|
Plagegeister aller Art und deren Bekämpfung: Abuse Brief Telekom: unerwünschte Zugriffe über Internet ZugangWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
08.08.2013, 16:37 | #1 |
| Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang Hallo zusammen, ich habe gestern einen Brief von der Telekom (Abuse) bekommen in dem steht: Über meinen Internet Zugang sind unerwünschte Zugriffe auf fremde Computer erfolgt. Damit kann ich jetzt nicht so wahnsinnig viel anfangen. Ich halte mein Windows und meine Virenscanner immer auf dem aktuellen Stand. Hab mir daraufhin Malwarebytes Anti-Malware runtergeladen und einen scan durchgeführt, in diesem wurde dann 15mal PUP.Optional.Tarma.A gefunden und auch erfolgreich entfernt. kann durch diesen so etwas entstehen? Ist mein Computer jetzt sauber oder muss ich sonst noch etwas unternehmen? Schonmal danke für Hilfe und Auskunft. mfg radix2111 |
08.08.2013, 17:39 | #2 |
/// the machine /// TB-Ausbilder | Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
08.08.2013, 18:00 | #3 |
| Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang Addition.txt:FRST Additions Logfile:
__________________[CODE]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-08-2013 Ran by Daniel at 2013-08-08 18:54:14 Running from C:\Users\Daniel\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Amnesia - The Dark Descent (x32 Version: 1.0.0) ANNO 2070 (x32 Version: 1.0.0.0) Assassin’s Creed® III (x32) AuthenTec Fingerprint Driver (Version: 1.6.1.0342) AuthenTec TrueSuite (Version: 5.2.500.16) avast! Free Antivirus (x32 Version: 8.0.1489.0) Battlefield 3™ (x32 Version: 1.6.0.0) Battlelog Web Plugins (x32 Version: 2.1.3) BioShock (x32) BioShock 2 (x32 Version: 1.0.0005.131) BioShock 2 (x32 Version: 1.00.0000) BioShock Infinite (x32) BurnAware Free 6.4 (x32) Call of Juarez Gunslinger (x32) CamStudio version 2.7 (x32 Version: 2.7) Crysis® 2 (x32 Version: 1.0.0.0) D3DX10 (x32 Version: 15.4.2368.0902) DAEMON Tools Lite (x32 Version: 4.47.1.0333) Dark Souls: Prepare to Die Edition (x32) Dead Space™ 2 (x32 Version: 1.0.941.0) devolo dLAN Cockpit (x32 Version: 4.1.2.0) Diablo III (x32 Version: 1.0.8.16603) Die Sims™ 3 (x32 Version: 1.55.4) Die Sims™ 3 Jahreszeiten (x32 Version: 16.0.136) Die Sims™ 3 Late Night (x32 Version: 6.5.1) Die Sims™ 3 Lebensfreude (x32 Version: 8.0.152) Die Sims™ 3 Luxus-Accessoires (x32 Version: 3.0.38) Die Sims™ 3 Reiseabenteuer (x32 Version: 2.0.86) Die Sims™ 3 Traumkarrieren (x32 Version: 4.0.87) Die Sims™ 3 Wildes Studentenleben (x32 Version: 18.0.126) Dragon's Prophet (x32 Version: 1.0.1087.10) eaner (Version: 4.03) EPSON SX235 Series Printer Uninstall ESN Sonar (x32 Version: 0.70.4) FileHippo.com Update Checker (x32) Finger Printer (x32 Version: 2.00.0000) Free YouTube to MP3 Converter version 3.12.8.717 (x32 Version: 3.12.8.717) GIMP 2.8.4 (Version: 2.8.4) Grand Theft Auto IV (x32 Version: 1.0.0013.131) Grand Theft Auto IV (x32 Version: 1.00.0000) Hotkey 8.0073 (x32 Version: 8.0073) ICQ 8.0 (build 6017) (HKCU Version: 8.0.6017.0) ICQ7M (x32 Version: 7.8) Infineon TPM Professional Package (Version: 4.3.000.3137) Intel(R) Control Center (x32 Version: 1.2.1.1008) Intel(R) Management Engine Components (x32 Version: 8.1.0.1281) Intel(R) Rapid Storage Technology (x32 Version: 11.6.0.1030) Intel® Trusted Connect Service Client (Version: 1.24.738.1) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) JDownloader 0.9 (x32 Version: 0.9) Left 4 Dead 2 (x32) Logitech Gaming Software (Version: 8.45.88) Logitech Gaming Software 8.45 (Version: 8.45.88) LogMeIn Hamachi (x32 Version: 2.1.0.374) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) MEDUSA NX USB 5.1 Gaming Headset (x32) Metro 2033 (x32) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Corporation (Version: 9.1.0.0) Microsoft Corporation (x32 Version: 9.1.0.0) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft LifeCam (Version: 3.60.253.0) Microsoft Office (x32 Version: 14.0.6120.5004) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) MyPhoneExplorer (x32 Version: 1.8.4) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA GeForce Experience 1.6 (Version: 1.6) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.131.854) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 7.2.17 (Version: 7.2.17) NVIDIA Update Components (Version: 7.2.17) NVIDIA Virtual Audio 1.2.1 (Version: 1.2.1) Origin (x32 Version: 9.1.15.109) Paint.NET v3.5.10 (Version: 3.60.0) PDF-Viewer (Version: 2.5.207.0) Photo Common (x32 Version: 16.4.3508.0205) PunkBuster Services (x32 Version: 0.991) Qualcomm Atheros Bluetooth Suite (64) (Version: 8.0.0.206) Qualcomm Atheros Killer Network Manager (Version: 6.1.0.437) Qualcomm Atheros Killer Network Manager (x32 Version: 6.1.0.437) Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6662) Realtek PCIE Card Reader (x32 Version: 6.2.8400.27024) Revo Uninstaller 1.94 (x32 Version: 1.94) Rome - Total War - Gold Edition (x32 Version: 1.6) S.T.A.L.K.E.R.: Shadow of Chernobyl (x32) SHIELD Streaming (Version: 1.05.19) SimCity™ (x32 Version: 1.0.0.0) Skype™ 6.3 (x32 Version: 6.3.107) Spec Ops: The Line (x32) Stalker Complete 2009 v1.4.4 (x32) Steam (x32 Version: 1.0.0.0) Streamripper (Remove only) (x32) Synaptics Pointing Device Driver (Version: 16.2.10.12) The Elder Scrolls V: Skyrim (x32) Ubisoft Game Launcher (x32 Version: 1.0.0.0) VLC media player 2.0.7 (Version: 2.0.7) Winamp (x32 Version: 5.63 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) Windows Live Communications Platform (x32 Version: 16.4.3508.0205) Windows Live Essentials (x32 Version: 16.4.3508.0205) Windows Live Installer (x32 Version: 16.4.3508.0205) Windows Live Messenger (x32 Version: 16.4.3508.0205) Windows Live Photo Common (x32 Version: 16.4.3508.0205) Windows Live PIMT Platform (x32 Version: 16.4.3508.0205) Windows Live SOXE (x32 Version: 16.4.3508.0205) Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205) Windows Live UX Platform (x32 Version: 16.4.3508.0205) Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205) XCOM: Enemy Unknown (x32) Yontoo 2.05 (Version: 2.05) ZoneAlarm Firewall (x32 Version: 11.0.000.057) ZoneAlarm LTD Toolbar ZoneAlarm Security (x32 Version: 11.0.000.504) ==================== Restore Points ========================= 20-07-2013 21:55:43 Installed ProductName from default.wxl 26-07-2013 11:55:38 DirectX wurde installiert 03-08-2013 10:21:16 Microsoft Visual C++ 2005 Redistributable wird installiert 04-08-2013 18:45:03 DirectX wurde installiert 07-08-2013 19:09:59 Windows Update ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation) Task: {11A8D0C5-0519-4ECB-B18C-CD2C02EDA4F0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15] (Adobe Systems