![]() |
|
Plagegeister aller Art und deren Bekämpfung: Windows 7 startet ausschließlich im abgesichertem Modus...Virus?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #3 | |
![]() | ![]() Windows 7 startet ausschließlich im abgesichertem Modus...Virus? Hi Leo danke,dass du mir helfen möchtest.
__________________Hier ist FRST.txt: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-07-2013 01 Ran by Arthur (administrator) on 23-07-2013 09:55:37 Running from C:\Users\Arthur\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (brother Industries Ltd) C:\Windows\SysWOW64\brsvc01a.exe (brother Industries Ltd) C:\Windows\SysWOW64\brss01a.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\vVX1000.exe (Valve Corporation) E:\steam\Steam.exe (SEC) C:\Program Files\MagicTune Premium\MagicTune.exe () C:\Program Files\MagicTune Premium\GammaTray.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MagicTuneEngine] - C:\Program Files\MagicTune Premium\MagicTuneLauncher.exe [53760 2010-12-14] () HKLM\...\Run: [VX1000] - C:\Windows\vVX1000.exe [762736 2010-05-20] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated) HKCU\...\Run: [Steam] - E:\steam\Steam.exe [1672616 2013-07-10] (Valve Corporation) HKCU\...\Run: [SCheck] - C:\Users\Arthur\AppData\Roaming\SCheck\SCheck.exe [36864 2013-04-10] () HKCU\...\Run: [SSync] - C:\Users\Arthur\AppData\Roaming\SSync\SSync.exe [36864 2013-04-10] () HKCU\...\Run: [DataMgr] - C:\Users\Arthur\AppData\Roaming\DataMgr\DataMgr.exe [168848 2013-06-26] (HTTO Group, Ltd.) HKCU\...\Run: [Intermediate] - C:\Users\Arthur\AppData\Roaming\Intermediate\Intermediate.exe [36864 2013-04-10] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) MountPoints2: {0af69a7e-4464-11e2-b165-0025226e2469} - H:\SETUP.EXE MountPoints2: {e1fbf440-4ac3-11e2-89d0-806e6f6e6963} - G:\Launcher.exe MountPoints2: {ea260789-3e5f-11e2-9259-806e6f6e6963} - H:\LaunchU3.exe -a HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-10-11] (Apple Inc.) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [BCSSync] - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKU\Lena\...\Run: [uTorrent] - "C:\Users\Lena\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x] HKU\Lena\...\Run: [Yontoo Desktop] - "C:\Users\Lena\AppData\Roaming\Yontoo\YontooDesktop.exe" [x] AppInit_DLLs: C:\PROGRA~3\Wincert\WIN64C~1.DLL [8704 2013-02-07] () AppInit_DLLs-x32: c:\progra~3\wincert\win32c~1.dll [7168 2013-02-07] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GammaTray.exe.lnk ShortcutTarget: GammaTray.exe.lnk -> C:\Program Files\MagicTune Premium\GammaTray.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.) Startup: C:\Users\Lena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * bootdeletebootdeletebootdelete ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. StartMenuInternet: IEXPLORE.EXE - "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - {C4AEC36F-CC2C-4C2D-B17B-47B8221E9488} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=4485148048034755&q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=261 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=261 SearchScopes: HKCU - {352FC33D-4B62-40F5-942F-A4E4F3FA10B3} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=8A3D1516-7B37-4981-8DE1-AB52718B43E5&apn_sauid=A0939C45-06D8-451D-BAF3-EA877CBEEE78 SearchScopes: HKCU - {C4AEC36F-CC2C-4C2D-B17B-47B8221E9488} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=4485148048034755&q={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Video downloader - {77BEC163-D389-42c1-91A4-C758846296A5} - No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Video downloader - {77BEC163-D389-42c1-91A4-C758846296A5} - No File BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 193.189.244.202 193.189.244.194 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Arthur\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF HKLM\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKCU\...