![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Hallo TB Mitglieder, seit einigen Tagen lädt mein Pc anscheinend irgendetwas im Hintergrund ![]() ![]() Geändert von Morfo (30.07.2013 um 19:04 Uhr) |
![]() | #2 |
hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Danke schon mal für deine Hilfe. Ich kann dir nur FRST.txt posten, weil sich kein Addition geöffnet hat
__________________![]() FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-07-2013 03 Ran by Arthur (administrator) on 30-07-2013 21:55:39 Running from C:\Users\Arthur\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (brother Industries Ltd) C:\Windows\SysWOW64\brsvc01a.exe (brother Industries Ltd) C:\Windows\SysWOW64\brss01a.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\vVX1000.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) E:\steam\Steam.exe (SEC) C:\Program Files\MagicTune Premium\MagicTune.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MagicTuneEngine] - C:\Program Files\MagicTune Premium\MagicTuneLauncher.exe [53760 2010-12-14] () HKLM\...\Run: [VX1000] - C:\Windows\vVX1000.exe [762736 2010-05-20] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13626072 2013-07-28] (Realtek Semiconductor) HKCU\...\Run: [Steam] - E:\steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [AdobeBridge] - [x] HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-07-12] (Adobe Systems Incorporated) HKU\Lena\...\Run: [uTorrent] - "C:\Users\Lena\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x] HKU\Lena\...\Run: [Steam] - E:\steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKU\Lena\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKU\Lena\...\Run: [AdobeBridge] - [x] AppInit_DLLs-x32: c:\progra~3\browse~1\261339~1.144\{c16c1~1\browse~1.dll [97280 2009-07-14] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.) Startup: C:\Users\Lena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * bootdeletebootdeletebootdelete ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=261 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Video downloader - {77BEC163-D389-42c1-91A4-C758846296A5} - No File BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Arthur\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF HKLM\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Arthur\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-14] (brother Industries Ltd) S4 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [109352 2013-07-14] (SurfRight B.V.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R0 amdide64; C:\Windows\System32\DRIVERS\amdide64.sys [11904 2013-07-28] (Advanced Micro Devices Inc.) S0 amdkmafd; C:\Windows\System32\DRIVERS\amdkmafd.sys [21160 2013-07-28] (Advanced Micro Devices, Inc.) R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [35936 2013-07-28] (Advanced Micro Devices, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-22] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-22] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-22] () S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 hitmanpro37; C:\Windows\SysWow64\drivers\hitmanpro37.sys [30616 2013-07-22] () S0 hitmanpro37duringboot; C:\Windows\SysWow64\drivers\hitmanpro37.sys [30616 2013-07-22] () R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-19] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 hitmanpro37; \??\C:\Windows\system32\drivers\hitmanpro37.sys [x] S0 hitmanpro37duringboot; system32\drivers\hitmanpro37.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-30 21:54 - 2013-07-30 21:55 - 01781589 _____ (Farbar) C:\Users\Arthur\Downloads\FRST64.exe 2013-07-29 18:58 - 2013-07-29 22:22 - 17052230 _____ C:\Users\Arthur\Downloads\IMAX -Pre Show- Intro (HD 1080p).mp4 2013-07-28 22:39 - 2013-07-28 22:39 - 00007605 _____ C:\Users\Arthur\AppData\Local\Resmon.ResmonCfg 2013-07-28 21:45 - 2013-07-28 21:45 - 00021160 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmafd.sys 2013-07-28 21:34 - 2013-07-28 21:34 - 00011904 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\Drivers\amdide64.sys 2013-07-28 21:14 - 2013-07-28 21:14 - 00035936 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmpfd.sys 2013-07-28 21:12 - 2013-07-28 21:12 - 03760856 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 03462616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-07-28 21:12 - 2013-07-28 21:12 - 02795224 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 02736160 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 02103040 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 02032896 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 01662024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-07-28 21:12 - 2013-07-28 21:12 - 01004248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00920320 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00613448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00602901 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-07-28 21:12 - 2013-07-28 21:12 - 00208072 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00146648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-07-28 21:09 - 2013-07-28 21:09 - 00849992 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-07-28 21:09 - 2013-07-28 21:09 - 00108104 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2013-07-28 21:09 - 2013-07-28 21:09 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-07-28 20:29 - 2013-07-28 20:29 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-28 20:11 - 2013-07-28 20:26 - 05653448 _____ (Uniblue Systems Ltd ) C:\Users\Arthur\Downloads\driverscanner.exe 2013-07-28 20:09 - 2013-07-28 20:20 - 04054000 _____ (LionSea Software ) C:\Users\Arthur\Downloads\setup.exe 2013-07-28 15:11 - 2013-07-28 15:14 - 00000000 ____D C:\Users\Arthur\Downloads\Juli - In Love (2010) - Pop [www.torrentazos.com] 2013-07-28 15:10 - 2013-07-28 15:22 - 00000000 ____D C:\Users\Arthur\Downloads\Silbermond 2013-07-25 18:45 - 2013-07-28 21:13 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-07-25 18:45 - 2013-07-25 18:45 - 00000000 ____D C:\Program Files\Realtek 2013-07-25 18:44 - 2013-07-25 18:44 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-07-25 18:44 - 2013-02-20 18:55 - 01284680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2013-07-25 18:44 - 2013-01-16 16:02 - 02079816 _____ (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll 2013-07-25 18:44 - 2012-06-20 17:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2013-07-25 18:44 - 2012-06-08 16:23 - 00083072 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp64.dll 2013-07-25 18:44 - 2012-06-08 16:21 - 00897152 _____ (Creative Technology Ltd.) C:\Windows\system32\MBAPO64.dll 2013-07-25 18:44 - 2012-06-08 16:21 - 00753280 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\MBAPO32.dll 2013-07-25 18:44 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2013-07-25 18:44 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2013-07-25 