Incorporated) Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {27D95B26-DC3F-4D1B-ADF5-696F39101A27} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect Task: {2A2718EA-A9F7-405C-BADA-F91D74DBD3AE} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update Task: {35278D6F-0615-437B-8B71-4AB11520098C} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-717783921-2200971646-309864134-1002 Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem Task: {3D09D16E-8BA6-4BF2-A6C8-A79F1D4F93DE} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation) Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required Task: {5CF6BCEF-F333-4956-A857-EC519D9AD3F7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation) Task: {68A83A1B-15E6-4E19-8D7D-584315E8A597} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2012-09-20] (Microsoft Corporation) Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation) Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode) Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific Task: {BF650398-6232-49D2-8A9F-8D6EEC1928B0} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\Windows\system32\sc.exe [2012-07-26] (Microsoft Corporation) Task: {C0BB0717-03E4-4A2D-9C43-F882C382ADEF} - System32\Tasks\WPD\SqmUpload_S-1-5-21-717783921-2200971646-309864134-1002 => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork Task: {D58B4E80-543A-49D3-B0EB-D16131BDB3D7} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe [2012-08-15] (Microsoft Corporation) Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery Task: {DF504E48-196D-42BC-9DB6-9FE00ABB24CF} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {E316EF28-8C08-4624-A078-4F1A514749D4} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask Task: {E87295CD-2805-4EED-9961-BB468C7183B1} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Faulty Device Manager Devices ============= Name: BisonCam, NB Pro Description: USB-Videogerät Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Microsoft Service: usbvideo Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (08/07/2013 10:27:40 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (08/07/2013 10:27:40 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (08/02/2013 00:41:46 PM) (Source: Application Hang) (User: ) Description: Programm ICQ.exe, Version 7.8.0.6800 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a98 Startzeit: 01ce8f6c7184c895 Endzeit: 5 Anwendungspfad: C:\Program Files (x86)\ICQ7M\ICQ.exe Berichts-ID: 1ec60bb2-fb60-11e2-be98-a417319ef79a Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (08/02/2013 00:38:03 PM) (Source: Application Hang) (User: ) Description: Programm ICQ.exe, Version 7.8.0.6800 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 185c Startzeit: 01ce8f6b856246da Endzeit: 6 Anwendungspfad: C:\Program Files (x86)\ICQ7M\ICQ.exe Berichts-ID: 9800d4e9-fb5f-11e2-be98-a417319ef79a Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (08/01/2013 05:34:01 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (08/01/2013 05:34:01 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (08/01/2013 05:26:09 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (08/01/2013 05:26:08 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (07/30/2013 02:38:04 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Hotkey.exe, Version: 6.0.0.71, Zeitstempel: 0x506f10ae Name des fehlerhaften Moduls: brightness.dll, Version: 1.0.0.1, Zeitstempel: 0x501c4bea Ausnahmecode: 0xc0000005 Fehleroffset: 0x000018f8 ID des fehlerhaften Prozesses: 0x1288 Startzeit der fehlerhaften Anwendung: 0xHotkey.exe0 Pfad der fehlerhaften Anwendung: Hotkey.exe1 Pfad des fehlerhaften Moduls: Hotkey.exe2 Berichtskennung: Hotkey.exe3 Vollständiger Name des fehlerhaften Pakets: Hotkey.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Hotkey.exe5 Error: (07/30/2013 02:38:04 PM) (Source: .NET Runtime) (User: ) Description: Anwendung: Hotkey.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.AccessViolationException Stapel: bei HotKey.CallingVariations.GetBrightness() bei HotKey.ControlCenter.myDevice_ControlCenter_change(System.Object, System.EventArgs) bei HotKey.Device+EventHandler.Invoke(System.Object, System.EventArgs) bei HotKey.Device.OnChange(HotKey.ControlCenterEventArgs) bei HotKey.Device.set_ACBrightness(Int32) bei HotKey.HotKey.OnSystemResume() bei HotKey.HotKey.SysResume_Tick(System.Object, System.EventArgs) bei System.Windows.Forms.Timer.OnTick(System.EventArgs) bei System.Windows.Forms.Timer+TimerNativeWindow.WndProc(System.Windows.Forms.Message ByRef) bei System.Windows.Forms.NativeWindow.Callback(IntPtr, Int32, IntPtr, IntPtr) bei System.Windows.Forms.UnsafeNativeMethods.DispatchMessageW(MSG ByRef) bei System.Windows.Forms.Application+ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(IntPtr, Int32, Int32) bei System.Windows.Forms.Application+ThreadContext.RunMessageLoopInner(Int32, System.Windows.Forms.ApplicationContext) bei System.Windows.Forms.Application+ThreadContext.RunMessageLoop(Int32, System.Windows.Forms.ApplicationContext) bei System.Windows.Forms.Application.Run(System.Windows.Forms.Form) bei HotKey.Program.Main() System errors: ============= Error: (08/08/2013 07:52:02 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Hamachi2Svc erreicht. Error: (08/07/2013 10:27:31 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT) Description: 0xc000014d0 Error: (08/07/2013 00:15:32 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Verbessertes Windows-Audio/Video-Streaming" ist von folgendem Dienst abhängig: lltdio. Dieser Dienst ist möglicherweise nicht installiert. Error: (08/01/2013 05:33:51 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT) Description: 0xc000014d0 Error: (08/01/2013 05:33:58 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 01.08.2013 um 17:28:05 unerwartet heruntergefahren. Error: (08/01/2013 00:24:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (08/01/2013 00:24:42 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (07/30/2013 01:06:50 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 30.07.2013 um 13:02:36 unerwartet heruntergefahren. Error: (07/30/2013 01:06:44 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT) Description: 0xc000014d0 Error: (07/30/2013 06:46:57 AM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "A-DESKTOP", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{D9239AD0-4F10-43E7-B66F-C95BAF31D8AA}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Microsoft Office Sessions: ========================= Error: (08/07/2013 10:27:40 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (08/07/2013 10:27:40 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (08/02/2013 00:41:46 PM) (Source: Application