\Firefox\Extensions: [lyricsmonkey@mendoni.net] C:\Program Files (x86)\LyricsMonkey\FF\ FF Extension: No Name - C:\Program Files (x86)\LyricsMonkey\FF\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.de/", "" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - E:\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - E:\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - E:\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - E:\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - E:\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\Arthur\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (YouTube) - C:\Users\Arthur\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Arthur\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdBlock) - C:\Users\Arthur\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.2_0 CHR Extension: (avast! Online Security) - C:\Users\Arthur\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0 CHR Extension: (Gmail) - C:\Users\Arthur\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [khialnikbocfgkohdegnebhmmaifoglp] - C:\Program Files (x86)\LyricsMonkey\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Arthur\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-14] (brother Industries Ltd) R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [109352 2013-07-14] (SurfRight B.V.) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-22] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-22] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-22] () S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 hitmanpro37; C:\Windows\SysWow64\drivers\hitmanpro37.sys [30616 2013-07-22] () S0 hitmanpro37duringboot; C:\Windows\SysWow64\drivers\hitmanpro37.sys [30616 2013-07-22] () R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 hitmanpro37; \??\C:\Windows\system32\drivers\hitmanpro37.sys [x] S0 hitmanpro37duringboot; system32\drivers\hitmanpro37.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-23 09:55 - 2013-07-23 09:55 - 00000000 ____D C:\FRST 2013-07-23 09:50 - 2013-07-23 09:50 - 01779447 _____ (Farbar) C:\Users\Arthur\Desktop\FRST64.exe 2013-07-22 22:49 - 2013-07-23 01:39 - 00000000 ____D C:\Windows\pss 2013-07-22 20:16 - 2013-07-22 20:16 - 00000132 _____ C:\Users\Arthur\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2013-07-22 20:11 - 2013-07-22 20:13 - 10339263 _____ C:\Users\Arthur\Downloads\Rijk van Nijmegen - Rivieren.mp4 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-22 16:03 - 2013-07-23 01:31 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-22 16:03 - 2013-07-22 16:04 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-22 16:03 - 2013-07-22 16:04 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-22 16:03 - 2013-07-22 16:04 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-22 16:03 - 2013-07-22 16:03 - 00001928 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 16:03 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-07-22 16:03 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-07-22 15:42 - 2013-07-22 15:45 - 117478104 _____ C:\Users\Arthur\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-22 15:39 - 2013-07-22 20:15 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Adobe 2013-07-21 20:28 - 2013-07-21 20:28 - 00000040 ____H C:\1B50C1B368B1 2013-07-21 20:10 - 2013-07-21 20:19 - 294969288 _____ C:\Users\Arthur\Downloads\AfterEffects.rar 2013-07-21 20:10 - 2013-07-21 20:10 - 00000840 _____ C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2013-07-21 20:08 - 2013-07-21 20:08 - 01126480 _____ (BitTorrent Inc.) C:\Users\Arthur\Downloads\utorrent_3.3.1b29812.exe 2013-07-21 17:41 - 2013-07-21 17:41 - 00003504 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-ADDIS-PC-Arthur 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\Documents\Adobe 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PDAppFlex 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Local\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy 2013-07-21 17:35 - 2013-07-21 17:35 - 00000000 ____D C:\Program Files (x86)\My Company Name 2013-07-21 17:35 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys 2013-07-21 17:35 