMP 2.8.4 (Version: 2.8.4) Google Chrome (Version: 27.0.1453.94) Google Update Helper (Version: 1.3.21.145) Inkscape 0.48.4 (Version: 0.48.4) Intel AppUp(SM) center (Version: 3.6.1.33057.10) Intel PROSet Wireless Intel(R) Control Center (Version: 1.2.1.1008) Intel(R) Management Engine Components (Version: 8.1.0.1252) Intel(R) Processor Graphics (Version: 9.17.10.2843) Intel(R) Rapid Storage Technology (Version: 11.5.4.1001) Intel(R) SDK for OpenCL - CPU Only Runtime Package (Version: 2.0.0.37149) Intel(R) WiDi (Version: 3.5.34.0) Intel® PROSet/Wireless WiFi-Software (Version: 15.05.2000.1462) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Intelligent Touchpad (Version: 2.00.0012.0723) Java 7 Update 21 (Version: 7.0.210) Java Auto Updater (Version: 2.1.9.5) JMicron Flash Media Controller Driver (Version: 1.0.71.1) Lenovo Bluetooth with Enhanced Data Rate Software (Version: 12.0.0.2200) Lenovo EasyCamera (Version: 13.12.824.1) Lenovo OneKey Recovery (Version: 8.0.0.0828) Lenovo PowerDVD10 (Version: 10.0.4331.52) Lenovo YouCam (Version: 4.1.3127) Microsoft Office (Version: 14.0.6120.5004) Microsoft PowerPoint Viewer (Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) NVIDIA Grafiktreiber 314.07 (Version: 314.07) NVIDIA Install Application (Version: 2.1002.109.706) NVIDIA Optimus 1.12.12 (Version: 1.12.12) NVIDIA PhysX (Version: 9.12.1031) NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031) NVIDIA Systemsteuerung 314.07 (Version: 314.07) NVIDIA Update 1.12.12 (Version: 1.12.12) NVIDIA Update Components (Version: 1.12.12) Onekey Theater (Version: 3.0.0.9) OpenOffice.org 3.4.1 (Version: 3.41.9593) Orange Mobiles Internet (Version: 1.0.0.1) PaintTool SAI Ver.1 Pando Media Booster (Version: 2.6.0.8) Power2Go (Version: 5.6.0.9109) Realtek High Definition Audio Driver (Version: 6.0.1.6680) Shared C Run-time for x64 (Version: 10.0.0) Skype™ 6.3 (Version: 6.3.107) SugarSync Manager (Version: 1.9.61.90905) Synaptics Pointing Device Driver (Version: 16.2.10.13) TuxGuitar (Version: 1.2) UserGuide (Version: 1.0.0.9) Wacom (Version: 5.3.2-1) WebTablet FB Plugin 32 bit (Version: 2.1.0.2) WebTablet FB Plugin 64 bit (Version: 2.1.0.2) Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733) ========================= Memory info: =================================== Percentage of memory in use: 24% Total physical RAM: 8057.77 MB Available physical RAM: 6115.32 MB Total Pagefile: 9273.77 MB Available Pagefile: 7217.29 MB Total Virtual: 4095.88 MB Available Virtual: 3956.03 MB ========================= Partitions: ===================================== 1 Drive c: (Windows8_OS) (Fixed) (Total:884.18 GB) (Free:764.96 GB) NTFS 2 Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.97 GB) NTFS 4 Drive f: (Mobiles Internet) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS ========================= Users: ======================================== Benutzerkonten fr \\MOONPIE Administrator Gast Sarah UpdatusUser Der Befehl wurde erfolgreich ausgefhrt. ========================= Minidump Files ================================== No minidump file found **** End of log **** Code:
ATTFilter Farbar Service Scanner Version: 31-05-2013 01 Ran by Sarah (administrator) on 03-06-2013 at 22:38:15 Running from "C:\Users\Sarah\Desktop" Windows 8 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Attempt to access Yahoo IP returned error. Yahoo IP is offline Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend: ""%ProgramFiles%\Windows Defender\MsMpEng.exe"". Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys [2013-04-15 10:26] - [2013-03-02 11:59] - 2231528 ____A (Microsoft Corporation) B6D52E2C38B49A156E58FF5B9C6CA8BE C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll [2013-05-18 08:57] - [2013-04-09 06:51] - 0099840 ____A (Microsoft Corporation) 012CFE7F0F95266F554EE3B91EE2128A C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll [2013-04-15 10:26] - [2013-03-02 04:45] - 3240448 ____A (Microsoft Corporation) 79F95469604B77296346DE7DB463EA2A C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll [2013-04-01 19:56] - [2013-01-29 01:08] - 1555920 ____A (Microsoft Corporation) 905601FFF40D8DA9FA82CBE77D1F5EB1 C:\Program Files\Windows Defender\MsMpEng.exe [2013-04-01 19:56] - [2013-01-29 03:57] - 0014920 ____A (Microsoft Corporation) 473B9548568BA927ACE0B77EC208A561 C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-06-2013 01 Ran by Sarah (administrator) on 03-06-2013 22:44:25 Running from C:\Users\Sarah\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Orange Mobiles Internet\AssistantServices.