18:44 - 2011-12-16 14:57 - 00065112 _____ (Creative Technology Ltd.) C:\Windows\system32\MBppld64.dll 2013-07-25 18:44 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2013-07-25 18:44 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2013-07-25 18:44 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2013-07-25 18:44 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2013-07-25 18:44 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2013-07-25 18:44 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2013-07-25 18:44 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2013-07-25 18:44 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-07-25 18:44 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2013-07-25 18:44 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2013-07-25 18:44 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2013-07-25 18:44 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2013-07-25 18:44 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2013-07-25 18:44 - 2009-11-18 07:13 - 00060504 _____ (Creative Technology Ltd.) C:\Windows\system32\MBPPCn64.dll 2013-07-25 18:33 - 2013-07-25 18:43 - 81891861 _____ (Realtek Semiconductor Corp.) C:\Users\Arthur\Downloads\64bit_Vista_Win7_Win8_R271.exe 2013-07-25 18:20 - 2013-07-25 18:20 - 03692323 _____ (Topala Software Solutions ) C:\Users\Arthur\Downloads\siw-setup.exe 2013-07-25 18:16 - 2013-07-25 18:16 - 04179293 _____ (Lavalys, Inc. ) C:\Users\Arthur\Downloads\everesthome220.exe 2013-07-25 17:53 - 2013-07-25 17:53 - 00002880 _____ C:\AdwCleaner[S4].txt 2013-07-25 12:33 - 2013-07-25 12:33 - 00000000 ____D C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6 LS7 2013-07-25 12:17 - 2013-07-25 12:17 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert 2013-07-24 12:31 - 2013-07-24 12:31 - 00000000 ____D C:\Users\Arthur\Documents\DVDVideoSoft 2013-07-24 12:31 - 2013-07-24 12:31 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-24 12:29 - 2013-07-24 12:29 - 01205024 _____ (DVDVideoSoft Ltd. ) C:\Users\Arthur\Downloads\FreeVideoFlipAndRotate.exe 2013-07-24 11:25 - 2013-07-24 11:25 - 00001090 _____ C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6.lnk 2013-07-24 10:56 - 2013-07-24 10:56 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\Arthur\Downloads\CreativeCloudSet-Up.exe 2013-07-24 10:42 - 2013-07-24 10:42 - 00000000 ____D C:\Users\Arthur\AppData\Local\NVIDIA 2013-07-24 02:48 - 2013-07-24 10:45 - 00001353 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-07-24 02:46 - 2013-07-24 02:46 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-07-24 02:44 - 2013-06-21 14:06 - 27781920 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 21102368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 15920536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 15144928 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 13411896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 12427240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 11235104 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-07-24 02:44 - 2013-06-21 14:06 - 09239344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 07687592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 07641832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 06324360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 02953504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 02936208 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 02777888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 02363680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 01059560 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00925648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00572704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00467232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00465184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00432928 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00372000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00266448 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00218592 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00214448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-07-24 02:44 - 2013-06-21 14:06 - 00181488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-07-24 02:44 - 2013-02-25 07:27 - 00194848 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-07-24 02:44 - 2013-02-25 07:27 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-07-24 02:43 - 2013-07-24 02:43 - 00000000 ____D C:\NVIDIA 2013-07-24 02:38 - 2013-07-24 02:38 - 01344480 _____ (techPowerUp (TechPowerUp)) C:\Users\Arthur\Downloads\GPU-Z.0.7.2.exe 2013-07-24 02:37 - 2013-07-24 02:43 - 229594432 _____ (NVIDIA Corporation) C:\Users\Arthur\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-07-23 22:40 - 2013-07-23 22:40 - 02347384 _____ (ESET) C:\Users\Arthur\Downloads\esetsmartinstaller_enu.exe 2013-07-23 22:39 - 2013-07-23 22:39 - 00001115 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-23 22:39 - 2013-07-23 22:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-23 22:39 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-07-23 22:37 - 2013-07-23 22:38 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Arthur\Downloads\mbam-setup- 2013-07-23 22:35 - 2013-07-23 22:35 - 01779757 _____ (Farbar) C:\Users\Arthur\Downloads\FRST64 (1).exe 2013-07-23 21:26 - 2013-07-23 21:26 - 00030221 _____ C:\ComboFix.txt 2013-07-23 21:13 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-23 21:13 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-23 21:13 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-23 21:13 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-23 21:13 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-23 21:13 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-23 21:13 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-23 21:13 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-23 21:12 - 2013-07-23 21:26 - 00000000 ____D C:\Qoobox 2013-07-23 21:12 - 2013-07-23 21:25 - 00000000 ____D C:\Windows\erdnt 2013-07-23 21:04 - 2013-07-23 21:05 - 00001771 _____ C:\AdwCleaner[S3].txt 2013-07-23 21:03 - 2013-07-23 21:03 - 00666633 _____ C:\Users\Arthur\Desktop\adwcleaner06.exe 2013-07-23 09:55 - 2013-07-23 09:55 - 00000000 ____D C:\FRST 2013-07-22 22:49 - 2013-07-23 01:39 - 00000000 ____D C:\Windows\pss 2013-07-22 20:16 - 2013-07-22 20:16 - 00000132 _____ C:\Users\Arthur\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2013-07-22 20:11 - 2013-07-22 20:13 - 10339263 _____ C:\Users\Arthur\Downloads\Rijk van Nijmegen - Rivieren.mp4 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-22 16:03 - 2013-07-30 18:41 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-22 16:03 - 2013-07-22 16:04 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-22 16:03 - 2013-07-22 16:04 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-22 