Hang)(User: ) Description: ICQ.exe7.8.0.6800a9801ce8f6c7184c8955C:\Program Files (x86)\ICQ7M\ICQ.exe1ec60bb2-fb60-11e2-be98-a417319ef79a Error: (08/02/2013 00:38:03 PM) (Source: Application Hang)(User: ) Description: ICQ.exe7.8.0.6800185c01ce8f6b856246da6C:\Program Files (x86)\ICQ7M\ICQ.exe9800d4e9-fb5f-11e2-be98-a417319ef79a Error: (08/01/2013 05:34:01 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (08/01/2013 05:34:01 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (08/01/2013 05:26:09 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (08/01/2013 05:26:08 PM) (Source: NvStreamSvc)(User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (07/30/2013 02:38:04 PM) (Source: Application Error)(User: ) Description: Hotkey.exe6.0.0.71506f10aebrightness.dll1.0.0.1501c4beac0000005000018f8128801ce8d150b47b275C:\Program Files (x86)\Hotkey\Hotkey.exeC:\Program Files (x86)\Hotkey\brightness.dlle07e2b2c-f914-11e2-be97-a417319ef79a Error: (07/30/2013 02:38:04 PM) (Source: .NET Runtime)(User: ) Description: Anwendung: Hotkey.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.AccessViolationException Stapel: bei HotKey.CallingVariations.GetBrightness() bei HotKey.ControlCenter.myDevice_ControlCenter_change(System.Object, System.EventArgs) bei HotKey.Device+EventHandler.Invoke(System.Object, System.EventArgs) bei HotKey.Device.OnChange(HotKey.ControlCenterEventArgs) bei HotKey.Device.set_ACBrightness(Int32) bei HotKey.HotKey.OnSystemResume() bei HotKey.HotKey.SysResume_Tick(System.Object, System.EventArgs) bei System.Windows.Forms.Timer.OnTick(System.EventArgs) bei System.Windows.Forms.Timer+TimerNativeWindow.WndProc(System.Windows.Forms.Message ByRef) bei System.Windows.Forms.NativeWindow.Callback(IntPtr, Int32, IntPtr, IntPtr) bei System.Windows.Forms.UnsafeNativeMethods.DispatchMessageW(MSG ByRef) bei System.Windows.Forms.Application+ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(IntPtr, Int32, Int32) bei System.Windows.Forms.Application+ThreadContext.RunMessageLoopInner(Int32, System.Windows.Forms.ApplicationContext) bei System.Windows.Forms.Application+ThreadContext.RunMessageLoop(Int32, System.Windows.Forms.ApplicationContext) bei System.Windows.Forms.Application.Run(System.Windows.Forms.Form) bei HotKey.Program.Main() CodeIntegrity Errors: =================================== Date: 2013-04-26 09:14:24.422 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:24.293 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:24.165 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:24.044 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:23.926 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:23.804 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:23.682 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:23.554 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:23.432 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. Date: 2013-04-26 09:14:23.301 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll with signing level Unsigned while the system requires signing level Microsoft or better to load. ==================== Memory info =========================== Percentage of memory in use: 14% Total physical RAM: 16343.91 MB Available physical RAM: 13906.63 MB Total Pagefile: 18647.91 MB Available Pagefile: 15767.29 MB Total Virtual: 8192 MB Available Virtual: 8191.76 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:107.83 GB) (Free:56.73 GB) NTFS (Disk=0 Partition=4) Drive d: (Volume) (Fixed) (Total:698.51 GB) (Free:253.01 GB) NTFS (Disk=1 Partition=2) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 119 GB) (Disk ID: C37CACCF) Partition: GPT Partition Type ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 00000000) Partition: GPT Partition Type ==================== End Of Log ============================ FRST.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-08-2013 Ran by Daniel (administrator) on 08-08-2013 18:54:00 Running from C:\Users\Daniel\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\ifxspmgt.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\ifxtcs.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\IfxPsdSv.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (Microsoft) C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TouchControl.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\PSDrt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\SpTna.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe () C:\Program Files\AuthenTec TrueSuite\x86\IEWebSiteLogon.exe (Authentec) C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Yontoo LLC) C:\Users\Daniel\AppData\Roaming\Yontoo\YontooDesktop.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Microsoft Corporation) C:\Windows\SysWOW64\NOTEPAD.EXE (VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\setup\avast.setup ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [KeepSafe] - C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe [38728 2011-10-21] (Authentec) HKLM\...\Run: [] - [x] HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [764032 2012-08-10] (Qualcomm Atheros) HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-10] (Atheros Communications) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKLM\...\Run: [Cm106Sound] - C:\Windows\Syswow64\cm106.dll [8151040 2010-07-01] (C-Media Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKCU\...\Run: [Steam] - D:\Spiele\Steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [DAEMON Tools Lite] - D:\Programme\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKCU\...\Run: [EPSON2C67D3 (Epson Stylus SX235)] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.EXE /FU "C:\Users\Daniel\AppData\Local\Temp\E_S43B8.tmp" /EF "HKCU" [x] HKCU\...\Run: [Yontoo Desktop] - C:\Users\Daniel\AppData\Roaming\Yontoo\YontooDesktop.exe [42784 2013-03-13] (Yontoo LLC) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-02] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\Sound Blaster X-Fi MB 2\THXAudioCP\THXAudio.exe [1517056 2011-08-29] (Creative Technology Ltd) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL, C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation) AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [653600 2013-07-27] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\Hotkey.