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys 2013-07-21 17:35 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys 2013-07-21 17:24 - 2013-07-21 17:26 - 00000000 ____D C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6 2013-07-20 11:34 - 2013-07-20 11:34 - 00000000 ____D C:\Users\Arthur\Documents\Rockstar Games 2013-07-20 11:14 - 2013-07-20 11:14 - 00000000 __SHD C:\ProgramData\SecuROM 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\SSync 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\SCheck 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Intermediate 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\DataMgr 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PiccShare 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Common 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Users\Arthur\Documents\Games for Windows - LIVE Demos 2013-07-20 10:56 - 2013-07-20 10:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-07-20 10:35 - 2013-07-20 11:14 - 00000000 ____D C:\Users\Arthur\AppData\Local\Rockstar Games 2013-07-20 10:33 - 2013-07-20 10:33 - 00000600 _____ C:\Users\Arthur\Desktop\Grand Theft Auto IV.lnk 2013-07-17 22:48 - 2013-07-17 22:49 - 00000000 ____D C:\Windows\system32\MRT 2013-07-17 08:32 - 2013-07-19 21:57 - 00000214 _____ C:\Users\Arthur\Desktop\rominfo.txt 2013-07-16 18:13 - 2013-07-19 22:22 - 00002048 _____ C:\Users\Arthur\Desktop\Super Mario World.srm 2013-07-16 18:12 - 2013-07-19 22:22 - 00274047 _____ C:\Users\Arthur\Desktop\Super Mario World.zst 2013-07-16 18:08 - 2013-07-19 22:22 - 00274047 _____ C:\Users\Arthur\Desktop\Super Mario World.zss 2013-07-15 21:49 - 2013-07-15 21:49 - 414046739 _____ C:\Windows\MEMORY.DMP 2013-07-15 21:49 - 2013-07-15 21:49 - 00307440 _____ C:\Windows\Minidump\071513-18018-01.dmp 2013-07-15 21:49 - 2013-07-15 21:49 - 00000000 ____D C:\Windows\Minidump 2013-07-15 15:03 - 2013-07-22 22:33 - 00011370 _____ C:\Windows\SysWOW64\.crusader 2013-07-15 15:03 - 2012-08-31 19:57 - 01687408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Drivers\ntfs.sys 2013-07-15 15:03 - 2010-11-20 14:17 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-07-15 15:03 - 2009-07-14 04:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storsvc.dll 2013-07-14 18:20 - 2013-07-22 22:36 - 00030616 _____ C:\Windows\SysWOW64\Drivers\hitmanpro37.sys 2013-07-14 13:17 - 2013-07-14 13:18 - 00000000 ____D C:\Program Files (x86)\Zoom Player 2013-07-11 17:33 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-11 17:33 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-11 17:33 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-11 17:33 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-11 17:33 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-11 17:33 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-11 17:33 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-11 17:33 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-11 17:33 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-11 15:43 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 15:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 15:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-11 15:43 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 15:43 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-11 15:42 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-11 15:42 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-04 19:18 - 2013-07-04 20:30 - 02419006 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz3.ppsx 2013-07-04 18:35 - 2013-07-04 19:18 - 02418995 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz1.pptx 2013-07-04 18:35 - 2013-07-04 18:35 - 02418812 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz2.ppsx 2013-07-04 15:35 - 2013-07-04 15:35 - 00005363 _____ C:\Users\Arthur\Documents\Alcatraz.wlmp 2013-07-04 14:36 - 2013-07-04 15:18 - 02326429 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz.pptx 2013-07-01 18:43 - 2013-07-01 18:43 - 00002218 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-06-25 16:38 - 2013-06-25 16:38 - 00013214 _____ C:\Users\Arthur\Documents\Mathe S.186 Nr 1.xlsx 2013-06-24 21:38 - 2013-06-24 21:38 - 00001473 _____ C:\Users\Arthur\AppData\Local\RecConfig.xml 2013-06-24 21:18 - 2013-06-24 21:19 - 00003992 _____ C:\AdwCleaner[S2].txt 2013-06-24 21:17 - 2013-06-24 21:17 - 00004439 _____ C:\AdwCleaner[R2].txt 2013-06-24 21:15 - 2013-06-24 21:15 - 00648201 _____ C:\Users\Arthur\Downloads\AdwCleaner.exe 2013-06-24 16:36 - 2013-06-24 21:03 - 00515574 _____ C:\spyhunter.fix 2013-06-24 16:04 - 2013-06-24 21:11 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-06-24 16:04 - 2013-06-24 16:04 - 00000000 ____D C:\Program Files (x86)\Enigma Software Group 2013-06-24 16:00 - 2013-07-21 21:49 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\uTorrent ==================== One Month Modified Files and Folders ======= 2013-07-23 09:55 - 2013-07-23 09:55 - 00000000 ____D C:\FRST 2013-07-23 09:54 - 2013-05-13 15:30 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-23 09:54 - 2012-12-17 21:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-07-23 09:54 - 2012-12-12 16:55 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-23 09:52 - 2009-07-14 06:45 - 00014528 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-23 09:52 - 2009-07-14 06:45 - 00014528 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-23 09:51 - 2013-05-13 15:30 - 00000000 ____D C:\Program Files\Microsoft Office 2013-07-23 09:50 - 2013-07-23 09:50 - 01779447 _____ (Farbar) C:\Users\Arthur\Desktop\FRST64.exe 2013-07-23 09:50 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-07-23 09:47 - 2012-12-06 15:33 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Skype 2013-07-23 09:44 - 2013-05-13 16:13 - 00008545 _____ C:\Windows\setupact.log 2013-07-23 09:44 - 2012-12-06 15:01 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-23 09:44 - 2012-12-05 00:34 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-23 09:44 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-23 02:28 - 2012-12-05 00:19 - 01926650 _____ C:\Windows\WindowsUpdate.log 2013-07-23 02:21 - 2012-12-06 15:01 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-23 02:00 - 2012-12-28 22:42 - 00000000 ____D C:\Users\Arthur\AppData\Local\Adobe 2013-07-23 01:44 - 2013-03-30 23:46 - 00000000 ____D C:\Program Files\Adobe 2013-07-23 01:44 - 2012-12-13 14:54 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-23 01:44 - 2012-12-12 16:54 - 00000000 ____D C:\ProgramData\Adobe 2013-07-23 01:43 - 2013-03-30 23:43 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-23 01:39 - 2013-07-22 22:49 - 00000000 ____D C:\Windows\pss 2013-07-23 01:31 - 2013-07-22 16:03 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-22 23:37 - 2013-04-23 20:34 - 00000000 ____D C:\Program Files (x86)\LyricsMonkey 2013-07-22 23:13 - 2013-04-11 17:35 - 00000000 ____D C:\Users\Arthur\AppData\Local\Sony 2013-07-22 23:13 - 2013-04-11 17:35 - 00000000 ____D C:\ProgramData\Sony 2013-07-22 23:10 - 2012-12-19 19:57 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-07-22 23:08 - 2012-12-06 15:01 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-22 23:08 - 2012-12-06 15:01 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-22 23:07 - 2013-02-09 15:44 - 00002952 _____ C:\Windows\System32\Tasks\{23A7EE5B-8126-4140-9EDD-6FB26AA5D81B} 2013-07-22 23:07 - 2012-12-20 18:37 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2013-07-22 23:06 - 2012-12-06 15:01 - 00000000 ____D C:\Users\Arthur\AppData\Local\Google 2013-07-22 23:06 - 2012-12-06 15:01 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-22 22:36 - 2013-07-14 18:20 - 00030616 _____ C:\Windows\SysWOW64\Drivers\hitmanpro37.sys 2013-07-22 22:33 - 2013-07-15 15:03 - 00011370 _____ C:\Windows\SysWOW64\.crusader 2013-07-22 22:33 - 2013-06-02 19:29 - 00000000 ____D C:\Program Files\HitmanPro 2013-07-22 20:16 - 2013-07-22 20:16 - 00000132 _____ C:\Users\Arthur\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2013-07-22 20:15 - 2013-07-22 15:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Adobe 2013-07-22 20:13 - 2013-07-22 20:11 - 10339263 _____ C:\Users\Arthur\Downloads\Rijk van Nijmegen - Rivieren.mp4 2013-07-22 19:37 - 2012-12-06 15:33 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-22 19:37 - 2012-12-06 15:27 - 00000000 ____D C:\ProgramData\Skype 2013-07-22 17:41 - 2009-07-14 19:58 - 00696904 _____ C:\Windows\system32\perfh007.dat 2013-07-22 17:41 - 2009-07-14 19:58 - 00148200 _____ C:\Windows\system32\perfc007.dat 2013-07-22 17:41 - 2009-07-14 07:13 - 01613644 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-22 16:04 - 2013-07-22 16:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-22 16:04 - 2013-07-22 16:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-22 16:04 - 2013-07-22 16:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-22 16:03 - 2013-07-22 16:03 - 00001928 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 16:03 - 2013-04-01 15:52 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-22 16:03 - 2013-04-01 15:52 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-22 16:03 - 2013-04-01 15:51 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-22 15:47 - 2013-04-27 13:52 - 00082000 _____ C:\Windows\PFRO.log 2013-07-22 15:46 - 2013-01-06 22:28 - 00000000 ____D C:\Users\hedev 2013-07-22 15:45 - 2013-07-22 15:42 - 117478104 _____ C:\Users\Arthur\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-22 15:39 - 2009-07-14 06:45 - 05070528 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-21 21:49 - 2013-06-24 16:00 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\uTorrent 2013-07-21 20:28 - 2013-07-21 20:28 - 00000040 ____H C:\1B50C1B368B1 2013-07-21 20:19 - 2013-07-21 20:10 - 294969288 _____ C:\Users\Arthur\Downloads\AfterEffects.rar 2013-07-21 20:10 - 2013-07-21 20:10 - 00000840 _____ C:\Users\Arthur\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2013-07-21 20:08 - 2013-07-21 20:08 - 01126480 _____ (BitTorrent Inc.) C:\Users\Arthur\Downloads\utorrent_3.3.1b29812.exe 2013-07-21 17:41 - 2013-07-21 17:41 - 00003504 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-ADDIS-PC-Arthur 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\Documents\Adobe 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PDAppFlex 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Local\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy 2013-07-21 17:39 - 2012-12-16 13:34 - 00000000 ___HD C:\Users\Arthur\AppData\Local\Il1yeC94tyS 2013-07-21 17:39 - 2012-12-05 01:01 - 00117664 _____ C:\Users\Arthur\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-21 17:38 - 2013-03-30 14:33 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-21 17:35 - 2013-07-21 17:35 - 00000000 ____D C:\Program Files (x86)\My Company Name 2013-07-21 17:26 - 2013-07-21 17:24 - 00000000 ____D C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6 2013-07-20 11:34 - 2013-07-20 11:34 - 00000000 ____D C:\Users\Arthur\Documents\Rockstar Games 2013-07-20 11:14 - 2013-07-20 11:14 - 00000000 __SHD C:\ProgramData\SecuROM 2013-07-20 11:14 - 2013-07-20 10:35 - 00000000 ____D C:\Users\Arthur\AppData\Local\Rockstar Games 2013-07-20 11:14 - 2012-12-06 17:32 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\SSync 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\SCheck 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Intermediate 2013-07-20 11:04 - 2013-07-20 11:04 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\DataMgr 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PiccShare 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Common 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Users\Arthur\Documents\Games for Windows - LIVE Demos 2013-07-20 10:57 - 2013-07-20 10:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-07-20 10:33 - 2013-07-20 10:33 - 00000600 _____ C:\Users\Arthur\Desktop\Grand Theft Auto IV.lnk 2013-07-19 22:22 - 2013-07-16 18:13 - 00002048 _____ C:\Users\Arthur\Desktop\Super Mario World.srm 2013-07-19 22:22 - 2013-07-16 18:12 - 00274047 _____ C:\Users\Arthur\Desktop\Super Mario World.zst 2013-07-19 22:22 - 2013-07-16 18:08 - 00274047 _____ C:\Users\Arthur\Desktop\Super Mario World.zss 2013-07-19 