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe () C:\Program Files (x86)\Orange Mobiles Internet\UIExec.exe () C:\Program Files (x86)\Bamboo Dock\BambooCore.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\Orange Mobiles Internet\UIMain.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe () C:\Program Files (x86)\Orange Mobiles Internet\CMUpdater.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16455_none_624a7aa150f57306\TiWorker.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated) HKLM\...\Run: [SynLenovoGestureMgr] "%ProgramFiles%\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m [665400 2012-08-27] (Synaptics) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [12921488 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 [1214608 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [OnekeyStudio] C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo) HKLM\...\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-10-20] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-10-20] (Lenovo(beijing) Limited) HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-16] () HKCU\...\Run: [GoogleChromeAutoLaunch_3AA6F76B1F039D21D0A8ED450CE79138] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window [825808 2013-05-23] (Google Inc.) MountPoints2: {3cc730bf-4c58-11e2-be76-20689d7b2506} - "F:\AutoRun.exe" HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 [277504 2012-08-16] (Intel Corporation) HKLM-x32\...\Run: [331BigDog] C:\Program Files (x86)\USB Camera\VM331STI.EXE [548864 2012-05-02] (Vimicro) HKLM-x32\...\Run: [Dolby Home Theater v4] "C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart [508656 2012-07-25] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe" [136488 2012-07-27] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s [167024 2012-07-27] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" [217088 2012-04-18] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe" [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4 [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [UIExec] "C:\Program Files (x86)\Orange Mobiles Internet\UIExec.exe" [153424 2012-02-11] () HKLM-x32\...\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] () HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345312 2013-05-08] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll [250504 2013-02-10] (NVIDIA Corporation) Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKCU SearchScopes: DefaultScope {B4001FFC-49CA-4047-BA64-2DA345FE8A83} URL = SearchScopes: HKCU - {B4001FFC-49CA-4047-BA64-2DA345FE8A83} URL = BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 213.94.78.26 213.94.78.27 Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR RestoreOnStartup: "hxxp://www.google.at/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File CHR Extension: (Google Docs) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Nuvi Collection) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbjcghmcibkemiabpnofapahcpjjpefe\5_0 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0 CHR Extension: (Gmail) - C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86752 2013-04-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110816 2013-04-02] (Avira Operations GmbH & Co. KG) R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252088 2012-08-25] (Broadcom Corporation.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [957304 2012-09-06] (Broadcom Corporation.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] () R2 UI Assistant Service; C:\Program Files (x86)\Orange Mobiles Internet\AssistantServices.exe [270672 2012-02-11] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [165688 2012-08-25] (Broadcom Corporation.) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-19] (Intel Corporation) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated) S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Windows (R) Win 7 DDK provider) R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [975104 2012-08-24] (Vimicro Corporation) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) R3 WUDFSensorLP; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) R3 WUDFWpdMtp; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation) S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider) R3 zte_cdc_acm; C:\Windows\system32\DRIVERS\zte_cdc_acm.sys [79872 2011-05-23] (ZTE) R3 zte_cdc_ecm; C:\Windows\system32\DRIVERS\zte_cdc_ecm.sys [36864 2011-05-23] (ZTE) S3 zte_cpo; C:\Windows\system32\DRIVERS\zte_cpo.sys [14336 2011-05-23] (ZTE) R3 zte_ecm_enum; C:\Windows\System32\drivers\zte_ecm_enum.sys [56320 2011-05-23] (ZTE) R3 zte_ecm_enum_filter; C:\Windows\System32\drivers\zte_ecm_enum_filter.sys [56320 2011-05-23] (ZTE) R2 avgntflt; system32\DRIVERS\avgntflt.sys [x] R1 avipbb; \SystemRoot\system32\DRIVERS\avipbb.sys [x] R1 avkmgr; \SystemRoot\system32\DRIVERS\avkmgr.