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mysn.de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mysn.de SearchScopes: HKLM - DefaultScope {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSBTDF&pc=MASB&src=IE-SearchBox SearchScopes: HKLM-x32 - DefaultScope {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSBTDF&pc=MASB&src=IE-SearchBox SearchScopes: HKCU - DefaultScope {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&r=171 SearchScopes: HKCU - {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&r=171 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.DLL (AuthenTec Inc.) BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Yontoo - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 02 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 03 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 04 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 05 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 06 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 18 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 05 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 06 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 18 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default FF user.js: detected! => C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\user.js FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @checkpoint.com/FFApi - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll No File FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF Extension: DownloadHelper - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-10] (Qualcomm Atheros Commnucations) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3516408 2013-07-05] (devolo AG) R2 FPLService; C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [2125160 2012-08-24] (AuthenTec, Inc) R2 IFXSpMgtSrv; C:\Program Files (x86)\Infineon\Security Platform Software\ifxspmgt.exe [1141656 2012-08-06] (Infineon Technologies AG) R2 IFXTCS; C:\Program Files (x86)\Infineon\Security Platform Software\ifxtcs.exe [994200 2012-08-06] (Infineon Technologies AG) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-09-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-09-18] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 PersonalSecureDriveService; C:\Program Files (x86)\Infineon\Security Platform Software\IfxPsdSv.exe [212888 2012-08-06] (Infineon Technologies AG) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-05-24] () R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [45568 2012-09-13] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2012-09-24] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401256 2012-07-16] (AuthenTec, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) R2 Yontoo Desktop Updater; C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [23552 2013-03-13] (Microsoft) ==================== Drivers (Whitelisted) ==================== R3 akw8x64; C:\Windows\system32\DRIVERS\akw8x64.sys [3203440 2012-09-24] (Qualcomm Atheros, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] () R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2012-09-24] (Qualcomm Atheros, Inc.) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-10] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-10] (DT Soft Ltd) R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.) R3 LGSUsbFilt; C:\Windows\system32\DRIVERS\LGSUsbFilt.Sys [44272 2013-01-17] (Logitech Inc.) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2013-07-05] (CACE Technologies) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R1 PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [44576 2012-02-04] (Infineon Technologies AG) S3 USBMULCD; C:\Windows\system32\drivers\CM10664.sys [1309696 2009-09-25] (C-Media Electronics Inc) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-08 18:53 - 2013-08-08 18:53 - 00000000 ____D C:\FRST 2013-08-08 18:52 - 2013-08-08 18:52 - 01790059 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-08-08 16:16 - 2013-08-08 17:34 - 00042632 _____ C:\Windows\WindowsUpdate.log 2013-08-08 16:16 - 2013-08-08 16:16 - 00000000 ___RD C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-08 06:35 - 2013-08-08 06:35 - 00136332 _____ C:\Users\Daniel\Desktop\OTL.Txt 2013-08-07 21:22 - 2013-08-07 21:22 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-07 21:22 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-07 21:10 - 2013-08-07 21:10 - 00000000 ____D C:\Windows\system32\MRT 2013-08-05 10:53 - 2013-08-05 10:53 - 00000000 ____D C:\Users\Daniel\Desktop\kofler 2013-08-04 20:45 - 2013-08-04 20:45 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2013-08-02 12:33 - 2013-08-02 13:25 - 00004543 _____ C:\Users\Daniel\AppData\Roaming\CamStudio.cfg 2013-08-02 12:33 - 2013-08-02 13:25 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamShapes.ini 2013-08-02 12:33 - 2013-08-02 13:25 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamLayout.ini 2013-08-02 12:33 - 2013-08-02 13:25 - 00000083 _____ C:\Users\Daniel\AppData\Roaming\Camdata.ini 2013-08-02 12:31 - 2013-08-02 12:31 - 00001051 _____ C:\Users\Public\Desktop\CamStudio.lnk 2013-08-02 12:31 - 2013-08-02 12:31 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2013-08-01 17:26 - 2013-08-01 17:26 - 00000000 ____D C:\NvidiaLogging 2013-08-01 17:25 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-01 17:25 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-08-01 17:25 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-07-26 13:58 - 2013-07-26 13:58 - 00000000 ____D C:\Users\Daniel\Documents\NBGI 2013-07-26 13:56 - 2013-07-26 13:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\NBGI 2013-07-22 10:44 - 2013-07-22 11:20 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\burnaware.ini 2013-07-22 10:34 - 2013-07-22 10:34 - 00000000 ____D C:\Program Files (x86)\BurnAware Free 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DVDVideoSoft 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-21 13:39 - 2013-07-21 13:39 - 00000000 ____D C:\Users\Daniel\Documents\EA Games 2013-07-21 13:36 - 2013-07-21 13:36 - 00000000 ____D C:\Users\Daniel\AppData\Local\EA Games 2013-07-20 18:33 - 2013-07-20 18:33 - 00281248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-17 02:42 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-17 02:42 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-17 02:42 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-17 02:42 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-17 02:42 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-17 02:42 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-17 02:42 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-17 02:42 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-17 02:42 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-17 02:42 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-17 02:42 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-17 02:42 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-17 02:42 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-17 02:42 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-17 