16:03 - 2013-07-22 16:04 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-22 16:03 - 2013-07-22 16:03 - 00001928 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 16:03 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-07-22 16:03 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-07-22 16:03 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-07-22 15:42 - 2013-07-22 15:45 - 117478104 _____ C:\Users\Arthur\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-22 15:39 - 2013-07-28 18:24 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Adobe 2013-07-21 20:28 - 2013-07-21 20:28 - 00000040 ____H C:\1B50C1B368B1 2013-07-21 20:10 - 2013-07-21 20:19 - 294969288 _____ C:\Users\Arthur\Downloads\AfterEffects.rar 2013-07-21 20:08 - 2013-07-21 20:08 - 01126480 _____ (BitTorrent Inc.) C:\Users\Arthur\Downloads\utorrent_3.3.1b29812.exe 2013-07-21 17:41 - 2013-07-21 17:41 - 00003504 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-ADDIS-PC-Arthur 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\Documents\Adobe 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PDAppFlex 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Local\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy 2013-07-21 17:35 - 2013-07-21 17:35 - 00000000 ____D C:\Program Files (x86)\My Company Name 2013-07-21 17:35 - 2011-11-03 03:01 - 00056208 ____N (Rovi Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys 2013-07-21 17:35 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdralw2k.sys 2013-07-21 17:35 - 2011-10-17 03:00 - 00010224 ____N (Sonic Solutions) C:\Windows\system32\Drivers\cdr4_xp.sys 2013-07-21 17:24 - 2013-07-25 12:44 - 00000000 ____D C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6 2013-07-20 11:34 - 2013-07-20 11:34 - 00000000 ____D C:\Users\Arthur\Documents\Rockstar Games 2013-07-20 11:14 - 2013-07-20 11:14 - 00000000 __SHD C:\ProgramData\SecuROM 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PiccShare 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Common 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Users\Arthur\Documents\Games for Windows - LIVE Demos 2013-07-20 10:56 - 2013-07-20 10:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-07-20 10:35 - 2013-07-20 11:14 - 00000000 ____D C:\Users\Arthur\AppData\Local\Rockstar Games 2013-07-20 10:33 - 2013-07-20 10:33 - 00000600 _____ C:\Users\Arthur\Desktop\Grand Theft Auto IV.lnk 2013-07-17 22:48 - 2013-07-17 22:49 - 00000000 ____D C:\Windows\system32\MRT 2013-07-15 21:49 - 2013-07-15 21:49 - 414046739 _____ C:\Windows\MEMORY.DMP 2013-07-15 21:49 - 2013-07-15 21:49 - 00307440 _____ C:\Windows\Minidump\071513-18018-01.dmp 2013-07-15 21:49 - 2013-07-15 21:49 - 00000000 ____D C:\Windows\Minidump 2013-07-15 15:03 - 2013-07-22 22:33 - 00011370 _____ C:\Windows\SysWOW64\.crusader 2013-07-15 15:03 - 2012-08-31 19:57 - 01687408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Drivers\ntfs.sys 2013-07-15 15:03 - 2010-11-20 14:17 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ie4uinit.exe 2013-07-15 15:03 - 2009-07-14 04:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storsvc.dll 2013-07-14 18:20 - 2013-07-22 22:36 - 00030616 _____ C:\Windows\SysWOW64\Drivers\hitmanpro37.sys 2013-07-14 13:17 - 2013-07-14 13:18 - 00000000 ____D C:\Program Files (x86)\Zoom Player 2013-07-11 17:33 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-11 17:33 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-11 17:33 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-11 17:33 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-11 17:33 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-11 17:33 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-11 17:33 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-11 17:33 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-11 17:33 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-11 17:33 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-11 17:33 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-11 17:33 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-11 15:43 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-11 15:43 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-11 15:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-11 15:43 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-11 15:43 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-11 15:42 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-11 15:42 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-04 19:18 - 2013-07-04 20:30 - 02419006 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz3.ppsx 2013-07-04 18:35 - 2013-07-04 19:18 - 02418995 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz1.pptx 2013-07-04 18:35 - 2013-07-04 18:35 - 02418812 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz2.ppsx 2013-07-04 15:35 - 2013-07-04 15:35 - 00005363 _____ C:\Users\Arthur\Documents\Alcatraz.wlmp 2013-07-04 14:36 - 2013-07-04 15:18 - 02326429 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz.pptx ==================== One Month Modified Files and Folders ======= 2013-07-30 21:55 - 2013-07-30 21:54 - 01781589 _____ (Farbar) C:\Users\Arthur\Downloads\FRST64.exe 2013-07-30 21:54 - 2012-12-12 16:55 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-30 21:21 - 2012-12-06 15:01 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-30 20:35 - 2012-12-06 15:33 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Skype 2013-07-30 20:30 - 2009-07-14 06:45 - 00026288 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-30 20:30 - 2009-07-14 06:45 - 00026288 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-30 20:28 - 2012-12-05 00:19 - 01156043 _____ C:\Windows\WindowsUpdate.log 2013-07-30 20:26 - 2012-12-06 15:01 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-30 20:23 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-30 20:22 - 2013-05-13 16:13 - 00011710 _____ C:\Windows\setupact.log 2013-07-30 20:22 - 2013-04-27 13:52 - 00086660 _____ C:\Windows\PFRO.log 2013-07-30 20:22 - 2012-12-05 00:34 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-30 18:41 - 2013-07-22 16:03 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-30 12:22 - 2012-12-28 22:42 - 00000000 ____D C:\Users\Arthur\AppData\Local\Adobe 2013-07-29 22:22 - 2013-07-29 18:58 - 17052230 _____ C:\Users\Arthur\Downloads\IMAX -Pre Show- Intro (HD 1080p).mp4 2013-07-29 01:22 - 2012-12-06 16:00 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\vlc 2013-07-28 23:05 - 2013-06-24 16:00 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\uTorrent 2013-07-28 22:58 - 2012-12-06 15:19 - 00000000 ____D C:\Users\UpdatusUser.ADDIS-PC 2013-07-28 22:39 - 2013-07-28 22:39 - 00007605 _____ C:\Users\Arthur\AppData\Local\Resmon.ResmonCfg 2013-07-28 21:45 - 2013-07-28 21:45 - 00021160 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmafd.sys 2013-07-28 21:34 - 2013-07-28 