![]() |
![]() | #1 |
Hallo, ich habe mich mit einer Maleware infiziert, die mein Internet verlangsamt. Diese habe ich mit Malewarebytes gefunden. Da ich noch nicht so viel Ahnung von Virenentfernung und sonstigem habe ersuche ich hier Rat was zu tun ist vielen Dank schon mal im Vorraus. Hier die logdatei von Malewarebytes Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2013.06.10.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16576 Besitzer :: ***** [Administrator] Schutz: Aktiviert 10.06.2013 14:44:53 MBAM-log-2013-06-10 (19-16-35).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|Q:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 339229 Laufzeit: 1 Stunde(n), 26 Minute(n), 22 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Besitzer\Documents\My Games\Titan Quest\titanv18trn.exe (Malware.Packer.as) -> Keine Aktion durchgeführt. (Ende)
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Hi,
__________________Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Hallo,
__________________hier die FRST Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-06-2013 02 Ran by Besitzer (administrator) on 10-06-2013 21:47:32 Running from C:\Users\Besitzer\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.EXE (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\Grinding Gear Games\Path of Exile\Client.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /DTSU2P [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [11406608 2011-12-19] (Intel Corporation) HKLM\...\Run: [LoadFUJ02E3] "C:\Program Files\Fujitsu\FUJ02E3\fuj02e3.exe" [76104 2012-01-16] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] "C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [158024 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] "C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe" [23368 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation) HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-01] () HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.) HKLM-x32\...\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291608 2012-02-06] (Intel Corporation) HKLM-x32\...\Run: [YouCam Service] "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s [255208 2012-03-21] (CyberLink Corp.) HKLM-x32\...\Run: [IndicatorUtility] "C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [48752 2010-09-29] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\WINDOW~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\WINDOW~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google ![]() CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParam eter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll No File CHR Extension: (Google Docs) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (AdBlock) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0 CHR Extension: (League of Legends Events) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnfkjennojjkajjmghdgkibohcnefdk\0.50.1_0 CHR Extension: (Gmail) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-09] (Intel Corporation) S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [638896 2012-03-09] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51280 2010-11-02] (LSI Corporation) S3 megasr1; C:\Windows\system32\drivers\megasr1.sys [806696 2012-02-08] (LSI Corporation, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw00.sys [11471872 2012-02-20] (Intel Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8217064 2012-01-02] (Realtek Semiconductor Corp.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-10 21:46 - 2013-06-10 21:46 - 00000000 ____D C:\FRST 2013-06-10 21:44 - 2013-06-10 21:45 - 01920126 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe 2013-06-10 21:42 - 2013-06-10 21:42 - 01358943 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST.exe 2013-06-10 14:38 - 2013-06-10 14:38 - 00000764 ____A C:\Windows\PFRO.log 2013-06-10 13:47 - 2013-06-10 14:01 - 00000000 ____D C:\Windows\erdnt 2013-06-09 22:09 - 2013-06-09 22:09 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\QuickScan 2013-06-09 21:16 - 2013-06-09 21:16 - 00001119 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-09 21:16 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-06-09 21:15 - 2013-06-09 21:15 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup- 2013-06-09 21:04 - 2013-06-09 21:04 - 00000961 ____A C:\AdwCleaner[R2].txt 2013-06-09 21:03 - 2013-06-09 21:04 - 00000902 ____A C:\AdwCleaner[R1].txt 2013-06-09 21:03 - 2013-06-09 21:03 - 00648201 ____A C:\Users\Besitzer\Downloads\adwcleaner.exe 2013-06-09 16:56 - 2013-06-10 14:38 - 00000280 ____A C:\Windows\setupact.log 2013-06-09 16:56 - 2013-06-09 16:56 - 00000000 ____A C:\Windows\setuperr.log 2013-06-09 16:45 - 2013-05-03 16:15 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-09 16:29 - 2013-06-09 16:29 - 00019302 ____A C:\Users\Besitzer\Documents\cc_20130609_162903.reg 2013-06-08 16:14 - 2013-06-08 16:14 - 00049152 ____A C:\Windows\SysWOW64\apache.dll 2013-06-08 15:54 - 2007-01-03 14:16 - 00040960 ___RA C:\Windows\SysWOW64\psfind.dll 2013-06-08 15:54 - 2006-07-11 18:43 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2013-06-08 15:54 - 2006-07-11 18:35 - 00503808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSVCP71.dll 2013-06-08 15:47 - 2013-06-08 22:27 - 00000000 ____D C:\Program Files (x86)\THQ 2013-06-08 11:16 - 2013-06-09 16:30 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-06-08 11:16 - 2013-06-08 11:16 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Gameforge4d 2013-06-02 23:48 - 2013-06-02 23:48 - 00000000 ____A C:\Windows\SysWOW64\sho8FAF.tmp 2013-06-02 12:06 - 2013-06-02 12:06 - 00000845 ____A C:\Users\Besitzer\AppData\Local\recently-used.xbel 2013-06-02 12:06 - 2013-06-02 12:06 - 00000000 ____D C:\Users\Besitzer\.thumbnails 2013-05-25 19:25 - 2013-06-10 19:14 - 00653004 ____A C:\Windows\WindowsUpdate.log 2013-05-20 22:01 - 2013-05-20 22:01 - 00000000 ____D C:\Users\Besitzer\AVM_Driver 2013-05-16 23:52 - 2013-04-05 08:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-16 23:52 - 2013-04-05 08:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-16 23:52 - 2013-04-05 08:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-16 23:52 - 2013-04-05 08:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-16 23:52 - 2013-04-05 07:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-16 23:52 - 2013-04-05 07:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-16 23:52 - 2013-04-05 06:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-16 23:52 - 2013-04-05 06:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-16 23:52 - 2013-04-05 05:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-05-16 23:52 - 2013-04-05 05:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-05-16 15:56 - 2013-05-16 15:56 - 00000000 ____D C:\Users\Besitzer\Documents\Diablo III 2013-05-16 14:58 - 2013-05-16 15:55 - 00000000 ____D C:\Program Files (x86)\Diablo III 2013-05-16 14:58 - 2013-05-16 15:24 - 00001168 ____A C:\Users\Public\Desktop\Diablo III.lnk 2013-05-16 14:58 - 2013-05-16 15:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-05-16 14:55 - 2013-05-16 14:56 - 00000000 ____D C:\ProgramData\Battle.net 2013-05-16 