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-03 22:41 - 2013-06-03 22:43 - 01916754 ____A (Farbar) C:\Users\Sarah\Desktop\FRST64.exe 2013-06-03 22:38 - 2013-06-03 22:38 - 00003064 ____A C:\Users\Sarah\Desktop\FSS.txt 2013-06-03 22:37 - 2013-06-03 22:37 - 00355651 ____A (Farbar) C:\Users\Sarah\Downloads\FSS (1).exe 2013-06-03 22:36 - 2013-06-03 22:36 - 00355651 ____A (Farbar) C:\Users\Sarah\Desktop\FSS.exe 2013-06-03 22:35 - 2013-06-03 22:35 - 00021951 ____A C:\Users\Sarah\Desktop\Result.txt 2013-06-03 22:33 - 2013-06-03 22:33 - 00760723 ____A (Farbar) C:\Users\Sarah\Desktop\MiniToolBox.exe 2013-06-03 22:26 - 2013-06-03 22:26 - 00000759 ____A C:\Users\Sarah\Desktop\JRT.txt 2013-06-03 22:22 - 2013-06-03 22:22 - 00000000 ____D C:\Windows\ERUNT 2013-06-03 22:21 - 2013-06-03 22:24 - 00000000 ____D C:\JRT 2013-06-03 22:21 - 2013-06-03 22:21 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Sarah\Desktop\JRT.exe 2013-06-03 22:12 - 2013-06-03 22:13 - 00016259 ____A C:\AdwCleaner[S1].txt 2013-06-03 22:10 - 2013-06-03 22:10 - 00632031 ____A C:\Users\Sarah\Desktop\adwcleaner.exe 2013-06-03 22:00 - 2013-06-03 22:00 - 00015388 ____A C:\Users\Sarah\Desktop\Addition.txt 2013-06-03 21:58 - 2013-06-03 21:58 - 00000000 ____D C:\FRST 2013-06-03 21:57 - 2013-06-03 21:57 - 01356197 ____A (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-06-02 15:27 - 2013-06-02 15:27 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-05-28 18:51 - 2013-05-28 18:51 - 00008454 ____A C:\Users\Sarah\AppData\Local\recently-used.xbel 2013-05-27 13:59 - 2013-05-27 13:59 - 00009565 ____A C:\Users\Sarah\Documents\songs.zip 2013-05-27 13:59 - 2013-05-27 13:59 - 00000000 ____D C:\Users\Sarah\Documents\songs 2013-05-24 20:08 - 2013-05-24 20:08 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-05-22 22:33 - 2013-05-23 19:20 - 00027999 ____A C:\Users\Sarah\Documents\Handout-Referat-Deutsch.odt 2013-05-22 21:06 - 2013-05-22 21:09 - 00009511 ____A C:\Users\Sarah\Documents\Unbenannt 1.odt 2013-05-22 20:40 - 2013-05-22 20:40 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone (1).ppt 2013-05-21 17:16 - 2013-05-21 17:16 - 00009688 ____A C:\Users\Sarah\Documents\song.tg 2013-05-21 16:35 - 2013-05-21 16:35 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Users\Sarah\.tuxguitar-1.2 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\ProgramData\Sun 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Program Files (x86)\Java 2013-05-21 16:31 - 2013-05-21 16:31 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (2).exe 2013-05-21 16:27 - 2013-05-21 16:27 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (1).exe 2013-05-21 16:26 - 2013-05-21 16:26 - 00008299 ____A C:\Users\Sarah\Documents\Untitled.tg 2013-05-21 16:19 - 2013-05-21 16:19 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21.exe 2013-05-21 16:19 - 2013-05-21 16:19 - 00000960 ____A C:\Users\Public\Desktop\TuxGuitar.lnk 2013-05-21 16:19 - 2013-05-21 16:19 - 00000000 ____D C:\Program Files (x86)\TuxGuitar 2013-05-21 16:17 - 2013-05-21 16:18 - 07715210 ____A (Herac) C:\Users\Sarah\Downloads\tuxguitar-1.2-windows-x86-installer.exe 2013-05-21 12:41 - 2013-05-21 12:41 - 00309752 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-20 17:30 - 2013-04-10 01:17 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-20 17:29 - 2013-04-10 01:17 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-20 17:29 - 2013-04-10 01:16 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-20 17:29 - 2013-04-10 01:16 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-20 17:29 - 2013-04-10 01:16 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-20 17:29 - 2013-04-10 01:16 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-20 17:29 - 2013-04-10 00:30 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-20 17:29 - 2013-04-10 00:30 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-20 17:29 - 2013-04-10 00:29 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-20 16:29 - 2013-05-20 16:29 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone.ppt 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\WebApp 