21:34 - 00011904 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\Drivers\amdide64.sys 2013-07-28 21:14 - 2013-07-28 21:14 - 00035936 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\amdkmpfd.sys 2013-07-28 21:13 - 2013-07-25 18:45 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-07-28 21:12 - 2013-07-28 21:12 - 03760856 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 03462616 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-07-28 21:12 - 2013-07-28 21:12 - 02795224 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 02736160 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 02103040 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 02032896 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 01662024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-07-28 21:12 - 2013-07-28 21:12 - 01004248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00920320 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00613448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00602901 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-07-28 21:12 - 2013-07-28 21:12 - 00208072 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-07-28 21:12 - 2013-07-28 21:12 - 00146648 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-07-28 21:09 - 2013-07-28 21:09 - 00849992 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-07-28 21:09 - 2013-07-28 21:09 - 00108104 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2013-07-28 21:09 - 2013-07-28 21:09 - 00073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-07-28 20:29 - 2013-07-28 20:29 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-28 20:26 - 2013-07-28 20:11 - 05653448 _____ (Uniblue Systems Ltd ) C:\Users\Arthur\Downloads\driverscanner.exe 2013-07-28 20:20 - 2013-07-28 20:09 - 04054000 _____ (LionSea Software ) C:\Users\Arthur\Downloads\setup.exe 2013-07-28 18:24 - 2013-07-22 15:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Adobe 2013-07-28 15:22 - 2013-07-28 15:10 - 00000000 ____D C:\Users\Arthur\Downloads\Silbermond 2013-07-28 15:14 - 2013-07-28 15:11 - 00000000 ____D C:\Users\Arthur\Downloads\Juli - In Love (2010) - Pop [www.torrentazos.com] 2013-07-28 14:48 - 2009-07-14 19:58 - 00696904 _____ C:\Windows\system32\perfh007.dat 2013-07-28 14:48 - 2009-07-14 19:58 - 00148200 _____ C:\Windows\system32\perfc007.dat 2013-07-28 14:48 - 2009-07-14 07:13 - 01613644 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-25 18:45 - 2013-07-25 18:45 - 00000000 ____D C:\Program Files\Realtek 2013-07-25 18:44 - 2013-07-25 18:44 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-07-25 18:44 - 2012-12-06 17:32 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-25 18:43 - 2013-07-25 18:33 - 81891861 _____ (Realtek Semiconductor Corp.) C:\Users\Arthur\Downloads\64bit_Vista_Win7_Win8_R271.exe 2013-07-25 18:20 - 2013-07-25 18:20 - 03692323 _____ (Topala Software Solutions ) C:\Users\Arthur\Downloads\siw-setup.exe 2013-07-25 18:16 - 2013-07-25 18:16 - 04179293 _____ (Lavalys, Inc. ) C:\Users\Arthur\Downloads\everesthome220.exe 2013-07-25 17:55 - 2009-07-14 06:45 - 05070528 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-25 17:53 - 2013-07-25 17:53 - 00002880 _____ C:\AdwCleaner[S4].txt 2013-07-25 17:42 - 2012-12-19 19:57 - 00000000 ____D C:\ProgramData\TuneUp Software 2013-07-25 13:01 - 2012-12-05 01:01 - 00117664 _____ C:\Users\Arthur\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-25 12:58 - 2013-03-30 23:43 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-25 12:44 - 2013-07-21 17:24 - 00000000 ____D C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6 2013-07-25 12:33 - 2013-07-25 12:33 - 00000000 ____D C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6 LS7 2013-07-25 12:17 - 2013-07-25 12:17 - 00003436 _____ C:\Windows\System32\Tasks\BrowserDefendert 2013-07-24 21:50 - 2013-05-13 15:30 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-24 12:36 - 2013-01-11 18:52 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\DVDVideoSoft 2013-07-24 12:32 - 2012-12-19 19:57 - 00000000 __SHD C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} 2013-07-24 12:31 - 2013-07-24 12:31 - 00000000 ____D C:\Users\Arthur\Documents\DVDVideoSoft 2013-07-24 12:31 - 2013-07-24 12:31 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-24 12:31 - 2013-04-30 12:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-24 12:29 - 2013-07-24 12:29 - 01205024 _____ (DVDVideoSoft Ltd. ) C:\Users\Arthur\Downloads\FreeVideoFlipAndRotate.exe 2013-07-24 11:25 - 2013-07-24 11:25 - 00001090 _____ C:\Users\Arthur\Desktop\Adobe Premiere Pro CS6.lnk 2013-07-24 11:00 - 2012-12-13 14:54 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-24 10:56 - 2013-07-24 10:56 - 03867000 _____ (Adobe Systems Incorporated) C:\Users\Arthur\Downloads\CreativeCloudSet-Up.exe 2013-07-24 10:54 - 2012-12-12 16:54 - 00000000 ____D C:\ProgramData\Adobe 2013-07-24 10:45 - 2013-07-24 02:48 - 00001353 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2013-07-24 10:42 - 2013-07-24 10:42 - 00000000 ____D C:\Users\Arthur\AppData\Local\NVIDIA 2013-07-24 10:40 - 2012-12-05 00:33 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-07-24 02:47 - 2012-12-05 00:33 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-07-24 02:46 - 2013-07-24 02:46 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-07-24 02:43 - 2013-07-24 02:43 - 00000000 ____D C:\NVIDIA 2013-07-24 02:43 - 2013-07-24 02:37 - 229594432 _____ (NVIDIA Corporation) C:\Users\Arthur\Downloads\320.49-desktop-win8-win7-winvista-64bit-international-whql.exe 2013-07-24 02:38 - 2013-07-24 02:38 - 01344480 _____ (techPowerUp (TechPowerUp)) C:\Users\Arthur\Downloads\GPU-Z.0.7.2.exe 2013-07-23 22:40 - 2013-07-23 22:40 - 02347384 _____ (ESET) C:\Users\Arthur\Downloads\esetsmartinstaller_enu.exe 2013-07-23 22:39 - 2013-07-23 22:39 - 00001115 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-23 22:39 - 2013-07-23 22:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-23 22:38 - 2013-07-23 22:37 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Arthur\Downloads\mbam-setup- 2013-07-23 22:35 - 2013-07-23 22:35 - 01779757 _____ (Farbar) C:\Users\Arthur\Downloads\FRST64 (1).exe 2013-07-23 21:26 - 2013-07-23 21:26 - 00030221 _____ C:\ComboFix.txt 2013-07-23 21:26 - 2013-07-23 21:12 - 00000000 ____D C:\Qoobox 2013-07-23 21:26 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-07-23 21:25 - 2013-07-23 21:12 - 00000000 ____D C:\Windows\erdnt 2013-07-23 21:22 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-07-23 21:20 - 2013-03-19 18:00 - 00000000 ____D C:\ProgramData\Wincert 2013-07-23 21:05 - 2013-07-23 21:04 - 00001771 _____ C:\AdwCleaner[S3].txt 2013-07-23 21:03 - 2013-07-23 21:03 - 00666633 _____ C:\Users\Arthur\Desktop\adwcleaner06.exe 2013-07-23 09:55 - 2013-07-23 09:55 - 00000000 ____D C:\FRST 2013-07-23 09:54 - 2012-12-17 21:58 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-07-23 