07:18 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-16 07:18 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-05-16 07:17 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-16 07:17 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-05-16 07:17 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-05-16 07:17 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-16 07:17 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-16 07:17 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-16 07:17 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-16 07:17 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-16 07:17 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-16 07:17 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-16 07:17 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-16 07:17 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-05-13 18:16 - 2013-05-13 18:16 - 00000000 ____A C:\Windows\SysWOW64\sho6B16.tmp 2013-05-12 18:08 - 2013-06-08 22:36 - 00000000 ____D C:\Users\Besitzer\Documents\My Games 2013-05-12 18:07 - 2013-05-12 18:07 - 00002116 ____A C:\Users\Public\Desktop\Path of Exile.lnk 2013-05-12 18:07 - 2013-05-12 18:07 - 00000000 ____D C:\Program Files (x86)\Grinding Gear Games ==================== One Month Modified Files and Folders ======= 2013-06-10 21:48 - 2013-02-01 19:31 - 00000000 ____D C:\Users\Besitzer\AppData\Local\PMB Files 2013-06-10 21:46 - 2013-06-10 21:46 - 00000000 ____D C:\FRST 2013-06-10 21:45 - 2013-06-10 21:44 - 01920126 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe 2013-06-10 21:42 - 2013-06-10 21:42 - 01358943 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST.exe 2013-06-10 21:25 - 2013-02-01 19:00 - 00001114 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-10 20:49 - 2013-05-25 19:25 - 00653004 ____A C:\Windows\WindowsUpdate.log 2013-06-10 14:46 - 2009-07-14 06:45 - 00025872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-10 14:46 - 2009-07-14 06:45 - 00025872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-10 14:39 - 2013-02-01 19:00 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-10 14:39 - 2013-01-28 13:07 - 00000000 ____D C:\Users\Besitzer\Documents\Youcam 2013-06-10 14:38 - 2013-06-10 14:38 - 00000764 ____A C:\Windows\PFRO.log 2013-06-10 14:38 - 2013-06-09 16:56 - 00000280 ____A C:\Windows\setupact.log 2013-06-10 14:38 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-10 14:28 - 2013-02-01 19:31 - 00000000 ____D C:\ProgramData\PMB Files 2013-06-10 14:02 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default 2013-06-10 14:01 - 2013-06-10 13:47 - 00000000 ____D C:\Windows\erdnt 2013-06-10 14:00 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-06-10 12:54 - 2013-04-13 17:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Skype 2013-06-09 22:09 - 2013-06-09 22:09 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\QuickScan 2013-06-09 21:16 - 2013-06-09 21:16 - 00001119 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-09 21:15 - 2013-06-09 21:15 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup- 2013-06-09 21:04 - 2013-06-09 21:04 - 00000961 ____A C:\AdwCleaner[R2].txt 2013-06-09 21:04 - 2013-06-09 21:03 - 00000902 ____A C:\AdwCleaner[R1].txt 2013-06-09 21:03 - 2013-06-09 21:03 - 00648201 ____A C:\Users\Besitzer\Downloads\adwcleaner.exe 2013-06-09 16:56 - 2013-06-09 16:56 - 00000000 ____A C:\Windows\setuperr.log 2013-06-09 16:54 - 2013-04-04 15:39 - 00000000 ____D C:\Program Files (x86)\Steam 2013-06-09 16:45 - 2013-02-01 21:56 - 00000000 ____D C:\Users\Besitzer\Desktop\test 2013-06-09 16:31 - 2013-03-27 22:47 - 00000000 ____D C:\Program Files (x86)\EA Sports 2013-06-09 16:30 - 2013-06-08 11:16 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-06-09 16:29 - 2013-06-09 16:29 - 00019302 ____A C:\Users\Besitzer\Documents\cc_20130609_162903.reg 2013-06-09 15:18 - 2013-06-08 15:47 - 00000000 ____D C:\Program Files (x86)\THQ 2013-06-09 15:18 - 2013-01-28 12:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-08 22:36 - 2013-05-12 18:08 - 00000000 ____D C:\Users\Besitzer\Documents\My Games 2013-06-08 16:14 - 2013-06-08 16:14 - 00049152 ____A C:\Windows\SysWOW64\apache.dll 2013-06-08 11:16 - 2013-06-08 11:16 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Gameforge4d 2013-06-07 23:20 - 2013-02-17 18:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\TS3Client 2013-06-07 07:26 - 2013-02-01 19:01 - 00002193 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-03 06:45 - 2009-07-14 07:08 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-02 23:48 - 2013-06-02 23:48 - 00000000 ____A C:\Windows\SysWOW64\sho8FAF.tmp 2013-06-02 12:09 - 2013-03-06 17:01 - 00000000 ____D C:\Users\Besitzer\.gimp-2.8 2013-06-02 12:06 - 2013-06-02 12:06 - 00000845 ____A C:\Users\Besitzer\AppData\Local\recently-used.xbel 2013-06-02 12:06 - 2013-06-02 12:06 - 00000000 ____D C:\Users\Besitzer\.thumbnails 2013-06-02 12:06 - 2013-01-28 12:32 - 00000000 ____D C:\users\Besitzer 2013-06-01 20:24 - 2013-02-17 18:48 - 00000000 ____D C:\Users\Besitzer\AppData\Local\TeamSpeak 3 Client 2013-05-25 23:19 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-05-21 10:26 - 2013-01-28 22:23 - 00000000 ____D C:\Windows\panther 2013-05-20 22:01 - 2013-05-20 22:01 - 00000000 ____D C:\Users\Besitzer\AVM_Driver 2013-05-19 17:39 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-05-18 01:04 - 2013-01-28 13:30 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\SoftGrid Client 2013-05-17 07:08 - 2009-07-14 06:45 - 00277584 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-16 23:55 - 2013-01-28 22:22 - 00657756 ____A C:\Windows\System32\perfh007.dat 2013-05-16 23:55 - 2013-01-28 22:22 - 00131914 ____A C:\Windows\System32\perfc007.dat 2013-05-16 23:55 - 2009-07-14 07:13 - 01530854 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-16 15:56 - 2013-05-16 15:56 - 00000000 ____D C:\Users\Besitzer\Documents\Diablo III 2013-05-16 15:55 - 2013-05-16 14:58 - 00000000 ____D C:\Program Files (x86)\Diablo III 2013-05-16 15:24 - 2013-05-16 14:58 - 00001168 ____A C:\Users\Public\Desktop\Diablo III.lnk 2013-05-16 15:24 - 2013-05-16 14:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-05-16 14:56 - 2013-05-16 14:55 - 00000000 ____D C:\ProgramData\Battle.net 2013-05-13 18:16 - 2013-05-13 18:16 - 00000000 ____A C:\Windows\SysWOW64\sho6B16.tmp 2013-05-12 18:07 - 2013-05-12 18:07 - 00002116 ____A C:\Users\Public\Desktop\Path of Exile.lnk 2013-05-12 18:07 - 2013-05-12 18:07 - 00000000 ____D C:\Program Files (x86)\Grinding Gear Games ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-03 14:34 Die Addition.txtFRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-06-2013 02 Ran by Besitzer at 2013-06-10 21:49:06 Run: Running from C:\Users\Besitzer\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player ActiveX (Version: Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) Adobe Shockwave Player (Version: Age of Empires II: HD Edition ALPS Touch Pad Driver Apple Application Support (Version: 2.3.3) Apple Mobile Device Support (Version: Apple Software Update (Version: Bonjour (Version: CCleaner (Version: 3.27) Crossfire Europe (Version: 1.144) CyberLink YouCam 