21:57 - 2013-07-17 08:32 - 00000214 _____ C:\Users\Arthur\Desktop\rominfo.txt 2013-07-17 22:49 - 2013-07-17 22:48 - 00000000 ____D C:\Windows\system32\MRT 2013-07-15 21:49 - 2013-07-15 21:49 - 414046739 _____ C:\Windows\MEMORY.DMP 2013-07-15 21:49 - 2013-07-15 21:49 - 00307440 _____ C:\Windows\Minidump\071513-18018-01.dmp 2013-07-15 21:49 - 2013-07-15 21:49 - 00000000 ____D C:\Windows\Minidump 2013-07-14 13:18 - 2013-07-14 13:17 - 00000000 ____D C:\Program Files (x86)\Zoom Player 2013-07-14 13:13 - 2013-05-17 20:20 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\FreeVideoConverter 2013-07-14 13:12 - 2012-12-06 16:00 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\vlc 2013-07-13 21:31 - 2013-05-14 19:18 - 00002189 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-11 18:54 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-11 18:52 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 18:52 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-11 18:52 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-09 20:59 - 2013-02-15 21:25 - 00017408 ____H C:\Users\Arthur\Downloads\photothumb.db 2013-07-09 20:59 - 2012-12-06 21:48 - 00001037 _____ C:\Users\Arthur\Desktop\PhotoScape.lnk 2013-07-09 20:59 - 2012-12-06 21:48 - 00000000 ____D C:\Program Files (x86)\PhotoScape 2013-07-05 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-07-04 20:51 - 2013-01-01 23:52 - 00272384 ___SH C:\Users\Arthur\Documents\Thumbs.db 2013-07-04 20:30 - 2013-07-04 19:18 - 02419006 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz3.ppsx 2013-07-04 19:18 - 2013-07-04 18:35 - 02418995 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz1.pptx 2013-07-04 18:42 - 2013-05-13 15:30 - 00000000 ____D C:\Users\Arthur\AppData\Local\Microsoft Help 2013-07-04 18:41 - 2009-07-14 04:34 - 00000499 _____ C:\Windows\win.ini 2013-07-04 18:35 - 2013-07-04 18:35 - 02418812 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz2.ppsx 2013-07-04 15:35 - 2013-07-04 15:35 - 00005363 _____ C:\Users\Arthur\Documents\Alcatraz.wlmp 2013-07-04 15:32 - 2013-01-01 20:50 - 00000000 ____D C:\Users\Arthur\AppData\Local\Windows Live 2013-07-04 15:18 - 2013-07-04 14:36 - 02326429 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz.pptx 2013-07-04 15:13 - 2009-07-14 20:18 - 00000000 ____D C:\Windows\ShellNew 2013-07-01 18:43 - 2013-07-01 18:43 - 00002218 _____ C:\Users\Public\Desktop\Google Earth.lnk 2013-06-29 23:57 - 2012-12-06 15:33 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk 2013-06-29 22:25 - 2012-12-06 15:27 - 00000000 ____D C:\ProgramData\Avira 2013-06-25 16:38 - 2013-06-25 16:38 - 00013214 _____ C:\Users\Arthur\Documents\Mathe S.186 Nr 1.xlsx 2013-06-24 21:49 - 2013-03-04 21:38 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Audacity 2013-06-24 21:38 - 2013-06-24 21:38 - 00001473 _____ C:\Users\Arthur\AppData\Local\RecConfig.xml 2013-06-24 21:19 - 2013-06-24 21:18 - 00003992 _____ C:\AdwCleaner[S2].txt 2013-06-24 21:17 - 2013-06-24 21:17 - 00004439 _____ C:\AdwCleaner[R2].txt 2013-06-24 21:15 - 2013-06-24 21:15 - 00648201 _____ C:\Users\Arthur\Downloads\AdwCleaner.exe 2013-06-24 21:11 - 2013-06-24 16:04 - 00000000 ____D C:\Windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2013-06-24 21:03 - 2013-06-24 16:36 - 00515574 _____ C:\spyhunter.fix 2013-06-24 16:04 - 2013-06-24 16:04 - 00000000 ____D C:\Program Files (x86)\Enigma Software Group 2013-06-24 00:57 - 2012-12-06 17:46 - 78277128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Files to move or delete: ==================== C:\ProgramData\ntuser.dat ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-13 19:57 ==================== End Of Log ============================ --- --- --- Und hier ist Addition.txt Zitat:
LG Artur |
Themen zu Windows 7 startet ausschließlich im abgesichertem Modus...Virus? |
entfernen, internet, meldung, pc kaputt, problem, programme, reparieren, schwarzer bildschirm, spyhunter, spyhunter entfernen, verschieben, virus, win32/adware.1clickdownload.am, win32/adware.addlyrics.f, win32/adware.yontoo, windows, windows 7, zahlen |