09:51 - 2013-05-13 15:30 - 00000000 ____D C:\Program Files\Microsoft Office 2013-07-23 09:50 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-07-23 01:44 - 2013-03-30 23:46 - 00000000 ____D C:\Program Files\Adobe 2013-07-23 01:39 - 2013-07-22 22:49 - 00000000 ____D C:\Windows\pss 2013-07-22 23:13 - 2013-04-11 17:35 - 00000000 ____D C:\Users\Arthur\AppData\Local\Sony 2013-07-22 23:13 - 2013-04-11 17:35 - 00000000 ____D C:\ProgramData\Sony 2013-07-22 23:08 - 2012-12-06 15:01 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-22 23:08 - 2012-12-06 15:01 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-22 23:07 - 2013-02-09 15:44 - 00002952 _____ C:\Windows\System32\Tasks\{23A7EE5B-8126-4140-9EDD-6FB26AA5D81B} 2013-07-22 23:07 - 2012-12-20 18:37 - 00003694 _____ C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm 2013-07-22 23:06 - 2012-12-06 15:01 - 00000000 ____D C:\Users\Arthur\AppData\Local\Google 2013-07-22 23:06 - 2012-12-06 15:01 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-22 22:36 - 2013-07-14 18:20 - 00030616 _____ C:\Windows\SysWOW64\Drivers\hitmanpro37.sys 2013-07-22 22:33 - 2013-07-15 15:03 - 00011370 _____ C:\Windows\SysWOW64\.crusader 2013-07-22 22:33 - 2013-06-02 19:29 - 00000000 ____D C:\Program Files\HitmanPro 2013-07-22 20:16 - 2013-07-22 20:16 - 00000132 _____ C:\Users\Arthur\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2013-07-22 20:13 - 2013-07-22 20:11 - 10339263 _____ C:\Users\Arthur\Downloads\Rijk van Nijmegen - Rivieren.mp4 2013-07-22 19:37 - 2012-12-06 15:33 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-22 19:37 - 2012-12-06 15:27 - 00000000 ____D C:\ProgramData\Skype 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-22 16:04 - 2013-07-22 16:04 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-22 16:04 - 2013-07-22 16:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-22 16:04 - 2013-07-22 16:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-22 16:04 - 2013-07-22 16:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-22 16:03 - 2013-07-22 16:03 - 00001928 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 16:03 - 2013-04-01 15:52 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-22 16:03 - 2013-04-01 15:52 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-22 16:03 - 2013-04-01 15:51 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-22 15:46 - 2013-01-06 22:28 - 00000000 ____D C:\Users\hedev 2013-07-22 15:45 - 2013-07-22 15:42 - 117478104 _____ C:\Users\Arthur\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-21 20:28 - 2013-07-21 20:28 - 00000040 ____H C:\1B50C1B368B1 2013-07-21 20:19 - 2013-07-21 20:10 - 294969288 _____ C:\Users\Arthur\Downloads\AfterEffects.rar 2013-07-21 20:08 - 2013-07-21 20:08 - 01126480 _____ (BitTorrent Inc.) C:\Users\Arthur\Downloads\utorrent_3.3.1b29812.exe 2013-07-21 17:41 - 2013-07-21 17:41 - 00003504 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-ADDIS-PC-Arthur 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\Documents\Adobe 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PDAppFlex 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\Users\Arthur\AppData\Local\PACE Anti-Piracy 2013-07-21 17:39 - 2013-07-21 17:39 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy 2013-07-21 17:39 - 2012-12-16 13:34 - 00000000 ___HD C:\Users\Arthur\AppData\Local\Il1yeC94tyS 2013-07-21 17:38 - 2013-03-30 14:33 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-21 17:35 - 2013-07-21 17:35 - 00000000 ____D C:\Program Files (x86)\My Company Name 2013-07-20 11:34 - 2013-07-20 11:34 - 00000000 ____D C:\Users\Arthur\Documents\Rockstar Games 2013-07-20 11:14 - 2013-07-20 11:14 - 00000000 __SHD C:\ProgramData\SecuROM 2013-07-20 11:14 - 2013-07-20 10:35 - 00000000 ____D C:\Users\Arthur\AppData\Local\Rockstar Games 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\PiccShare 2013-07-20 11:02 - 2013-07-20 11:02 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\Common 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Windows\SysWOW64\xlive 2013-07-20 10:57 - 2013-07-20 10:57 - 00000000 ____D C:\Users\Arthur\Documents\Games for Windows - LIVE Demos 2013-07-20 10:57 - 2013-07-20 10:56 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE 2013-07-20 10:33 - 2013-07-20 10:33 - 00000600 _____ C:\Users\Arthur\Desktop\Grand Theft Auto IV.lnk 2013-07-17 22:49 - 2013-07-17 22:48 - 00000000 ____D C:\Windows\system32\MRT 2013-07-15 21:49 - 2013-07-15 21:49 - 414046739 _____ C:\Windows\MEMORY.DMP 2013-07-15 21:49 - 2013-07-15 21:49 - 00307440 _____ C:\Windows\Minidump\071513-18018-01.dmp 2013-07-15 21:49 - 2013-07-15 21:49 - 00000000 ____D C:\Windows\Minidump 2013-07-14 13:18 - 2013-07-14 13:17 - 00000000 ____D C:\Program Files (x86)\Zoom Player 2013-07-14 13:13 - 2013-05-17 20:20 - 00000000 ____D C:\Users\Arthur\AppData\Roaming\FreeVideoConverter 2013-07-13 21:31 - 2013-05-14 19:18 - 00002189 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-11 18:54 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-11 18:52 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 18:52 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-11 18:52 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-09 20:59 - 2013-02-15 21:25 - 00017408 ____H C:\Users\Arthur\Downloads\photothumb.db 2013-07-09 20:59 - 2012-12-06 21:48 - 00001037 _____ C:\Users\Arthur\Desktop\PhotoScape.lnk 2013-07-09 20:59 - 2012-12-06 21:48 - 00000000 ____D C:\Program Files (x86)\PhotoScape 2013-07-05 20:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-07-04 20:51 - 2013-01-01 23:52 - 00272384 ___SH C:\Users\Arthur\Documents\Thumbs.db 2013-07-04 20:30 - 2013-07-04 19:18 - 02419006 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz3.ppsx 2013-07-04 19:18 - 2013-07-04 18:35 - 02418995 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz1.pptx 2013-07-04 18:42 - 2013-05-13 15:30 - 00000000 ____D C:\Users\Arthur\AppData\Local\Microsoft Help 2013-07-04 18:41 - 2009-07-14 04:34 - 00000499 _____ C:\Windows\win.ini 2013-07-04 18:35 - 2013-07-04 18:35 - 02418812 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz2.ppsx 2013-07-04 15:35 - 2013-07-04 15:35 - 00005363 _____ C:\Users\Arthur\Documents\Alcatraz.wlmp 2013-07-04 15:32 - 2013-01-01 20:50 - 00000000 ____D C:\Users\Arthur\AppData\Local\Windows Live 2013-07-04 15:18 - 2013-07-04 14:36 - 02326429 _____ C:\Users\Arthur\Documents\The Escape from Alcatraz.pptx 2013-07-04 15:13 - 2009-07-14 20:18 - 00000000 ____D C:\Windows\ShellNew ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-13 19:57 ==================== End Of Log ============================ |
![]() | #4 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Hi, FRST öffnen, Haken setzen bei Additional und scannen, jetzt bitte Additional.txt posten.
ja aber in Quarantäen, also weg gesperrt ![]() Frisches FRST log fehlt ![]()

gruß, schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!