02:42 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-17 02:42 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-17 02:42 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-17 02:42 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-17 02:42 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-17 02:42 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-17 02:42 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-17 02:42 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-17 02:42 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-17 02:42 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-17 02:42 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-16 12:47 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-16 12:46 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-16 12:46 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-16 12:46 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-16 12:46 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-16 12:46 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-16 12:46 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-16 12:46 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-16 12:46 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-16 12:45 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-16 12:45 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-16 12:06 - 2013-07-16 12:06 - 00000000 ___RD C:\Users\Daniel\Documents\Notes 2013-07-16 11:49 - 2013-07-05 14:53 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys 2013-07-15 21:15 - 2013-07-15 21:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-10 08:11 - 2005-01-12 16:53 - 01233920 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4.dll 2013-07-10 08:11 - 2005-01-12 16:53 - 00082432 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4r.dll 2013-07-10 08:11 - 2005-01-12 16:53 - 00044544 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4a.dll ==================== One Month Modified Files and Folders ======= 2013-08-08 18:53 - 2013-08-08 18:53 - 00000000 ____D C:\FRST 2013-08-08 18:52 - 2013-08-08 18:52 - 01790059 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-08-08 18:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-08 17:57 - 2013-04-05 11:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-08 17:34 - 2013-08-08 16:16 - 00042632 _____ C:\Windows\WindowsUpdate.log 2013-08-08 16:16 - 2013-08-08 16:16 - 00000000 ___RD C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-08 16:16 - 2013-05-05 11:23 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Yontoo 2013-08-08 16:16 - 2013-04-05 12:46 - 00180224 ___SH C:\Users\Daniel\Desktop\Thumbs.db 2013-08-08 16:16 - 2013-04-03 16:53 - 00000000 ____D C:\ProgramData\Bigfoot Networks 2013-08-08 06:35 - 2013-08-08 06:35 - 00136332 _____ C:\Users\Daniel\Desktop\OTL.Txt 2013-08-08 06:29 - 2013-04-06 14:32 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2013-08-07 22:41 - 2013-05-17 14:05 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Winamp 2013-08-07 22:38 - 2013-04-05 11:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-08-07 22:34 - 2012-07-26 12:27 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-08-07 22:34 - 2012-07-26 12:27 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-08-07 22:34 - 2012-07-26 09:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-07 22:27 - 2013-04-03 16:42 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-07 22:27 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-07 21:22 - 2013-08-07 21:22 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-07 21:10 - 2013-08-07 21:10 - 00000000 ____D C:\Windows\system32\MRT 2013-08-07 06:44 - 2013-04-18 10:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\ICQ 2013-08-06 16:48 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-05 10:53 - 2013-08-05 10:53 - 00000000 ____D C:\Users\Daniel\Desktop\kofler 2013-08-04 20:45 - 2013-08-04 20:45 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2013-08-04 20:45 - 2013-04-05 13:33 - 00000000 ____D C:\Users\Daniel\Documents\my games 2013-08-04 02:13 - 2013-04-05 16:32 - 00000000 ____D C:\Users\Daniel 2013-08-02 13:25 - 2013-08-02 12:33 - 00004543 _____ C:\Users\Daniel\AppData\Roaming\CamStudio.cfg 2013-08-02 13:25 - 2013-08-02 12:33 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamShapes.ini 2013-08-02 13:25 - 2013-08-02 12:33 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamLayout.ini 2013-08-02 13:25 - 2013-08-02 12:33 - 00000083 _____ C:\Users\Daniel\AppData\Roaming\Camdata.ini 2013-08-02 12:31 - 2013-08-02 12:31 - 00001051 _____ C:\Users\Public\Desktop\CamStudio.lnk 2013-08-02 12:31 - 2013-08-02 12:31 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2013-08-01 19:06 - 2013-04-05 13:01 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\.minecraft 2013-08-01 18:26 - 2013-04-05 11:43 - 00000000 ___RD C:\Users\Daniel\Desktop\Spiele 2013-08-01 18:10 - 2013-04-06 16:00 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Origin 2013-08-01 18:10 - 2013-04-06 16:00 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2013-08-01 17:26 - 2013-08-01 17:26 - 00000000 ____D C:\NvidiaLogging 2013-08-01 17:26 - 2013-04-03 16:42 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-01 17:26 - 2013-04-03 16:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-07-29 14:24 - 2013-06-04 12:31 - 00000078 _____ C:\Users\Daniel\Desktop\rome total war multiplayer.txt 2013-07-28 17:09 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-07-28 11:33 - 2013-04-18 11:03 - 00000000 ____D C:\Users\Daniel\Documents\ICQ 2013-07-27 18:53 - 2013-04-05 22:20 - 00000000 ____D C:\Users\Daniel\AppData\Local\Paint.NET 2013-07-26 13:58 - 2013-07-26 13:58 - 00000000 ____D C:\Users\Daniel\Documents\NBGI 2013-07-26 13:56 - 2013-07-26 13:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\NBGI 2013-07-26 11:41 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-07-23 20:17 - 2013-04-05 16:38 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-717783921-2200971646-309864134-1002 2013-07-22 11:20 - 2013-07-22 10:44 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\burnaware.ini 2013-07-22 10:44 - 2013-04-05 11:13 - 00000000 ___RD C:\Users\Daniel\Desktop\Programme 2013-07-22 10:34 - 2013-07-22 10:34 - 00000000 ____D C:\Program Files (x86)\BurnAware Free 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DVDVideoSoft 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-21 13:39 - 2013-07-21 13:39 - 00000000 ____D C:\Users\Daniel\Documents\EA Games 2013-07-21 13:36 - 2013-07-21 13:36 - 00000000 ____D C:\Users\Daniel\AppData\Local\EA Games 2013-07-20 23:55 - 2013-04-10 17:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DAEMON