5 (Version: 5.0.1521) Diablo III (Version: FIFA 08 (Version: FJ Camera (Version: 6.1.7600.137) Fujitsu Hotkey Utility (Version: Fujitsu MobilityCenter Extension Utility (Version: Fujitsu System Extension Utility (Version: GIMP 2.8.4 (Version: 2.8.4) Google Chrome (Version: 27.0.1453.110) Google Update Helper (Version: High-Definition Video Playback (Version: 7.3.10900.8.0) Intel PROSet Wireless Intel(R) Management Engine Components (Version: Intel(R) OpenCL CPU Runtime Intel(R) Processor Graphics (Version: Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: Intel(R) USB 3.0 eXtensible Host Controller Driver (Version: Intel® PROSet/Wireless WiFi-Software (Version: 15.01.0000.0830) Intel® Trusted Connect Service Client (Version: iTunes (Version: Java 7 Update 21 (Version: 7.0.210) Java Auto Updater (Version: Junk Mail filter update (Version: 14.0.8117.416) League of Legends (Version: 1.3) LIFEBOOK Application Panel (Version: Malwarebytes Anti-Malware Version (Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Age of Empires II Microsoft Age of Empires II: The Conquerors Expansion Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Choice Guard (Version: Microsoft Office 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (Version: 14.0.4763.1000) Microsoft Security Client (Version: 4.2.0223.1) Microsoft Security Essentials (Version: Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (Version: 11.0.51106.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (Version: 11.0.51106.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (Version: 11.0.51106) MinecraftAlpha MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Nero 10 Movie ThemePack Basic (Version: 10.6.10000.1.0) Nero BurnRights 10 Help (CHM) (Version: 10.6.10700) Nero Control Center 10 (Version: 10.6.12700.0.7) Nero ControlCenter 10 Help (CHM) (Version: 10.6.10800) Nero Core Components 10 (Version: 2.0.20000.9.12) Nero CoverDesigner 10 Help (CHM) (Version: 10.6.10700) Nero InfoTool 10 Help (CHM) (Version: 10.6.10700) Nero Multimedia Suite 10 Essentials (Version: 10.6.10200) Nero StartSmart 10 (Version: 10.6.10400.2.100) Nero StartSmart 10 Help (CHM) (Version: 10.6.10700) Nero Update (Version: 1.0.10900.31.0) NeroKwikMedia Help (CHM) (Version: 10.6.10900) Pando Media Booster (Version: Path of Exile (Version: Plugfree NETWORK (Version: Plugfree NETWORK (Version: 6.2.001) Power Saving Utility (Version: Realtek Ethernet Controller Driver (Version: 7.49.927.2011) Realtek High Definition Audio Driver (Version: Realtek USB 2.0 Card Reader (Version: 6.1.7601.30129) Skype™ 6.3 (Version: 6.3.105) Steam (Version: TeamSpeak 3 Client (Version: Titan Quest (Version: 1.00.0000) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Vocup 1.4.3 (Version: 1.4.3) Warcraft III Windows Live Anmelde-Assistent (Version: 5.000.818.5) Windows Live Call (Version: 14.0.8117.0416) Windows Live Communications Platform (Version: 14.0.8117.416) Windows Live Essentials (Version: 14.0.8117.0416) Windows Live Essentials (Version: 14.0.8117.416) Windows Live Fotogalerie (Version: 14.0.8117.416) Windows Live Mail (Version: 14.0.8117.0416) Windows Live Messenger (Version: 14.0.8117.0416) Windows Live Movie Maker (Version: 14.0.8117.0416) Windows Live Sync (Version: 14.0.8117.416) Windows Live Writer (Version: 14.0.8117.0416) Windows Live-Uploadtool (Version: 14.0.8014.1029) WinRAR 4.20 (32-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 31-05-2013 17:18:00 Windows Update 04-06-2013 14:05:44 Windows Update 08-06-2013 08:29:41 Windows Update 08-06-2013 09:21:25 DirectX wurde installiert 08-06-2013 13:47:28 Installiert Titan Quest 08-06-2013 13:54:55 DirectX wurde installiert 08-06-2013 20:26:52 Installiert Titan Quest Immortal Throne 08-06-2013 20:31:52 DirectX wurde installiert 09-06-2013 12:43:27 Entfernt Titan Quest Immortal Throne 09-06-2013 14:29:29 Removed osu! 09-06-2013 14:31:00 Removed FIFA 11 09-06-2013 14:45:10 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/10/2013 08:33:23 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2499354 Error: (06/10/2013 08:33:23 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2499354 Error: (06/10/2013 08:33:23 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2013 07:51:51 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7051 Error: (06/10/2013 07:51:51 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7051 Error: (06/10/2013 07:51:51 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2013 07:51:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6006 Error: (06/10/2013 07:51:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6006 Error: (06/10/2013 07:51:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2013 07:51:49 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5008 System errors: ============= Error: (06/10/2013 02:38:53 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (06/10/2013 02:00:38 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2013 02:00:13 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (06/10/2013 01:58:46 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2013 00:53:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (06/10/2013 06:42:51 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (06/09/2013 10:35:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (06/09/2013 04:56:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (06/09/2013 03:19:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Error: (06/09/2013 09:48:03 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%-2147196306 Microsoft Office Sessions: ========================= Error: (06/10/2013 08:33:23 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2499354 Error: (06/10/2013 08:33:23 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2499354 Error: (06/10/2013 08:33:23 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2013 07:51:51 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7051 Error: (06/10/2013 07:51:51 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7051 Error: (06/10/2013 07:51:51 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2013 07:51:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6006 Error: (06/10/2013 07:51:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6006 Error: (06/10/2013 07:51:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2013 07:51:49 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5008 CodeIntegrity Errors: =================================== Date: 2013-06-10 20:36:00.078 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 19:14:33.355 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 16:11:16.422 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 14:38:45.518 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 14:22:06.801 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 14:00:13.150 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-10 14:00:13.134 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-10 12:53:30.459 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 06:51:32.591 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-10 06:42:22.409 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\sxs.