![]() | #5 | |
![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Ok dann ist hier Addition.txt Zitat:
![]() | #6 | |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr?Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ --> Pc lädt ständig irgendetwas...Trojaner Gefahr? |
![]() | #7 |
![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Also hier ist die log.txt Combofix Logfile: Code:
ATTFilter ComboFix 13-07-31.02 - Arthur 31.07.2013 20:46:29.2.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.4095.2878 [GMT 2:00] ausgeführt von:: c:\users\Arthur\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\security\Database\tmp.edb . . ((((((((((((((((((((((( Dateien erstellt von 2013-06-28 bis 2013-07-31 )))))))))))))))))))))))))))))) . . 2013-07-31 18:55 . 2013-07-31 18:55 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-07-31 18:55 . 2013-07-31 18:55 -------- d-----w- c:\users\UpdatusUser.ADDIS-PC\AppData\Local\temp 2013-07-31 18:55 . 2013-07-31 18:55 -------- d-----w- c:\users\Lena\AppData\Local\temp 2013-07-31 18:55 . 2013-07-31 18:55 -------- d-----w- c:\users\hedev\AppData\Local\temp 2013-07-31 18:55 . 2013-07-31 18:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-30 09:53 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{484C356F-41BF-4DD3-A731-77BCBCB83930}\mpengine.dll 2013-07-28 19:45 . 2013-07-28 19:45 21160 ----a-w- c:\windows\system32\drivers\amdkmafd.sys 2013-07-28 19:34 . 2013-07-28 19:34 11904 ----a-w- c:\windows\system32\drivers\amdide64.sys 2013-07-28 19:14 . 2013-07-28 19:14 35936 ----a-w- c:\windows\system32\drivers\amdkmpfd.sys 2013-07-28 19:12 . 2013-07-28 19:12 2103040 ----a-w- c:\windows\system32\WavesGUILib64.dll 2013-07-28 19:12 . 2013-07-28 19:12 613448 ----a-w- c:\windows\system32\RtDataProc64.dll 2013-07-28 19:12 . 2013-07-28 19:12 3760856 ----a-w- c:\windows\system32\RtkAPO64.dll 2013-07-28 19:12 . 2013-07-28 19:12 2795224 ----a-w- c:\windows\system32\RtPgEx64.dll 2013-07-28 19:12 . 2013-07-28 19:12 1004248 ----a-w- c:\windows\system32\RtkApi64.dll 2013-07-28 19:12 . 2013-07-28 19:12 1662024 ----a-w- c:\windows\system32\RTSnMg64.cpl 2013-07-28 19:12 . 2013-07-28 19:12 3462616 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys 2013-07-28 19:12 . 2013-07-28 19:12 146648 ----a-w- c:\windows\system32\RCoInstII64.dll 2013-07-28 19:12 . 2013-07-28 19:12 920320 ----a-w- c:\windows\system32\MaxxAudioAPOShell64.dll 2013-07-28 19:12 . 2013-07-28 19:12 2032896 ----a-w- c:\windows\system32\MaxxAudioEQ64.dll 2013-07-28 19:12 . 2013-07-28 19:12 2736160 ----a-w- c:\windows\system32\FMAPO64.dll 2013-07-28 19:12 . 2013-07-28 19:12 208072 ----a-w- c:\windows\system32\AERTAC64.dll 2013-07-28 19:09 . 2013-07-28 19:09 849992 ----a-w- c:\windows\system32\drivers\Rt64win7.sys 2013-07-28 19:09 . 2013-07-28 19:09 73800 ----a-w- c:\windows\system32\RtNicProp64.dll 2013-07-28 19:09 . 2013-07-28 19:09 108104 ----a-w- c:\windows\system32\RTNUninst64.dll 2013-07-28 18:29 . 2013-07-28 18:29 -------- d-----w- c:\programdata\Uniblue 2013-07-25 16:45 . 2013-07-28 19:13 -------- d-----w- c:\windows\SysWow64\RTCOM 2013-07-25 16:45 . 2013-07-25 16:45 -------- d-----w- c:\program files\Realtek 2013-07-24 10:31 . 2013-07-24 10:31 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft 2013-07-24 10:31 . 2013-07-24 10:31 -------- d-----w- c:\program files (x86)\DVDVideoSoft 2013-07-24 08:42 . 2013-07-24 08:42 -------- d-----w- c:\users\Arthur\AppData\Local\NVIDIA 2013-07-24 00:46 . 2013-07-24 00:46 -------- d-----w- c:\program files (x86)\AGEIA Technologies 2013-07-24 00:43 . 2013-07-24 00:43 -------- d-----w- C:\NVIDIA 2013-07-23 20:39 . 2013-07-23 20:39 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-07-23 20:39 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-07-23 07:55 . 2013-07-23 07:55 -------- d-----w- C:\FRST 2013-07-22 14:03 . 2013-05-09 08:59 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-07-22 14:03 . 2013-07-22 14:04 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-07-22 14:03 . 2013-05-09 08:59 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-07-22 14:03 . 2013-05-09 08:59 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-07-22 14:03 . 2013-07-22 14:04 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-07-22 14:03 . 2013-07-22 14:04 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-07-22 14:03 . 2013-05-09 08:59 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-07-22 14:03 . 2013-05-09 08:59 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-07-22 14:03 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr 2013-07-21 15:39 . 2013-07-21 15:39 -------- d-----w- c:\users\Arthur\AppData\Roaming\PACE Anti-Piracy 2013-07-21 15:39 . 2013-07-21 15:39 -------- d-----w- c:\programdata\PACE Anti-Piracy 2013-07-21 15:39 . 2013-07-21 15:39 -------- d-----w- c:\users\Arthur\AppData\Local\PACE Anti-Piracy 2013-07-21 15:39 . 2013-07-21 15:39 -------- d-----w- c:\users\Arthur\AppData\Roaming\PDAppFlex 2013-07-21 15:35 . 2011-11-03 01:01 56208 ------w- c:\windows\system32\drivers\PxHlpa64.sys 2013-07-21 15:35 . 2011-10-17 01:00 10224 ------w- c:\windows\system32\drivers\cdralw2k.sys 2013-07-21 15:35 . 2011-10-17 01:00 10224 ------w- c:\windows\system32\drivers\cdr4_xp.sys 2013-07-21 15:35 . 2013-07-25 10:55 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine 2013-07-21 15:35 . 2013-07-21 15:35 -------- d-----w- c:\program files (x86)\Common Files\Sonic Shared 2013-07-21 15:35 . 2013-07-21 15:35 -------- d-----w- c:\program files (x86)\My Company Name 2013-07-20 09:14 . 2013-07-20 09:14 -------- d-sh--w- c:\programdata\SecuROM 2013-07-20 09:02 . 2013-07-20 09:02 -------- d-----w- c:\users\Arthur\AppData\Roaming\PiccShare 2013-07-20 09:02 . 2013-07-20 09:02 -------- d-----w- c:\users\Arthur\AppData\Roaming\Common 2013-07-20 08:57 . 2013-07-20 08:57 -------- d-----w- c:\windows\SysWow64\xlive 2013-07-20 08:56 . 2013-07-20 08:57 -------- d-----w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2013-07-20 08:35 . 2013-07-20 09:14 -------- d-----w- c:\users\Arthur\AppData\Local\Rockstar Games 2013-07-17 20:48 . 