Tools Lite 2013-07-20 18:33 - 2013-07-20 18:33 - 00281248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-17 16:34 - 2012-07-26 12:29 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-17 16:34 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-16 12:06 - 2013-07-16 12:06 - 00000000 ___RD C:\Users\Daniel\Documents\Notes 2013-07-16 12:06 - 2013-06-04 17:21 - 00000000 ____D C:\Program Files (x86)\devolo 2013-07-16 11:45 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-07-15 21:16 - 2013-07-15 21:15 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-15 21:16 - 2013-04-05 11:19 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-07-14 13:22 - 2013-05-31 11:48 - 00000000 ____D C:\Users\Daniel\Tracing 2013-07-14 13:22 - 2013-04-05 11:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\LogMeIn Hamachi 2013-07-14 12:56 - 2013-04-25 10:34 - 00000000 ____D C:\Program Files\CCleaner ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-01 18:01 ==================== End Of Log ============================ --- --- --- |
08.08.2013, 19:24 | #4 |
/// the machine /// TB-Ausbilder | Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.08.2013, 20:45 | #5 |
| Abuse Brief Telekom: unerwünschte Zugriffe über Internet ZugangCode:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.08.06 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16635 Daniel :: DANIEL-GAMINGNB [Administrator] 08.08.2013 20:58:52 mbam-log-2013-08-08 (20-58-52).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 238815 Laufzeit: 1 Minute(n), 32 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v2.306 - Datei am 08/08/2013 um 21:34:39 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzer : Daniel - DANIEL-GAMINGNB # Bootmodus : Normal # Ausgeführt unter : C:\Users\Daniel\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : Yontoo Desktop Updater ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Program Files (x86)\Yontoo Ordner Gelöscht : C:\Users\Daniel\AppData\Roaming\CheckPoint\ZoneAlarm LTD Toolbar Ordner Gelöscht : C:\Users\Daniel\AppData\Roaming\Yontoo ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZoneAlarm LTD Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Tarma Installer Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Yontoo Desktop] ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\prefs.js C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\user.js ... Gelöscht ! Gelöscht : user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers"); Gelöscht : user_pref("extentions.y2layers.installId", "3e0bc5d4-e153-4e4a-a2bb-f4cc8897a9f0"); ************************* AdwCleaner[S1].txt - [4452 octets] - [08/08/2013 21:34:39] ########## EOF - C:\AdwCleaner[S1].txt - [4512 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.3.8 (08.07.2013:4) OS: Windows 8 x64 Ran by Daniel on 08.08.2013 at 21:38:47,56 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\powerpack Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\trolltech ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Daniel\AppData\Roaming\mozilla\firefox\profiles\yieiwv0c.default\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.08.2013 at 21:42:35,83 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-08-2013 Ran by Daniel (administrator) on 08-08-2013 21:43:25 Running from C:\Users\Daniel\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\ifxspmgt.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\ifxtcs.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\IfxPsdSv.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\PSDrt.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\SpTna.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TouchControl.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe () C:\Program Files\AuthenTec TrueSuite\x86\IEWebSiteLogon.exe (Authentec) C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [KeepSafe] - C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe [38728 2011-10-21] (Authentec) HKLM\...\Run: [] - [x] HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [764032 2012-08-10] (Qualcomm Atheros) HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-10] (Atheros Communications) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKLM\...\Run: [Cm106Sound] - C:\Windows\Syswow64\cm106.dll [8151040 2010-07-01] (C-Media Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKCU\...\Run: [Steam] - D:\Spiele\Steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [DAEMON Tools Lite] - D:\Programme\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKCU\...\Run: [EPSON2C67D3 (Epson Stylus SX235)] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.EXE /FU "C:\Users\Daniel\AppData\Local\Temp\E_S43B8.tmp" /EF "HKCU" [x] HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-02] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\Sound Blaster X-Fi MB 2\THXAudioCP\THXAudio.exe [1517056 2011-08-29] (Creative Technology Ltd) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL, C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] (NVIDIA Corporation) AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\Hotkey.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mysn.de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mysn.de SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&r=171 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.DLL (AuthenTec Inc.) BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 02 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 03 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 04 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 05 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 06 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 18 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 05 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 06 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 18 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF Extension: DownloadHelper - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-10] (Qualcomm Atheros Commnucations) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3516408 2013-07-05] (devolo AG) R2 FPLService; C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [2125160 2012-08-24] (AuthenTec, Inc) R2 IFXSpMgtSrv; C:\Program Files (x86)\Infineon\Security Platform Software\ifxspmgt.exe [1141656 2012-08-06] (Infineon Technologies AG) R2 IFXTCS; C:\Program Files (x86)\Infineon\Security Platform Software\ifxtcs.exe [994200 2012-08-06] (Infineon Technologies AG) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-09-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-09-18] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 PersonalSecureDriveService; C:\Program Files (x86)\Infineon\Security Platform Software\IfxPsdSv.exe [212888 2012-08-06] (Infineon Technologies AG) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-05-24] () R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [45568 2012-09-13] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2012-09-24] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401256 2012-07-16] (AuthenTec, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R3 akw8x64; C:\Windows\system32\DRIVERS\akw8x64.sys [3203440 2012-09-24] (Qualcomm Atheros, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] () R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2012-09-24] (Qualcomm Atheros, Inc.) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-10] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-10] (DT Soft Ltd) R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.) R3 LGSUsbFilt; C:\Windows\system32\DRIVERS\LGSUsbFilt.Sys [44272 2013-01-17] (Logitech Inc.) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2013-07-05] (CACE Technologies) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R1 PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [44576 2012-02-04] (Infineon Technologies AG) S3 USBMULCD; C:\Windows\system32\drivers\CM10664.sys [1309696 2009-09-25] (C-Media Electronics Inc) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-08 21:38 - 2013-08-08 21:38 - 00000000 ____D C:\Windows\ERUNT 2013-08-08 21:37 - 2013-08-08 21:37 - 00004571 _____ C:\Users\Daniel\Desktop\AdwCleaner[S1].txt 2013-08-08 21:36 - 2013-08-08 21:36 - 00000438 _____ C:\Windows\PFRO.log 2013-08-08 21:36 - 2013-08-08 21:36 - 00000000 ___RD C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-08 21:34 - 2013-08-08 21:34 - 00004571 _____ C:\AdwCleaner[S1].txt 2013-08-08 21:06 - 2013-08-08 21:06 - 00001054 _____ C:\Users\Daniel\Desktop\mbam.txt 2013-08-08 20:58 - 2013-08-08 20:58 - 00957230 _____ (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe 2013-08-08 20:57 - 2013-08-08 20:57 - 00666633 _____ C:\Users\Daniel\Desktop\adwcleaner.exe 2013-08-08 18:54 - 2013-08-08 18:54 - 00038414 _____ C:\Users\Daniel\Desktop\FRST 1.txt 2013-08-08 18:54 - 2013-08-08 18:54 - 00030316 _____ C:\Users\Daniel\Desktop\Addition.txt 2013-08-08 18:53 - 2013-08-08 18:53 - 00000000 ____D C:\FRST 2013-08-08 18:52 - 2013-08-08 18:52 - 01790059 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-08-08 16:16 - 2013-08-08 17:34 - 00042632 _____ C:\Windows\WindowsUpdate.log 2013-08-08 06:35 - 2013-08-08 06:35 - 00136332 _____ C:\Users\Daniel\Desktop\OTL.Txt 2013-08-07 21:22 - 2013-08-07 21:22 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-07 21:22 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-07 21:10 - 2013-08-07 21:10 - 00000000 ____D C:\Windows\system32\MRT 2013-08-05 10:53 - 2013-08-05 10:53 - 00000000 ____D C:\Users\Daniel\Desktop\kofler 2013-08-04 20:45 - 2013-08-04 20:45 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2013-08-02 12:33 - 2013-08-02 13:25 - 00004543 _____ C:\Users\Daniel\AppData\Roaming\CamStudio.cfg 2013-08-02 12:33 - 2013-08-02 13:25 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamShapes.ini 2013-08-02 12:33 - 2013-08-02 13:25 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamLayout.ini 2013-08-02 12:33 - 2013-08-02 13:25 - 00000083 _____ C:\Users\Daniel\AppData\Roaming\Camdata.ini 2013-08-02 12:31 - 2013-08-02 12:31 - 00001051 _____ C:\Users\Public\Desktop\CamStudio.lnk 2013-08-02 12:31 - 2013-08-02 12:31 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2013-08-01 17:26 - 2013-08-01 17:26 - 00000000 ____D C:\NvidiaLogging 2013-08-01 17:25 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-01 17:25 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-08-01 17:25 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-07-26 13:58 - 2013-07-26 13:58 - 00000000 ____D C:\Users\Daniel\Documents\NBGI 2013-07-26 13:56 - 2013-07-26 13:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\NBGI 2013-07-22 10:44 - 2013-07-22 11:20 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\burnaware.ini 2013-07-22 10:34 - 2013-07-22 10:34 - 00000000 ____D C:\Program Files (x86)\BurnAware Free 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DVDVideoSoft 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-21 13:39 - 2013-07-21 13:39 - 00000000 ____D C:\Users\Daniel\Documents\EA Games 2013-07-21 13:36 - 2013-07-21 13:36 - 00000000 ____D C:\Users\Daniel\AppData\Local\EA Games 2013-07-20 18:33 - 2013-07-20 18:33 - 00281248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-17 02:42 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-17 02:42 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-17 02:42 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-17 02:42 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-17 02:42 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-17 02:42 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-17 02:42 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-17 02:42 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-17 02:42 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-17 02:42 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-17 02:42 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-17 02:42 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-17 02:42 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-17 02:42 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-17 02:42 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-17 02:42 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-17 02:42 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-17 02:42 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-17 02:42 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-17 02:42 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-17 02:42 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-17 02:42 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-17 02:42 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-17 02:42 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-17 02:42 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-16 12:47 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-16 12:46 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-16 12:46 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-16 12:46 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-16 12:46 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-16 12:46 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-16 12:46 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-16 12:46 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-16 12:46 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-16 