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Lenovo 2013-05-19 14:42 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\Documents\CyberLink 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\Users\Sarah\Documents\Lenovo 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\ProgramData\Lenovo 2013-05-19 14:22 - 2013-04-16 04:34 - 01455368 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-18 16:44 - 2013-03-06 08:31 - 19758592 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-18 16:44 - 2013-03-06 07:03 - 17561600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-18 16:43 - 2013-03-06 09:10 - 00112872 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-18 16:43 - 2013-03-06 08:31 - 00222208 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-18 16:43 - 2013-03-06 08:29 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-18 16:43 - 2013-03-06 07:03 - 00199168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-18 16:09 - 2013-03-15 02:17 - 00861184 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys 2013-05-18 13:08 - 2013-03-22 05:49 - 02382336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\esent.dll 2013-05-18 13:08 - 2013-03-22 00:47 - 02851840 ____A (Microsoft Corporation) C:\Windows\System32\esent.dll 2013-05-18 08:58 - 2013-04-09 06:51 - 14267904 ____A (Microsoft Corporation) C:\Windows\System32\wmp.dll 2013-05-18 08:58 - 2013-04-09 06:51 - 13648384 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll 2013-05-18 08:58 - 2013-04-09 06:51 - 03552768 ____A (Microsoft Corporation) C:\Windows\System32\tquery.dll 2013-05-18 08:58 - 2013-04-09 06:50 - 02107904 ____A (Microsoft Corporation) C:\Windows\System32\mssrch.dll 2013-05-18 08:58 - 2013-04-08 23:52 - 11878912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-05-18 08:58 - 2013-04-08 23:51 - 10789888 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2013-05-18 08:58 - 2013-04-08 23:51 - 02767360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2013-05-18 08:58 - 2013-04-08 23:51 - 01593344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2013-05-18 08:57 - 2013-04-09 07:33 - 00489576 ____A (Microsoft Corporation) C:\Windows\System32\AudioEng.dll 2013-05-18 08:57 - 2013-04-09 07:33 - 00446792 ____A (Microsoft Corporation) C:\Windows\System32\AudioSes.dll 2013-05-18 08:57 - 2013-04-09 07:33 - 00253544 ____A (Microsoft Corporation) C:\Windows\System32\audiodg.exe 2013-05-18 08:57 - 2013-04-09 07:27 - 00284424 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys 2013-05-18 08:57 - 2013-04-09 07:20 - 00306952 ____A (Microsoft Corporation) C:\Windows\System32\kd_02_10ec.dll 2013-05-18 08:57 - 2013-04-09 07:20 - 00086280 ____A (Microsoft Corporation) C:\Windows\System32\kdnet.dll 2013-05-18 08:57 - 2013-04-09 07:18 - 00077960 ____A (Microsoft Corporation) C:\Windows\System32\kdvm.dll 2013-05-18 08:57 - 2013-04-09 07:17 - 01829408 ____A (Microsoft Corporation) C:\Windows\System32\ntdll.dll 2013-05-18 08:57 - 2013-04-09 06:52 - 00816128 ____A (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00804352 ____A (Microsoft Corporation) C:\Windows\System32\RecoveryDrive.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00373760 ____A (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe 2013-05-18 08:57 - 2013-04-09 06:52 - 00126464 ____A (Microsoft Corporation) C:\Windows\System32\Robocopy.exe 2013-05-18 08:57 - 2013-04-09 06:51 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00595456 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\XpsGdiConverter.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00456704 ____A (Microsoft Corporation) C:\Windows\System32\wpncore.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00391168 ____A (Microsoft Corporation) C:\Windows\System32\Windows.Networking.BackgroundTransfer.dll 2013-05-18 08:57 - 2013-04-09 06:51 - 00367616 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe 2013-05-18 08:57 - 2013-04-09 06:51 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wscsvc.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 01285632 ____A (Microsoft Corporation) C:\Windows\System32\schedsvc.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00745984 ____A (Microsoft Corporation) C:\Windows\System32\mssvp.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00435200 ____A (Microsoft Corporation) C:\Windows\System32\mssph.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00422400 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00414720 ____A (Microsoft Corporation) C:\Windows\System32\GenuineCenter.