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 96% Total physical RAM: 3956.3 MB Available physical RAM: 118.96 MB Total Pagefile: 7910.79 MB Available Pagefile: 2452.17 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:207.86 GB) NTFS (Disk=0 Partition=2) Drive d: (TQGOLD) (CDROM) (Total:4.39 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: BEBC961E) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Hi, Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Hallo, hier die Logdatei
ATTFilter ComboFix 13-06-08.02 - Besitzer 11.06.2013 13:46:42.2.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3956.2499 [GMT 2:00] ausgeführt von:: c:\users\Besitzer\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2013-05-11 bis 2013-06-11 )))))))))))))))))))))))))))))) . . 2013-06-11 11:51 . 2013-06-11 11:51 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-06-10 19:46 . 2013-06-10 19:46 -------- d-----w- C:\FRST 2013-06-10 13:03 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0FCCB965-E780-424F-83B4-B896C59A376E}\mpengine.dll 2013-06-09 20:09 . 2013-06-09 20:09 -------- d-----w- c:\users\Besitzer\AppData\Roaming\QuickScan 2013-06-09 19:16 . 2013-06-09 19:16 -------- d-----w- c:\users\Besitzer\AppData\Roaming\Malwarebytes 2013-06-09 19:16 . 2013-06-09 19:16 -------- d-----w- c:\programdata\Malwarebytes 2013-06-09 19:16 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-06-09 19:16 . 2013-06-09 19:16 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-06-09 14:45 . 2013-05-03 14:15 75016696 ----a-w- c:\windows\system32\MRT.exe 2013-06-09 11:30 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-06-08 14:14 . 2013-06-08 14:14 49152 ----a-w- c:\windows\SysWow64\apache.dll 2013-06-08 13:54 . 2007-01-03 12:16 40960 ----a-r- c:\windows\SysWow64\psfind.dll 2013-06-08 13:54 . 2006-07-11 16:43 1060864 ----a-w- c:\windows\SysWow64\mfc71.dll 2013-06-08 13:54 . 2006-07-11 16:35 503808 ----a-w- c:\windows\SysWow64\MSVCP71.dll 2013-06-08 13:47 . 2013-06-09 13:18 -------- d-----w- c:\program files (x86)\THQ 2013-06-08 09:16 . 2013-06-08 09:16 -------- d-----w- c:\users\Besitzer\AppData\Local\Gameforge4d 2013-06-08 09:16 . 2013-06-09 14:30 -------- d-----w- c:\program files (x86)\GameforgeLive 2013-06-02 21:48 . 2013-06-02 21:48 0 ----a-w- c:\windows\SysWow64\sho8FAF.tmp 2013-06-02 10:06 . 2013-06-02 10:06 -------- d-----w- c:\users\Besitzer\.thumbnails 2013-05-22 11:48 . 2013-05-22 11:43 964552 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{62906956-FD61-48FE-B106-8B75B064A89B}\gapaengine.dll 2013-05-20 20:01 . 2013-05-20 20:01 -------- d-----w- c:\users\Besitzer\AVM_Driver 2013-05-20 19:53 . 2013-05-20 19:53 -------- d-----w- c:\users\Besitzer\AppData\Local\ElevatedDiagnostics 2013-05-16 12:58 . 2013-05-16 13:55 -------- d-----w- c:\program files (x86)\Diablo III 2013-05-16 12:58 . 2013-05-16 13:24 -------- d-----w- c:\programdata\Blizzard Entertainment 2013-05-16 12:55 . 2013-05-16 12:56 -------- d-----w- c:\programdata\Battle.net 2013-05-16 05:18 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-05-16 05:18 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-05-16 05:17 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll 2013-05-16 05:17 . 2013-02-27 05:52 14172672 ----a-w- c:\windows\system32\shell32.dll 2013-05-16 05:17 . 2013-02-27 05:48 1930752 ----a-w- c:\windows\system32\authui.dll 2013-05-16 05:17 . 2013-02-27 05:52 197120 ----a-w- c:\windows\system32\shdocvw.dll 2013-05-16 05:17 . 2013-02-27 06:02 111448 ----a-w- c:\windows\system32\consent.exe 2013-05-16 05:17 . 2013-02-27 05:47 70144 ----a-w- c:\windows\system32\appinfo.dll 2013-05-16 05:17 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\SysWow64\authui.dll 2013-05-16 05:17 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll 2013-05-16 05:17 . 2013-03-19 05:53 230400 ----a-w- c:\windows\system32\wwansvc.dll 2013-05-16 05:17 . 2013-04-10 03:30 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-05-13 16:16 . 2013-05-13 16:16 0 ----a-w- c:\windows\SysWow64\sho6B16.tmp 2013-05-12 16:07 . 2013-05-12 16:07 -------- d-----w- c:\program files (x86)\Grinding Gear Games . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-02 15:29 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-04-23 21:41 . 2013-03-12 19:08 905296 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2013-04-13 05:49 . 2013-05-16 05:17 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-16 05:17 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-16 05:17 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-16 05:17 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-16 05:17 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-16 05:17 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-24 12:57 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-04 03:35 . 2013-05-04 09:10 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-03-30 21:33 . 2013-03-30 21:33 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll 2013-03-22 22:28 . 2013-03-22 22:28 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-03-22 22:28 . 2013-03-22 22:28 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-03-22 22:28 . 2013-03-22 22:28 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-03-22 22:28 . 2013-03-22 22:28 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-03-22 22:28 . 2013-03-22 22:28 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-03-22 22:28 . 2013-03-22 22:28 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-03-22 22:28 . 2013-03-22 22:28 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-03-22 22:28 . 2013-03-22 22:28 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-03-22 22:28 . 2013-03-22 22:28 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-03-22 22:28 . 2013-03-22 22:28 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-03-22 22:28 . 2013-03-22 22:28 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-03-22 22:28 . 2013-03-22 22:28 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-03-22 22:28 . 2013-03-22 22:28 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-03-22 22:28 . 2013-03-22 22:28 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-03-22 22:28 . 2013-03-22 22:28 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-03-22 22:28 . 2013-03-22 22:28 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-03-22 22:28 . 2013-03-22 22:28 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-03-22 22:28 . 2013-03-22 22:28 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-03-22 22:28 . 2013-03-22 22:28 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-03-22 22:28 . 2013-03-22 22:28 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-03-22 22:28 . 2013-03-22 22:28 81408 ----a-w- c:\windows\system32\icardie.dll 2013-03-22 22:28 . 2013-03-22 22:28 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-03-22 22:28 . 2013-03-22 22:28 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-03-22 22:28 . 2013-03-22 22:28 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-03-22 22:28 . 2013-03-22 22:28 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-03-22 22:28 . 2013-03-22 22:28 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-03-22 22:28 . 