2013-07-17 20:49 -------- d-----w- c:\windows\system32\MRT 2013-07-15 13:03 . 2009-07-14 02:57 23552 ----a-w- c:\windows\SysWow64\storsvc.dll 2013-07-15 13:03 . 2012-08-31 17:57 1687408 ----a-w- c:\windows\SysWow64\drivers\ntfs.sys 2013-07-14 16:20 . 2013-07-22 20:36 30616 ----a-w- c:\windows\SysWow64\drivers\hitmanpro37.sys 2013-07-14 11:17 . 2013-07-14 11:18 -------- d-----w- c:\program files (x86)\Zoom Player 2013-07-11 13:44 . 2013-05-27 05:50 1011712 ----a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-11 13:44 . 2013-05-27 05:50 571904 ----a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-11 13:44 . 2013-05-27 05:50 314880 ----a-w- c:\program files\Windows Defender\MpCommu.dll 2013-07-11 13:44 . 2013-05-27 04:57 4608 ----a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll 2013-07-11 13:44 . 2013-05-27 04:57 54784 ----a-w- c:\program files (x86)\Windows Defender\MpOAV.dll 2013-07-11 13:44 . 2013-05-27 04:57 392704 ----a-w- c:\program files (x86)\Windows Defender\MpClient.dll 2013-07-11 13:44 . 2013-05-27 03:15 9216 ----a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll 2013-07-11 13:43 . 2013-06-04 06:00 624128 ----a-w- c:\windows\system32\qedit.dll 2013-07-11 13:43 . 2013-06-04 04:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2013-07-11 13:43 . 2013-05-06 06:03 1887744 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-11 13:43 . 2013-05-06 04:56 1620480 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-11 13:43 . 2013-06-05 03:34 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-07-11 13:43 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-11 13:43 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-11 13:43 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-11 13:43 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 13:43 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2013-07-11 13:42 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2013-07-11 13:42 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-23 22:57 . 2012-12-06 15:46 78277128 ----a-w- c:\windows\system32\MRT.exe 2013-06-21 12:06 . 2013-04-16 16:04 2597856 ----a-w- c:\windows\SysWow64\nvapi.dll 2013-06-21 12:06 . 2012-12-06 13:18 61216 ----a-w- c:\windows\system32\OpenCL.dll 2013-06-21 12:06 . 2012-12-06 13:18 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll 2013-06-21 10:23 . 2012-12-06 13:19 6496544 ----a-w- c:\windows\system32\nvcpl.dll 2013-06-21 10:23 . 2012-12-06 13:19 3514656 ----a-w- c:\windows\system32\nvsvc64.dll 2013-06-21 10:23 . 2012-12-06 13:19 884512 ----a-w- c:\windows\system32\nvvsvc.exe 2013-06-21 10:23 . 2012-12-06 13:19 63776 ----a-w- c:\windows\system32\nvshext.dll 2013-06-21 10:23 . 2012-12-06 13:19 2555680 ----a-w- c:\windows\system32\nvsvcr.dll 2013-06-21 10:23 . 2012-12-06 13:19 237856 ----a-w- c:\windows\system32\nvmctray.dll 2013-06-21 03:16 . 2013-06-21 03:16 566048 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2013-06-20 04:17 . 2012-12-06 13:19 3253909 ----a-w- c:\windows\system32\nvcoproc.bin 2013-06-12 12:55 . 2012-12-12 14:55 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-12 12:55 . 2012-12-12 14:55 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-02 17:17 . 2013-06-02 17:16 234 ----a-w- c:\windows\DeleteOnReboot.bat 2013-05-13 05:51 . 2013-06-12 12:59 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 05:51 . 2013-06-12 12:59 1464320 ----a-w- c:\windows\system32\crypt32.dll 2013-05-13 05:51 . 2013-06-12 12:59 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-05-13 05:50 . 2013-06-12 12:59 52224 ----a-w- c:\windows\system32\certenc.dll 2013-05-13 04:45 . 2013-06-12 12:59 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 12:59 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-05-13 04:45 . 2013-06-12 12:59 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-05-13 03:43 . 2013-06-12 12:59 1192448 ----a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 12:59 903168 ----a-w- c:\windows\SysWow64\certutil.exe 2013-05-13 03:08 . 2013-06-12 12:59 43008 ----a-w- c:\windows\SysWow64\certenc.dll 2013-05-11 11:03 . 2012-07-17 13:37 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-10 05:49 . 2013-06-12 13:00 30720 ----a-w- c:\windows\system32\cryptdlg.dll 2013-05-10 03:20 . 2013-06-12 13:00 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll 2013-05-09 08:58 . 2013-04-01 13:52 287840 ----a-w- c:\windows\system32\aswBoot.exe 2013-05-08 06:39 . 2013-06-12 13:00 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="e:\steam\Steam.exe" [2013-07-26 1807272] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-21 19875432] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-07-12 2236816] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2012-7-23 17432576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete\0bootdelete\0bootdelete . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="E:\QTTask.exe" -atboottime "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-disabled] "LifeCam"="c:\program files (x86)\Microsoft LifeCam\LifeExp.exe" "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s "SweetIM"=c:\program files (x86)\SweetIM\Messenger\SweetIM.exe "Sweetpacks Communicator"=c:\program files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe "BrMfcWnd"=c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start "Smart File Advisor"="c:\program files (x86)\Smart File Advisor\sfa.exe" /checkassoc "QuickTime Task"="E:\QTTask.exe" -atboottime . R0 amdkmafd;AMD Audio Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmafd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmafd.sys [x] R0 hitmanpro37duringboot;hitmanpro37duringboot;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 gupdate;Google Update-Dienst (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 esgiguard;esgiguard;c:\program files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys;c:\program files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x] R3 gupdatem;Google Update-Dienst (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe;c:\program files (x86)\Google\Update\GoogleUpdate.exe [x] R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WinRing0_1_2_0;WinRing0_1_2_0; [x] R4 HitmanProScheduler;HitmanPro Scheduler;c:\program files\HitmanPro\hmpsched.exe;c:\program files\HitmanPro\hmpsched.exe [x] S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x] S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-07-31 16:17 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-07-31 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-12 12:55] . 