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00096256 ____A (Microsoft Corporation) C:\Windows\System32\mssprxy.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\msscntrs.dll 2013-05-18 08:57 - 2013-04-09 06:50 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\msshooks.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 01444864 ____A (Microsoft Corporation) C:\Windows\System32\MSAudDecMFT.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00817152 ____A (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00468992 ____A (Microsoft Corporation) C:\Windows\System32\MFMediaEngine.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00281088 ____A (Microsoft Corporation) C:\Windows\System32\mfreadwrite.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\fhengine.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00210432 ____A (Microsoft Corporation) C:\Windows\System32\iuilp.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\dmvdsitf.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00172544 ____A (Microsoft Corporation) C:\Windows\System32\dwmredir.dll 2013-05-18 08:57 - 2013-04-09 06:49 - 00050176 ____A (Microsoft Corporation) C:\Windows\System32\fmifs.dll 2013-05-18 08:57 - 2013-04-09 06:48 - 02303488 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-18 08:57 - 2013-04-09 06:48 - 00785408 ____A (Microsoft Corporation) C:\Windows\System32\audiosrv.dll 2013-05-18 08:57 - 2013-04-09 06:48 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl 2013-05-18 08:57 - 2013-04-09 06:48 - 00169472 ____A (Microsoft Corporation) C:\Windows\System32\AudioEndpointBuilder.dll 2013-05-18 08:57 - 2013-04-09 04:35 - 04038144 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-18 08:57 - 2013-04-09 04:34 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidbth.sys 2013-05-18 08:57 - 2013-04-09 04:34 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys 2013-05-18 08:57 - 2013-04-09 04:34 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys 2013-05-18 08:57 - 2013-04-09 04:33 - 00623104 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srv2.sys 2013-05-18 08:57 - 2013-04-09 04:33 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ndproxy.sys 2013-05-18 08:57 - 2013-04-09 04:32 - 00805376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\PEAuth.sys 2013-05-18 08:57 - 2013-04-09 04:31 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\srvnet.sys 2013-05-18 08:57 - 2013-04-09 04:31 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\wanarp.sys 2013-05-18 08:57 - 2013-04-09 01:44 - 00123880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll 2013-05-18 08:57 - 2013-04-09 01:39 - 01408896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-05-18 08:57 - 2013-04-09 01:37 - 00426024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2013-05-18 08:57 - 2013-04-09 01:37 - 00324368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2013-05-18 08:57 - 2013-04-08 23:52 - 00670208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2013-05-18 08:57 - 2013-04-08 23:52 - 00364544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-05-18 08:57 - 2013-04-08 23:52 - 00302592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2013-05-18 08:57 - 2013-04-08 23:52 - 00171008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2013-05-18 08:57 - 2013-04-08 23:52 - 00106496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2013-05-18 08:57 - 2013-04-08 23:51 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 02035200 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 01113600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSAudDecMFT.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00659456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00656896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00403968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl 2013-05-18 08:57 - 2013-04-08 23:51 - 00361984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00324096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00268800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00214528 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00186880 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00155648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dmvdsitf.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\fmifs.