2013-03-22 22:28 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-03-22 22:28 . 2013-03-22 22:28 441856 ----a-w- c:\windows\system32\html.iec 2013-03-22 22:28 . 2013-03-22 22:28 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-03-22 22:28 . 2013-03-22 22:28 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-03-22 22:28 . 2013-03-22 22:28 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-03-22 22:28 . 2013-03-22 22:28 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-03-22 22:28 . 2013-03-22 22:28 235008 ----a-w- c:\windows\system32\url.dll 2013-03-22 22:28 . 2013-03-22 22:28 216064 ----a-w- c:\windows\system32\msls31.dll 2013-03-22 22:28 . 2013-03-22 22:28 197120 ----a-w- c:\windows\system32\msrating.dll 2013-03-22 22:28 . 2013-03-22 22:28 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-03-22 22:28 . 2013-03-22 22:28 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-03-22 22:28 . 2013-03-22 22:28 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-03-22 22:28 . 2013-03-22 22:28 149504 ----a-w- c:\windows\system32\occache.dll 2013-03-22 22:28 . 2013-03-22 22:28 144896 ----a-w- c:\windows\system32\wextract.exe 2013-03-22 22:28 . 2013-03-22 22:28 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-03-22 22:28 . 2013-03-22 22:28 13824 ----a-w- c:\windows\system32\mshta.exe 2013-03-22 22:28 . 2013-03-22 22:28 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-03-22 22:28 . 2013-03-22 22:28 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-03-22 22:28 . 2013-03-22 22:28 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-03-22 22:28 . 2013-03-22 22:28 102912 ----a-w- c:\windows\system32\inseng.dll 2013-03-22 22:28 . 2013-03-22 22:28 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-03-22 22:28 . 2013-03-22 22:28 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-03-22 22:28 . 2013-03-22 22:28 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-03-19 06:04 . 2013-04-10 12:18 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 05:46 . 2013-04-10 12:18 43520 ----a-w- c:\windows\system32\csrsrv.dll 2013-03-19 05:04 . 2013-04-10 12:18 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 12:18 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47 . 2013-04-10 12:18 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll 2013-03-19 03:06 . 2013-04-10 12:18 112640 ----a-w- c:\windows\system32\smss.exe 2013-03-16 09:21 . 2013-02-16 13:34 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-03-16 09:21 . 2013-02-16 13:34 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-02-01 3093624] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-02-28 18642024] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-02-06 291608] "YouCam Service"="c:\program files (x86)\CyberLink\YouCam\YouCamService.exe" [2012-03-21 255208] "IndicatorUtility"="c:\program files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2010-09-29 48752] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x] R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protokoll;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 iaStorS;iaStorS;c:\windows\system32\drivers\iaStorS.sys;c:\windows\SYSNATIVE\drivers\iaStorS.sys [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] R3 megasas2;megasas2;c:\windows\system32\drivers\megasas2.sys;c:\windows\SYSNATIVE\drivers\megasas2.sys [x] R3 megasr1;megasr1;c:\windows\system32\drivers\megasr1.sys;c:\windows\SYSNATIVE\drivers\megasr1.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x] R3 tihub3;TI USB3 Hub Service;c:\windows\system32\drivers\tihub3.sys;c:\windows\SYSNATIVE\drivers\tihub3.sys [x] R3 tixhci;TI XHCI Service;c:\windows\system32\drivers\tixhci.sys;c:\windows\SYSNATIVE\drivers\tixhci.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 X6va012;X6va012;c:\windows\SysWOW64\Drivers\X6va012;c:\windows\SysWOW64\Drivers\X6va012 [x] S0 FBIOSDRV;Fujitsu BIOS Driver;c:\windows\System32\Drivers\FBIOSDRV.sys;c:\windows\SYSNATIVE\Drivers\FBIOSDRV.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\drivers\iusb3hcs.sys;c:\windows\SYSNATIVE\drivers\iusb3hcs.sys [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DTSAudioSvc;DTSAudioSvc;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [x] S2 FUJ02E3Service;FUJ02E3Service;c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe;c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 PFNService;PFNService;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe;c:\program files\Fujitsu\Plugfree NETWORK\PFNService.exe [x] S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe;c:\program files\Fujitsu\PSUtility\PSUService.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed - Virtueller Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\DRIVERS\FUJ02E3.sys;c:\windows\SYSNATIVE\DRIVERS\FUJ02E3.sys [x] S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 rtsuvc;FJ Camera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-06-07 05:25 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01 17:00] . 2013-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-02-01 17:00] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-03-25 170264] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-03-25 398616] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-03-25 439064] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-13 13374568] "RtHDVBg_DTS"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-11-15 2277992] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2011-12-20 589176] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-12-19 11406608] "LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\fuj02e3.exe" [2012-01-16 76104] "PSUTility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2011-10-03 205168] "LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2011-09-30 158024] "LoadBtnHnd"="c:\program files\Fujitsu\Application Panel\BtnHnd.exe" [2011-09-30 23368] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = . - - - - Entfernte verwaiste Registrierungseinträge - - - - . AddRemove-Adobe Shockwave Player - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va012] "ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va012" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}] @Denied: (A 2) (Everyone) @="FlashProp Class" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.9" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9d.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9d.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}] @Denied: (A 2) (Everyone) @="IFlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-06-11 13:52:33 ComboFix-quarantined-files.txt 2013-06-11 11:52 . Vor Suchlauf: 16 Verzeichnis(se), 230.900.953.088 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 230.838.681.600 Bytes frei . - - End Of File - - 564C0FA440542F782BC2F2ADE71B2890 D41D8CD98F00B204E9800998ECF8427E |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Hi, Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST Logfile. Noch Probleme?
__________________ --> Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe hallo, ich habe ein Problem bei der Benutzung von Security Check Es wird folgende Fehlermeldung angezeigt UNSUPPORTED OPERATING SYSTEM! ABORTED!