2013-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-06 13:01] . 2013-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-06 13:01] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-06-19 22:45 3317616 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-06-19 22:45 3317616 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-06-19 22:45 3317616 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MagicTuneEngine"="c:\program files\MagicTune Premium\MagicTuneLauncher.exe" [2010-12-14 53760] "VX1000"="c:\windows\vVX1000.exe" [2010-05-20 762736] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-07-03 1028896] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-07-28 13626072] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~2\Office10\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{77BEC163-D389-42c1-91A4-C758846296A5} - (no file) Wow6432Node-HKCU-Run-AdobeBridge - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-950287045-4052571293-3502393058-1000\Software\SecuROM\License information*] "datasecu"=hex:b0,87,95,82,9f,6f,08,58,ce,32,14,8d,48,66,e5,5a,9c,32,5e,0f,d8, 58,f6,00,b1,0c,d2,b0,62,c8,26,5b,64,34,43,c4,b3,87,22,86,66,09,2d,dc,9e,88,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet004\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-07-31 21:07:04 ComboFix-quarantined-files.txt 2013-07-31 19:07 ComboFix2.txt 2013-07-23 19:26 . Vor Suchlauf: 16 Verzeichnis(se), 63.597.101.056 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), Bytes frei . - - End Of File - - 0BF3489B1DA5E1F29DE24D867CD9A6CD A36C5E4F47E84449FF07ED3517B43A31 [/QUOTE] |
![]() | #8 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
und ein frisches FRST log bitte.
und ein frisches FRST log bitte.

gruß, schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!
![]() | #9 | |
![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? AdwCleaner.txt AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 31/07/2013 um 21:26:46 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : Arthur - ADDIS-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Arthur\Desktop\adwcleaner06.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\InstallCore ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v28.0.1500.95 Datei : C:\Users\Arthur\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. Datei : C:\Users\Lena\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.2354] : homepage = "hxxp://www.searchnu.com/406", ************************* AdwCleaner[R1].txt - [26004 octets] - [02/06/2013 19:15:50] AdwCleaner[R2].txt - [4439 octets] - [24/06/2013 21:17:45] AdwCleaner[S1].txt - [24117 octets] - [02/06/2013 19:16:21] AdwCleaner[S2].txt - [3992 octets] - [24/06/2013 21:18:04] AdwCleaner[S3].txt - [1771 octets] - [23/07/2013 21:04:48] AdwCleaner[S4].txt - [2880 octets] - [25/07/2013 17:53:10] AdwCleaner[S5].txt - [1279 octets] - [31/07/2013 21:26:46] ########## EOF - C:\AdwCleaner[S5].txt - [1339 octets] ########## Und das ist Malwarebyte ![]() Zitat:
Geändert von Morfo (31.07.2013 um 20:44 Uhr) |
![]() | #10 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? ja aber in Quarantäen, also weg gesperrt ![]() Frisches FRST log fehlt ![]()
ja aber in Quarantäen, also weg gesperrt ![]() Frisches FRST log fehlt ![]()

gruß, schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!
![]() | #11 |
![]() | ![]() Pc lädt ständig irgendetwas...Trojaner Gefahr? Ups das habe ich anscheinend übersehen FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-07-2013 03 Ran by Arthur (administrator) on 01-08-2013 10:37:23 Running from C:\Users\Arthur\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\vVX1000.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Valve Corporation) E:\steam\Steam.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (SEC) C:\Program Files\MagicTune Premium\MagicTune.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (brother Industries Ltd) C:\Windows\SysWOW64\brsvc01a.exe (brother Industries Ltd) C:\Windows\SysWOW64\brss01a.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\setup\avast.setup (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MagicTuneEngine] - C:\Program Files\MagicTune Premium\MagicTuneLauncher.exe [53760 2010-12-14] () HKLM\...\Run: [VX1000] - C:\Windows\vVX1000.exe [762736 2010-05-20] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13626072 2013-07-28] (Realtek Semiconductor) HKCU\...\Run: [Steam] - E:\steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18705664 2013-01-08] (Skype Technologies S.A.) HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-07-12] (Adobe Systems Incorporated) HKU\Lena\...\Run: [uTorrent] - "C:\Users\Lena\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x] HKU\Lena\...\Run: [Steam] - E:\steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKU\Lena\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18705664 2013-01-08] (Skype Technologies S.A.) HKU\Lena\...\Run: [AdobeBridge] - [x] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.) Startup: C:\Users\Lena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * bootdeletebootdeletebootdelete ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=261 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Video downloader - {77BEC163-D389-42c1-91A4-C758846296A5} - No File BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.17.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Arthur\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF HKLM\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [{77BEC163-D389-42c1-91A4-C758846296A5}] C:\Program Files\Video downloader\Firefox FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! 