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00035328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2013-05-18 08:57 - 2013-04-08 23:51 - 00010752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2013-05-18 08:57 - 2013-04-05 01:30 - 00503080 ____A (Microsoft Corporation) C:\Windows\System32\ci.dll 2013-05-18 08:57 - 2013-04-03 00:08 - 00387688 ____A C:\Windows\System32\ApnDatabase.xml 2013-05-18 08:57 - 2013-03-30 20:16 - 01403784 ____A (Microsoft Corporation) C:\Windows\System32\winload.efi 2013-05-18 08:57 - 2013-03-30 20:16 - 01267424 ____A (Microsoft Corporation) C:\Windows\System32\winload.exe 2013-05-18 08:57 - 2013-03-29 00:09 - 01217328 ____A (Microsoft Corporation) C:\Windows\System32\winresume.efi 2013-05-18 08:57 - 2013-03-29 00:09 - 01093880 ____A (Microsoft Corporation) C:\Windows\System32\winresume.exe 2013-05-18 08:57 - 2013-03-16 00:05 - 00298456 ____A (Microsoft Corporation) C:\Windows\System32\rsaenh.dll 2013-05-18 08:57 - 2013-03-16 00:05 - 00252928 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll 2013-05-18 08:57 - 2012-12-13 06:00 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2013-05-18 08:57 - 2012-12-13 05:59 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-05-15 19:21 - 2013-04-11 08:40 - 06987528 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-05-15 15:09 - 2013-05-15 15:09 - 00013658 ____A C:\Users\Sarah\Documents\In The Mourning.odt 2013-05-14 20:09 - 2013-01-15 23:06 - 03662237 ____A C:\Users\Sarah\Documents\Dublin pp.pptx 2013-05-14 20:09 - 2012-11-21 18:29 - 01249251 ____A C:\Users\Sarah\Documents\Die spätbyzantinische Zeit-PPP.pptx 2013-05-14 18:50 - 2013-05-14 20:05 - 03351024 ____A C:\Users\Sarah\Documents\Geburten.odp 2013-05-14 18:33 - 2013-05-14 18:33 - 00222253 ____A C:\Users\Sarah\Downloads\Geburten.pptx 2013-05-14 18:20 - 2013-05-14 20:08 - 00023905 ____A C:\Users\Sarah\Documents\BIUK-Geburt.odt 2013-05-13 12:43 - 2013-05-13 21:02 - 00021118 ____A C:\Users\Sarah\Documents\Frankreich- Jahresbericht!.odt 2013-05-13 08:05 - 2013-05-13 08:05 - 00021195 ____A C:\Users\Sarah\Documents\GWK.odt 2013-05-12 21:12 - 2013-05-13 08:03 - 00018534 ____A C:\Users\Sarah\Documents\GWK Handout.odt 2013-05-12 20:59 - 2013-05-12 21:42 - 01952043 ____A C:\Users\Sarah\Documents\GWK PPP.odp 2013-05-12 20:39 - 2013-05-13 08:05 - 00021195 ____A C:\Users\Sarah\Downloads\GWK.odt 2013-05-12 19:48 - 2013-05-12 19:48 - 00164636 ____A C:\Users\Sarah\Downloads\Alte Industrieregionen.pptx 2013-05-09 21:37 - 2013-05-09 21:37 - 00010094 ____A C:\Users\Sarah\Downloads\Unbenannt 1.odt 2013-05-09 21:13 - 2013-05-09 21:13 - 00049103 ____A C:\Users\Sarah\Downloads\Daydreamer.odt 2013-05-08 21:23 - 2013-05-08 21:23 - 00083160 ____A (Avira GmbH) C:\Windows\System32\Drivers\avnetflt.sys 2013-05-05 17:12 - 2013-05-05 17:12 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-05-05 17:11 - 2012-03-14 05:00 - 00385024 ____A (CANON INC.) C:\Windows\System32\CNMLMAR.DLL 2013-05-05 17:11 - 2011-04-27 11:01 - 00373248 ____A (CANON INC.) C:\Windows\System32\CNC_ARL.dll 2013-05-05 17:11 - 2011-04-27 11:00 - 00323584 ____A (CANON INC.) C:\Windows\SysWOW64\CNC_ARL.dll 2013-05-05 17:11 - 2011-03-31 10:07 - 00302080 ____A (CANON INC.) C:\Windows\System32\CNC_ARC.dll 2013-05-05 17:11 - 2011-03-31 10:07 - 00114688 ____A (CANON INC.) C:\Windows\SysWOW64\CNC_ARU.dll 2013-05-05 17:11 - 2011-03-31 10:06 - 00112128 ____A (CANON INC.) C:\Windows\System32\CNC_ARI.dll 2013-05-05 17:11 - 2010-11-29 09:17 - 00063744 ____A C:\Windows\SysWOW64\CNC1752D.TBL 2013-05-05 17:11 - 2008-08-25 18:02 - 00017920 ____A (CANON INC.) C:\Windows\System32\CNHMCA6.dll 2013-05-05 17:11 - 2008-08-25 18:02 - 00015872 ____A (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll 2013-05-05 15:59 - 2013-05-05 15:59 - 00012684 ____A C:\Users\Sarah\Documents\English Presentation.odt 2013-05-04 00:43 - 2013-05-04 00:43 - 00001250 ____A C:\Users\Sarah\Desktop\League of Legends.lnk ==================== One Month Modified Files and Folders ======= 2013-06-03 22:44 - 2013-02-16 16:33 - 00000000 ____D C:\Users\Sarah\AppData\Local\PMB Files 2013-06-03 22:43 - 2013-06-03 22:41 - 01916754 ____A (Farbar) C:\Users\Sarah\Desktop\FRST64.exe 2013-06-03 22:42 - 2012-10-20 02:10 - 01200621 ____A C:\Windows\WindowsUpdate.log 2013-06-03 22:38 - 2013-06-03 22:38 - 00003064 ____A C:\Users\Sarah\Desktop\FSS.txt 2013-06-03 22:37 - 2013-06-03 22:37 - 00355651 ____A (Farbar) C:\Users\Sarah\Downloads\FSS (1).exe 2013-06-03 22:36 - 2013-06-03 22:36 - 00355651 ____A (Farbar) C:\Users\Sarah\Desktop\FSS.exe 2013-06-03 22:35 - 2013-06-03 22:35 - 00021951 ____A C:\Users\Sarah\Desktop\Result.txt 2013-06-03 22:33 - 2013-06-03 22:33 - 00760723 ____A (Farbar) C:\Users\Sarah\Desktop\MiniToolBox.exe 2013-06-03 22:33 - 2012-10-20 11:17 - 00754172 ____A C:\Windows\System32\perfh007.dat 2013-06-03 22:33 - 2012-10-20 11:17 - 00156362 ____A C:\Windows\System32\perfc007.dat 2013-06-03 22:33 - 2012-07-26 09:28 - 01748838 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-03 22:26 - 2013-06-03 22:26 - 00000759 ____A C:\Users\Sarah\Desktop\JRT.txt 2013-06-03 22:24 - 2013-06-03 22:21 - 00000000 ____D C:\JRT 2013-06-03 22:22 - 2013-06-03 22:22 - 00000000 ____D C:\Windows\ERUNT 2013-06-03 22:21 - 2013-06-03 22:21 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Sarah\Desktop\JRT.exe 2013-06-03 22:15 - 2013-02-03 18:41 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-03 22:14 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-03 22:13 - 2013-06-03 22:12 - 00016259 ____A C:\AdwCleaner[S1].txt 2013-06-03 22:13 - 2012-07-26 07:26 - 00262144 __ASH C:\Windows\System32\config\BBI 2013-06-03 22:12 - 2013-02-18 19:49 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Skype 2013-06-03 22:10 - 2013-06-03 22:10 - 00632031 ____A C:\Users\Sarah\Desktop\adwcleaner.exe 2013-06-03 22:01 - 2013-02-03 18:41 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-03 22:00 - 2013-06-03 22:00 - 00015388 ____A C:\Users\Sarah\Desktop\Addition.txt 2013-06-03 22:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru 2013-06-03 21:58 - 2013-06-03 21:58 - 00000000 ____D C:\FRST 2013-06-03 21:57 - 2013-06-03 21:57 - 01356197 ____A (Farbar) C:\Users\Sarah\Downloads\FRST.exe 2013-06-02 16:01 - 2012-12-25 14:44 - 00000000 ____D C:\Users\Sarah\Documents\Fortsetzungsstorys 2013-06-02 15:27 - 2013-06-02 15:27 - 00000000 ____D C:\Users\Sarah\Documents\Neuer Ordner 2013-06-02 12:20 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-06-01 13:23 - 2012-07-26 09:21 - 00051373 ____A C:\Windows\setupact.log 2013-05-28 18:51 - 2013-05-28 18:51 - 00008454 ____A C:\Users\Sarah\AppData\Local\recently-used.xbel 2013-05-27 13:59 - 2013-05-27 13:59 - 00009565 ____A C:\Users\Sarah\Documents\songs.zip 2013-05-27 13:59 - 2013-05-27 13:59 - 00000000 ____D C:\Users\Sarah\Documents\songs 2013-05-26 17:14 - 2013-02-16 16:33 - 00000000 ____D C:\ProgramData\PMB Files 2013-05-26 15:12 - 2013-05-03 14:26 - 00001082 ____A C:\Users\Public\Desktop\Gameforge Live.lnk 2013-05-26 15:12 - 2013-05-03 14:26 - 00000000 ____D C:\Users\Sarah\Downloads\Gameforge Live 2013-05-26 15:12 - 2013-05-03 14:26 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-05-24 20:08 - 2013-05-24 20:08 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2013-05-24 19:32 - 2013-02-20 21:58 - 00000000 ____D C:\Users\Sarah\Documents\Story-Ib 2013-05-24 18:11 - 2013-02-03 18:45 - 00002194 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-05-23 19:20 - 2013-05-22 22:33 - 00027999 ____A C:\Users\Sarah\Documents\Handout-Referat-Deutsch.odt 2013-05-22 21:09 - 2013-05-22 21:06 - 00009511 ____A C:\Users\Sarah\Documents\Unbenannt 1.odt 2013-05-22 20:40 - 2013-05-22 20:40 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone (1).ppt 2013-05-22 19:50 - 2013-01-11 17:41 - 00000000 ____D C:\Users\Sarah\.gimp-2.8 2013-05-21 17:16 - 2013-05-21 17:16 - 00009688 ____A C:\Users\Sarah\Documents\song.tg 2013-05-21 16:35 - 2013-05-21 16:35 - 00866720 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00788896 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00263584 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-05-21 16:35 - 2013-05-21 16:35 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Users\Sarah\.tuxguitar-1.2 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\ProgramData\Sun 2013-05-21 16:35 - 2013-05-21 16:35 - 00000000 ____D C:\Program Files (x86)\Java 2013-05-21 16:35 - 2013-02-03 18:22 - 00000000 ____D C:\users\Sarah 2013-05-21 16:31 - 2013-05-21 16:31 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (2).exe 2013-05-21 16:27 - 2013-05-21 16:27 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21 (1).exe 2013-05-21 16:26 - 2013-05-21 16:26 - 00008299 ____A C:\Users\Sarah\Documents\Untitled.tg 2013-05-21 16:19 - 2013-05-21 16:19 - 00903072 ____A (Oracle Corporation) C:\Users\Sarah\Downloads\chromeinstall-7u21.exe 2013-05-21 16:19 - 2013-05-21 16:19 - 00000960 ____A C:\Users\Public\Desktop\TuxGuitar.lnk 2013-05-21 16:19 - 2013-05-21 16:19 - 00000000 ____D C:\Program Files (x86)\TuxGuitar 2013-05-21 16:18 - 2013-05-21 16:17 - 07715210 ____A (Herac) C:\Users\Sarah\Downloads\tuxguitar-1.2-windows-x86-installer.exe 2013-05-21 12:41 - 2013-05-21 12:41 - 00309752 