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Lass das weg
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Okay, vielen dank, jedoch ist mein Internet noch immer ein wenig lahm. Hier die Adw Logdatei
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Professional x64 Ran by Besitzer on 11.06.2013 at 14:32:01,60 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\sho4BF5.tmp Successfully deleted: [File] C:\Windows\syswow64\sho6B16.tmp Successfully deleted: [File] C:\Windows\syswow64\sho8FAF.tmp ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.06.2013 at 14:35:17,15 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Eset Logdatei ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43 # engine=14047 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-06-11 05:10:54 # local_time=2013-06-11 07:10:54 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 11566108 122600504 0 0 # scanned=100248 # found=0 # cleaned=0 # scan_time=16116 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=afa2ed7bdd84804988f3b9d4436aeb43 # engine=14049 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-06-11 06:48:10 # local_time=2013-06-11 08:48:10 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 11571944 122606340 0 0 # scanned=142381 # found=0 # cleaned=0 # scan_time=5483 |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Sehr schön, dann frisches FRST. Und meine Frage beantworten bitte
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Oh entschuldigung, eigentlich so gut wie keine mehr nur, dass mein Internet immer noch recht lahm ist, was dann wahrscheinlich einen anderen Grund hat C:\Program Files\Bonjour\mDNSResponder.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\PSUService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\PSUtility\TrayManager.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (FUJITSU LIMITED) C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNAutoCon.exe (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNetDm.EXE (FUJITSU LIMITED) C:\Program Files\Fujitsu\Plugfree NETWORK\PFNTray.EXE (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe (Blizzard Entertainment) C:\Program Files (x86)\Diablo III\Diablo III.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Besitzer\Downloads\FRST64 (2).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [13374568 2011-12-13] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /DTSU2P [2277992 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe [589176 2011-12-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [11406608 2011-12-19] (Intel Corporation) HKLM\...\Run: [LoadFUJ02E3] "C:\Program Files\Fujitsu\FUJ02E3\fuj02e3.exe" [76104 2012-01-16] (FUJITSU LIMITED) HKLM\...\Run: [PSUTility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [205168 2011-10-03] (FUJITSU LIMITED) HKLM\...\Run: [LoadFujitsuQuickTouch] "C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe" [158024 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [LoadBtnHnd] "C:\Program Files\Fujitsu\Application Panel\BtnHnd.exe" [23368 2011-09-30] (FUJITSU LIMITED) HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation) HKCU\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-02-01] () HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [291608 2012-02-06] (Intel Corporation) HKLM-x32\...\Run: [YouCam Service] "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s [255208 2012-03-21] (CyberLink Corp.) HKLM-x32\...\Run: [IndicatorUtility] "C:\Program Files (x86)\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [48752 2010-09-29] (FUJITSU LIMITED) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\WINDOW~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\WINDOW~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google ![]() CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParam eter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll No File CHR Extension: (Google Docs) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (AdBlock) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.63_0 CHR Extension: (League of Legends Events) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnfkjennojjkajjmghdgkibohcnefdk\0.50.1_0 CHR Extension: (Gmail) - C:\Users\Besitzer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [225280 2011-08-05] (DTS, Inc) R2 FUJ02E3Service; C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [76104 2012-01-16] (FUJITSU LIMITED) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] () R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 PFNService; C:\Program Files\Fujitsu\Plugfree NETWORK\PFNService.exe [2213376 2011-12-22] (FUJITSU LIMITED) R2 PowerSavingUtilityService; C:\Program Files\Fujitsu\PSUtility\PSUService.exe [63856 2011-10-03] (FUJITSU LIMITED) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 FBIOSDRV; C:\Windows\System32\Drivers\FBIOSDRV.sys [21104 2009-06-24] (FUJITSU LIMITED) R3 FUJ02B1; C:\Windows\System32\DRIVERS\FUJ02B1.sys [7808 2006-11-01] (FUJITSU LIMITED) R3 FUJ02E3; C:\Windows\System32\DRIVERS\FUJ02E3.sys [7296 2006-11-01] (FUJITSU LIMITED) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-09] (Intel Corporation) S3 iaStorS; C:\Windows\system32\drivers\iaStorS.sys [638896 2012-03-09] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 megasas2; C:\Windows\system32\drivers\megasas2.sys [51280 2010-11-02] (LSI Corporation) S3 megasr1; C:\Windows\system32\drivers\megasr1.sys [806696 2012-02-08] (LSI Corporation, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw00.sys [11471872 2012-02-20] (Intel Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8217064 2012-01-02] (Realtek Semiconductor Corp.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-11 21:21 - 2013-06-11 21:22 - 01920158 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64 (2).exe 2013-06-11 21:13 - 2013-06-11 21:14 - 01920158 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64 (1).exe 2013-06-11 19:15 - 2013-06-11 19:15 - 02347384 ____A (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (2).exe 2013-06-11 19:14 - 2013-06-11 19:15 - 00890839 ____A C:\Users\Besitzer\Downloads\SecurityCheck (1).exe 2013-06-11 19:13 - 2013-06-11 19:15 - 02347384 ____A (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (1).exe 2013-06-11 19:13 - 2013-06-11 19:13 - 00890839 ____A C:\Users\Besitzer\Downloads\SecurityCheck.exe 2013-06-11 14:38 - 2013-06-11 14:38 - 02347384 ____A (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu.exe 2013-06-11 14:38 - 2013-06-11 14:38 - 00000000 ____D C:\Program Files (x86)\ESET 2013-06-11 14:35 - 2013-06-11 14:35 - 00000816 ____A C:\Users\Besitzer\Desktop\JRT.txt 2013-06-11 14:31 - 2013-06-11 14:31 - 00001019 ____A C:\Users\Besitzer\Desktop\AdwCleaner[S1].txt 2013-06-11 14:31 - 2013-06-11 14:31 - 00000000 ____D C:\Windows\ERUNT 2013-06-11 14:31 - 2013-06-11 14:31 - 00000000 ____D C:\JRT 2013-06-11 14:29 - 2013-06-11 14:31 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Besitzer\Downloads\JRT.exe 2013-06-11 14:24 - 2013-06-11 14:24 - 00001026 ____A C:\AdwCleaner[S1].txt 2013-06-11 14:23 - 2013-06-11 14:23 - 00648201 ____A C:\Users\Besitzer\Downloads\adwcleaner (1).exe 2013-06-11 13:52 - 2013-06-11 13:52 - 00026873 ____A C:\ComboFix.txt 2013-06-11 13:45 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-06-11 13:45 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-06-11 13:45 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-06-11 13:45 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-06-11 13:45 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-06-11 13:45 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-06-11 13:45 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-06-11 13:45 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-06-11 13:41 - 2013-06-11 13:52 - 00000000 ____D C:\Qoobox 2013-06-11 13:40 - 2013-06-11 13:40 - 05078680 ____R (Swearware) C:\Users\Besitzer\Downloads\ComboFix.exe 2013-06-10 21:49 - 2013-06-10 21:49 - 00015748 ____A C:\Users\Besitzer\Downloads\Addition.txt 2013-06-10 21:46 - 2013-06-10 21:46 - 00000000 ____D C:\FRST 2013-06-10 21:44 - 2013-06-10 21:45 - 01920126 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe 2013-06-10 21:42 - 2013-06-10 21:42 - 01358943 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST.exe 2013-06-10 14:38 - 2013-06-11 14:14 - 00001316 ____A C:\Windows\PFRO.log 2013-06-10 13:47 - 2013-06-10 14:01 - 00000000 ____D C:\Windows\erdnt 2013-06-09 22:09 - 2013-06-09 22:09 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\QuickScan 2013-06-09 21:16 - 2013-06-09 21:16 - 00001119 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-09 21:16 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-06-09 21:15 - 2013-06-09 21:15 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup- 2013-06-09 21:04 - 2013-06-09 21:04 - 00000961 ____A C:\AdwCleaner[R2].txt 2013-06-09 21:03 - 2013-06-09 21:04 - 00000902 ____A C:\AdwCleaner[R1].txt 2013-06-09 21:03 - 2013-06-09 21:03 - 00648201 ____A C:\Users\Besitzer\Downloads\adwcleaner.exe 2013-06-09 16:56 - 2013-06-11 14:26 - 00000448 ____A C:\Windows\setupact.log 2013-06-09 16:56 - 2013-06-09 16:56 - 00000000 ____A C:\Windows\setuperr.log 2013-06-09 16:45 - 2013-05-03 16:15 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-09 16:29 - 2013-06-09 16:29 - 00019302 ____A C:\Users\Besitzer\Documents\cc_20130609_162903.reg 2013-06-08 16:14 - 2013-06-08 16:14 - 00049152 ____A C:\Windows\SysWOW64\apache.dll 2013-06-08 15:54 - 2007-01-03 14:16 - 00040960 ___RA C:\Windows\SysWOW64\psfind.dll 2013-06-08 15:54 - 2006-07-11 18:43 - 01060864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2013-06-08 15:54 - 2006-07-11 18:35 - 00503808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MSVCP71.dll 2013-06-08 15:47 - 2013-06-09 15:18 - 00000000 ____D C:\Program Files (x86)\THQ 2013-06-08 11:16 - 2013-06-09 16:30 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-06-08 11:16 - 2013-06-08 11:16 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Gameforge4d 2013-06-02 12:06 - 2013-06-02 12:06 - 00000845 ____A C:\Users\Besitzer\AppData\Local\recently-used.xbel 2013-06-02 12:06 - 2013-06-02 12:06 - 00000000 ____D C:\Users\Besitzer\.thumbnails 2013-05-25 19:25 - 2013-06-11 19:02 - 00712088 ____A C:\Windows\WindowsUpdate.log 2013-05-20 22:01 - 2013-05-20 22:01 - 00000000 ____D C:\Users\Besitzer\AVM_Driver 2013-05-16 23:52 - 2013-04-05 08:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-16 23:52 - 2013-04-05 08:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-16 23:52 - 2013-04-05 08:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-05-16 23:52 - 2013-04-05 08:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-16 23:52 - 2013-04-05 08:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-05-16 23:52 - 2013-04-05 07:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-16 23:52 - 2013-04-05 07:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-16 23:52 - 2013-04-05 07:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-05-16 23:52 - 2013-04-05 06:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-16 23:52 - 2013-04-05 06:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-16 23:52 - 2013-04-05 05:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-05-16 23:52 - 2013-04-05 05:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-05-16 15:56 - 2013-05-16 15:56 - 00000000 ____D C:\Users\Besitzer\Documents\Diablo III 2013-05-16 14:58 - 2013-05-16 15:55 - 00000000 ____D C:\Program Files (x86)\Diablo III 2013-05-16 14:58 - 2013-05-16 15:24 - 00001168 ____A C:\Users\Public\Desktop\Diablo III.lnk 2013-05-16 14:58 - 2013-05-16 15:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-05-16 14:55 - 2013-05-16 14:56 - 00000000 ____D C:\ProgramData\Battle.net 2013-05-16 07:18 - 2013-04-10 08:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-16 07:18 - 2013-04-10 08:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys 2013-05-16 07:17 - 2013-04-10 05:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-16 07:17 - 2013-03-19 07:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll 2013-05-16 07:17 - 2013-03-19 07:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll 2013-05-16 07:17 - 2013-02-27 08:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe 2013-05-16 07:17 - 2013-02-27 07:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2013-05-16 07:17 - 2013-02-27 07:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll 2013-05-16 07:17 - 2013-02-27 07:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll 2013-05-16 07:17 - 2013-02-27 07:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll 2013-05-16 07:17 - 2013-02-27 06:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-05-16 07:17 - 2013-02-27 06:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-05-16 07:17 - 2013-02-27 06:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-05-16 07:17 - 2011-02-03 13:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-05-12 18:08 - 2013-06-08 22:36 - 00000000 ____D C:\Users\Besitzer\Documents\My Games 2013-05-12 18:07 - 2013-05-12 18:07 - 00002116 ____A C:\Users\Public\Desktop\Path of Exile.lnk 2013-05-12 18:07 - 2013-05-12 18:07 - 00000000 ____D C:\Program Files (x86)\Grinding Gear Games ==================== One Month Modified Files and Folders ======= 2013-06-11 21:22 - 2013-06-11 21:21 - 01920158 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64 (2).exe 2013-06-11 21:22 - 2013-02-01 19:31 - 00000000 ____D C:\Users\Besitzer\AppData\Local\PMB Files 2013-06-11 21:14 - 2013-06-11 21:13 - 01920158 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64 (1).exe 2013-06-11 21:11 - 2013-04-13 17:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Skype 2013-06-11 20:49 - 2013-05-25 19:25 - 00712088 ____A C:\Windows\WindowsUpdate.log 2013-06-11 20:25 - 2013-02-01 19:00 - 00001114 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-11 19:15 - 2013-06-11 19:15 - 02347384 ____A (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (2).exe 2013-06-11 19:15 - 2013-06-11 19:14 - 00890839 ____A C:\Users\Besitzer\Downloads\SecurityCheck (1).exe 2013-06-11 19:15 - 2013-06-11 19:13 - 02347384 ____A (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu (1).exe 2013-06-11 19:13 - 2013-06-11 19:13 - 00890839 ____A C:\Users\Besitzer\Downloads\SecurityCheck.exe 2013-06-11 14:38 - 2013-06-11 14:38 - 02347384 ____A (ESET) C:\Users\Besitzer\Downloads\esetsmartinstaller_enu.exe 2013-06-11 14:38 - 2013-06-11 14:38 - 