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-20 19:47 - 2013-01-05 19:07 - 00000000 ____D C:\Users\Sarah\Documents\Youcam 2013-05-20 16:29 - 2013-05-20 16:29 - 00330240 ____A C:\Users\Sarah\Downloads\decamerone.ppt 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\WebApp 2013-05-19 14:43 - 2013-05-19 14:43 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\Lenovo 2013-05-19 14:43 - 2013-05-19 14:42 - 00000000 ____D C:\Users\Sarah\Documents\CyberLink 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\Users\Sarah\Documents\Lenovo 2013-05-19 14:42 - 2013-05-19 14:42 - 00000000 ____D C:\ProgramData\Lenovo 2013-05-19 14:42 - 2013-02-15 17:07 - 00000000 ____D C:\Users\Sarah\AppData\Roaming\CyberLink 2013-05-19 14:25 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData 2013-05-19 14:25 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore 2013-05-17 19:52 - 2013-02-18 19:49 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-05-17 19:52 - 2013-02-18 19:49 - 00000000 ____D C:\ProgramData\Skype 2013-05-17 19:06 - 2012-09-13 20:32 - 00106688 ____A C:\Windows\PFRO.log 2013-05-17 18:09 - 2013-02-08 17:11 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-05-15 15:09 - 2013-05-15 15:09 - 00013658 ____A C:\Users\Sarah\Documents\In The Mourning.odt 2013-05-14 20:08 - 2013-05-14 18:20 - 00023905 ____A C:\Users\Sarah\Documents\BIUK-Geburt.odt 2013-05-14 20:05 - 2013-05-14 18:50 - 03351024 ____A C:\Users\Sarah\Documents\Geburten.odp 2013-05-14 18:33 - 2013-05-14 18:33 - 00222253 ____A C:\Users\Sarah\Downloads\Geburten.pptx 2013-05-13 21:02 - 2013-05-13 12:43 - 00021118 ____A C:\Users\Sarah\Documents\Frankreich- Jahresbericht!.odt 2013-05-13 08:05 - 2013-05-13 08:05 - 00021195 ____A C:\Users\Sarah\Documents\GWK.odt 2013-05-13 08:05 - 2013-05-12 20:39 - 00021195 ____A C:\Users\Sarah\Downloads\GWK.odt 2013-05-13 08:03 - 2013-05-12 21:12 - 00018534 ____A C:\Users\Sarah\Documents\GWK Handout.odt 2013-05-12 21:42 - 2013-05-12 20:59 - 01952043 ____A C:\Users\Sarah\Documents\GWK PPP.odp 2013-05-12 19:48 - 2013-05-12 19:48 - 00164636 ____A C:\Users\Sarah\Downloads\Alte Industrieregionen.pptx 2013-05-09 21:37 - 2013-05-09 21:37 - 00010094 ____A C:\Users\Sarah\Downloads\Unbenannt 1.odt 2013-05-09 21:13 - 2013-05-09 21:13 - 00049103 ____A C:\Users\Sarah\Downloads\Daydreamer.odt 2013-05-08 21:23 - 2013-05-08 21:23 - 00083160 ____A (Avira GmbH) C:\Windows\System32\Drivers\avnetflt.sys 2013-05-07 22:07 - 2013-03-03 08:06 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-05-07 22:07 - 2013-03-03 08:06 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-05-05 17:12 - 2013-05-05 17:12 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-05-05 17:11 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media 2013-05-05 15:59 - 2013-05-05 15:59 - 00012684 ____A C:\Users\Sarah\Documents\English Presentation.odt 2013-05-04 00:43 - 2013-05-04 00:43 - 00001250 ____A C:\Users\Sarah\Desktop\League of Legends.lnk ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit Last Boot: 2013-06-02 08:11 ==================== End Of Log ============================ Geändert von Bun (03.06.2013 um 21:46 Uhr) |
03.06.2013, 21:46 | #9 |
/// the machine /// TB-Ausbilder | Auf seltsamen Link geklickt Dann noch FRST. Wie läuft der Rechner?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2013, 21:49 | #10 |
| Auf seltsamen Link geklickt Der FRST ist da ^^ Also der Rechner läuft, so weit ich das bemerkt habe, eigentlich wie sonst auch. |
03.06.2013, 21:50 | #11 |
/// the machine /// TB-Ausbilder | Auf seltsamen Link geklickt Ey, rumeditieren zählt nit ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2013, 22:11 | #12 |
| Auf seltsamen Link geklickt Ist es normal, dass ESET sehr lange dauert? (nach 12 min bei 25 %) Danke für alles bis jetzt ^^ |
03.06.2013, 22:12 | #13 |
/// the machine /// TB-Ausbilder | Auf seltsamen Link geklickt Ja der dauert schon manchmal 2h oder so
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2013, 22:14 | #14 |
| Auf seltsamen Link geklickt Wäre es dann eigentlich in Ordnung wenn ich ihn über Nacht laufen lasse und morgen erst den Rest erledige, da ich früh raus muss. Oder wäre das ein Risiko? |
03.06.2013, 22:16 | #15 |
| Auf seltsamen Link geklickt Und kaum habe ich das gefragt ist er bei 99% |
Themen zu Auf seltsamen Link geklickt |
angeblich, anmelde, anmelden, befürchtung, direkt, geklickt, geschickt, kommentare, link, link geklickt, malware, melde, melden, natürlich, paypal, seite, seltsame, seltsamen, suspekte, warum |