00000000 ____D C:\Program Files (x86)\ESET 2013-06-11 14:35 - 2013-06-11 14:35 - 00000816 ____A C:\Users\Besitzer\Desktop\JRT.txt 2013-06-11 14:34 - 2009-07-14 06:45 - 00025872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-11 14:34 - 2009-07-14 06:45 - 00025872 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-11 14:31 - 2013-06-11 14:31 - 00001019 ____A C:\Users\Besitzer\Desktop\AdwCleaner[S1].txt 2013-06-11 14:31 - 2013-06-11 14:31 - 00000000 ____D C:\Windows\ERUNT 2013-06-11 14:31 - 2013-06-11 14:31 - 00000000 ____D C:\JRT 2013-06-11 14:31 - 2013-06-11 14:29 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Besitzer\Downloads\JRT.exe 2013-06-11 14:28 - 2013-01-28 13:07 - 00000000 ____D C:\Users\Besitzer\Documents\Youcam 2013-06-11 14:27 - 2013-02-01 19:00 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-11 14:26 - 2013-06-09 16:56 - 00000448 ____A C:\Windows\setupact.log 2013-06-11 14:26 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-11 14:24 - 2013-06-11 14:24 - 00001026 ____A C:\AdwCleaner[S1].txt 2013-06-11 14:23 - 2013-06-11 14:23 - 00648201 ____A C:\Users\Besitzer\Downloads\adwcleaner (1).exe 2013-06-11 14:14 - 2013-06-10 14:38 - 00001316 ____A C:\Windows\PFRO.log 2013-06-11 13:52 - 2013-06-11 13:52 - 00026873 ____A C:\ComboFix.txt 2013-06-11 13:52 - 2013-06-11 13:41 - 00000000 ____D C:\Qoobox 2013-06-11 13:51 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-06-11 13:40 - 2013-06-11 13:40 - 05078680 ____R (Swearware) C:\Users\Besitzer\Downloads\ComboFix.exe 2013-06-10 21:49 - 2013-06-10 21:49 - 00015748 ____A C:\Users\Besitzer\Downloads\Addition.txt 2013-06-10 21:46 - 2013-06-10 21:46 - 00000000 ____D C:\FRST 2013-06-10 21:45 - 2013-06-10 21:44 - 01920126 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST64.exe 2013-06-10 21:42 - 2013-06-10 21:42 - 01358943 ____A (Farbar) C:\Users\Besitzer\Downloads\FRST.exe 2013-06-10 14:28 - 2013-02-01 19:31 - 00000000 ____D C:\ProgramData\PMB Files 2013-06-10 14:02 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default 2013-06-10 14:01 - 2013-06-10 13:47 - 00000000 ____D C:\Windows\erdnt 2013-06-09 22:09 - 2013-06-09 22:09 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\QuickScan 2013-06-09 21:16 - 2013-06-09 21:16 - 00001119 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-06-09 21:16 - 2013-06-09 21:16 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-06-09 21:15 - 2013-06-09 21:15 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Besitzer\Downloads\mbam-setup- 2013-06-09 21:04 - 2013-06-09 21:04 - 00000961 ____A C:\AdwCleaner[R2].txt 2013-06-09 21:04 - 2013-06-09 21:03 - 00000902 ____A C:\AdwCleaner[R1].txt 2013-06-09 21:03 - 2013-06-09 21:03 - 00648201 ____A C:\Users\Besitzer\Downloads\adwcleaner.exe 2013-06-09 16:56 - 2013-06-09 16:56 - 00000000 ____A C:\Windows\setuperr.log 2013-06-09 16:54 - 2013-04-04 15:39 - 00000000 ____D C:\Program Files (x86)\Steam 2013-06-09 16:45 - 2013-02-01 21:56 - 00000000 ____D C:\Users\Besitzer\Desktop\test 2013-06-09 16:31 - 2013-03-27 22:47 - 00000000 ____D C:\Program Files (x86)\EA Sports 2013-06-09 16:30 - 2013-06-08 11:16 - 00000000 ____D C:\Program Files (x86)\GameforgeLive 2013-06-09 16:29 - 2013-06-09 16:29 - 00019302 ____A C:\Users\Besitzer\Documents\cc_20130609_162903.reg 2013-06-09 15:18 - 2013-06-08 15:47 - 00000000 ____D C:\Program Files (x86)\THQ 2013-06-09 15:18 - 2013-01-28 12:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-06-08 22:36 - 2013-05-12 18:08 - 00000000 ____D C:\Users\Besitzer\Documents\My Games 2013-06-08 16:14 - 2013-06-08 16:14 - 00049152 ____A C:\Windows\SysWOW64\apache.dll 2013-06-08 11:16 - 2013-06-08 11:16 - 00000000 ____D C:\Users\Besitzer\AppData\Local\Gameforge4d 2013-06-07 23:20 - 2013-02-17 18:49 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\TS3Client 2013-06-07 07:26 - 2013-02-01 19:01 - 00002193 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-03 06:45 - 2009-07-14 07:08 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-02 12:09 - 2013-03-06 17:01 - 00000000 ____D C:\Users\Besitzer\.gimp-2.8 2013-06-02 12:06 - 2013-06-02 12:06 - 00000845 ____A C:\Users\Besitzer\AppData\Local\recently-used.xbel 2013-06-02 12:06 - 2013-06-02 12:06 - 00000000 ____D C:\Users\Besitzer\.thumbnails 2013-06-02 12:06 - 2013-01-28 12:32 - 00000000 ____D C:\users\Besitzer 2013-06-01 20:24 - 2013-02-17 18:48 - 00000000 ____D C:\Users\Besitzer\AppData\Local\TeamSpeak 3 Client 2013-05-25 23:19 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-05-21 10:26 - 2013-01-28 22:23 - 00000000 ____D C:\Windows\panther 2013-05-20 22:01 - 2013-05-20 22:01 - 00000000 ____D C:\Users\Besitzer\AVM_Driver 2013-05-19 17:39 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-05-18 01:04 - 2013-01-28 13:30 - 00000000 ____D C:\Users\Besitzer\AppData\Roaming\SoftGrid Client 2013-05-17 07:08 - 2009-07-14 06:45 - 00277584 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-16 23:55 - 2013-01-28 22:22 - 00657756 ____A C:\Windows\System32\perfh007.dat 2013-05-16 23:55 - 2013-01-28 22:22 - 00131914 ____A C:\Windows\System32\perfc007.dat 2013-05-16 23:55 - 2009-07-14 07:13 - 01530854 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-16 15:56 - 2013-05-16 15:56 - 00000000 ____D C:\Users\Besitzer\Documents\Diablo III 2013-05-16 15:55 - 2013-05-16 14:58 - 00000000 ____D C:\Program Files (x86)\Diablo III 2013-05-16 15:24 - 2013-05-16 14:58 - 00001168 ____A C:\Users\Public\Desktop\Diablo III.lnk 2013-05-16 15:24 - 2013-05-16 14:58 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-05-16 14:56 - 2013-05-16 14:55 - 00000000 ____D C:\ProgramData\Battle.net 2013-05-12 18:07 - 2013-05-12 18:07 - 00002116 ____A C:\Users\Public\Desktop\Path of Exile.lnk 2013-05-12 18:07 - 2013-05-12 18:07 - 00000000 ____D C:\Program Files (x86)\Grinding Gear Games ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit Hallo, ich möchte Anfügen, dass die Probleme allenanscheins Nach doch noch nicht verschwunden ist, denn mein Internet immer noch viel zu langsam ist, so kann ich z.B keine Videos auf Youtube und co flüssig anschauen, was normalerweise immer reibungslos klappte. Anfangs war es nur ein wenig langsam aber nun ist es genauso langsam wie zur Zeit als ich mich mit der Maleware infiziert hatte. |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Schauen wi mal Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden ).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Habe mich mit Maleware (Malware.Packer.as), die mein Internet verlangsamt, infiziert bitte um Hilfe Hallo, Hier die OTL
ATTFilter OTL logfile created on: 12.06.2013 18:38:51 - Run 2 OTL by OldTimer - Version Folder = C:\Users\Besitzer\Downloads 64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16576) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,86 Gb Total Physical Memory | 1,85 Gb Available Physical Memory | 47,92% Memory free 7,73 Gb Paging File | 5,28 Gb Available in Paging File | 68,38% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 297,99 Gb Total Space | 213,66 Gb Free Space | 71,70% Space Free | Partition Type: NTFS Drive D: | 4,39 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF Computer Name: LAPTOPJULIAN | User Name: Besitzer | Logged in as Administrator. 