12:45 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-16 12:45 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-16 12:06 - 2013-07-16 12:06 - 00000000 ___RD C:\Users\Daniel\Documents\Notes 2013-07-16 11:49 - 2013-07-05 14:53 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys 2013-07-15 21:15 - 2013-07-15 21:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-10 08:11 - 2005-01-12 16:53 - 01233920 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4.dll 2013-07-10 08:11 - 2005-01-12 16:53 - 00082432 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4r.dll 2013-07-10 08:11 - 2005-01-12 16:53 - 00044544 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4a.dll 109 ==================== One Month Modified Files and Folders ======= 2013-08-08 21:43 - 2012-07-26 12:27 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-08-08 21:43 - 2012-07-26 12:27 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-08-08 21:43 - 2012-07-26 09:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-08 21:42 - 2013-08-08 21:42 - 00000998 _____ C:\Users\Daniel\Desktop\JRT.txt 2013-08-08 21:38 - 2013-08-08 21:38 - 00000000 ____D C:\Windows\ERUNT 2013-08-08 21:37 - 2013-08-08 21:37 - 00004571 _____ C:\Users\Daniel\Desktop\AdwCleaner[S1].txt 2013-08-08 21:36 - 2013-08-08 21:36 - 00000438 _____ C:\Windows\PFRO.log 2013-08-08 21:36 - 2013-08-08 21:36 - 00000000 ___RD C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-08 21:36 - 2013-04-03 16:53 - 00000000 ____D C:\ProgramData\Bigfoot Networks 2013-08-08 21:36 - 2013-04-03 16:42 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-08 21:36 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-08 21:35 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-08-08 21:34 - 2013-08-08 21:34 - 00004571 _____ C:\AdwCleaner[S1].txt 2013-08-08 21:33 - 2013-04-06 14:32 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2013-08-08 21:06 - 2013-08-08 21:06 - 00001054 _____ C:\Users\Daniel\Desktop\mbam.txt 2013-08-08 21:02 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-08 21:01 - 2013-06-06 15:27 - 00000125 _____ C:\Users\Daniel\Desktop\netzwerk key.txt 2013-08-08 20:58 - 2013-08-08 20:58 - 00957230 _____ (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe 2013-08-08 20:57 - 2013-08-08 20:57 - 00666633 _____ C:\Users\Daniel\Desktop\adwcleaner.exe 2013-08-08 20:57 - 2013-04-05 11:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-08 18:54 - 2013-08-08 18:54 - 00038414 _____ C:\Users\Daniel\Desktop\FRST 1.txt 2013-08-08 18:54 - 2013-08-08 18:54 - 00030316 _____ C:\Users\Daniel\Desktop\Addition.txt 2013-08-08 18:53 - 2013-08-08 18:53 - 00000000 ____D C:\FRST 2013-08-08 18:52 - 2013-08-08 18:52 - 01790059 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-08-08 17:34 - 2013-08-08 16:16 - 00042632 _____ C:\Windows\WindowsUpdate.log 2013-08-08 16:16 - 2013-04-05 12:46 - 00180224 ___SH C:\Users\Daniel\Desktop\Thumbs.db 2013-08-08 06:35 - 2013-08-08 06:35 - 00136332 _____ C:\Users\Daniel\Desktop\OTL.Txt 2013-08-07 22:41 - 2013-05-17 14:05 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Winamp 2013-08-07 22:38 - 2013-04-05 11:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-08-07 21:22 - 2013-08-07 21:22 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-07 21:10 - 2013-08-07 21:10 - 00000000 ____D C:\Windows\system32\MRT 2013-08-07 06:44 - 2013-04-18 10:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\ICQ 2013-08-06 16:48 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-05 10:53 - 2013-08-05 10:53 - 00000000 ____D C:\Users\Daniel\Desktop\kofler 2013-08-04 20:45 - 2013-08-04 20:45 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2013-08-04 20:45 - 2013-04-05 13:33 - 00000000 ____D C:\Users\Daniel\Documents\my games 2013-08-04 02:13 - 2013-04-05 16:32 - 00000000 ____D C:\Users\Daniel 2013-08-02 13:25 - 2013-08-02 12:33 - 00004543 _____ C:\Users\Daniel\AppData\Roaming\CamStudio.cfg 2013-08-02 13:25 - 2013-08-02 12:33 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamShapes.ini 2013-08-02 13:25 - 2013-08-02 12:33 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamLayout.ini 2013-08-02 13:25 - 2013-08-02 12:33 - 00000083 _____ C:\Users\Daniel\AppData\Roaming\Camdata.ini 2013-08-02 12:31 - 2013-08-02 12:31 - 00001051 _____ C:\Users\Public\Desktop\CamStudio.lnk 2013-08-02 12:31 - 2013-08-02 12:31 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2013-08-01 19:06 - 2013-04-05 13:01 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\.minecraft 2013-08-01 18:26 - 2013-04-05 11:43 - 00000000 ___RD C:\Users\Daniel\Desktop\Spiele 2013-08-01 18:10 - 2013-04-06 16:00 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Origin 2013-08-01 18:10 - 2013-04-06 16:00 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2013-08-01 17:26 - 2013-08-01 17:26 - 00000000 ____D C:\NvidiaLogging 2013-08-01 17:26 - 2013-04-03 16:42 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-01 17:26 - 2013-04-03 16:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-07-29 14:24 - 2013-06-04 12:31 - 00000078 _____ C:\Users\Daniel\Desktop\rome total war multiplayer.txt 2013-07-28 17:09 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-07-28 11:33 - 2013-04-18 11:03 - 00000000 ____D C:\Users\Daniel\Documents\ICQ 2013-07-27 18:53 - 2013-04-05 22:20 - 00000000 ____D C:\Users\Daniel\AppData\Local\Paint.NET 2013-07-26 13:58 - 2013-07-26 13:58 - 00000000 ____D C:\Users\Daniel\Documents\NBGI 2013-07-26 13:56 - 2013-07-26 13:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\NBGI 2013-07-23 20:17 - 2013-04-05 16:38 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-717783921-2200971646-309864134-1002 2013-07-22 11:20 - 2013-07-22 10:44 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\burnaware.ini 2013-07-22 10:44 - 2013-04-05 11:13 - 00000000 ___RD C:\Users\Daniel\Desktop\Programme 2013-07-22 10:34 - 2013-07-22 10:34 - 00000000 ____D C:\Program Files (x86)\BurnAware Free 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DVDVideoSoft 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-21 13:39 - 2013-07-21 13:39 - 00000000 ____D C:\Users\Daniel\Documents\EA Games 2013-07-21 13:36 - 2013-07-21 13:36 - 00000000 ____D C:\Users\Daniel\AppData\Local\EA Games 2013-07-20 23:55 - 2013-04-10 17:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DAEMON Tools Lite 2013-07-20 18:33 - 2013-07-20 18:33 - 00281248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-17 16:34 - 2012-07-26 12:29 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-17 16:34 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-16 12:06 - 2013-07-16 12:06 - 00000000 ___RD C:\Users\Daniel\Documents\Notes 2013-07-16 12:06 - 2013-06-04 17:21 - 00000000 ____D C:\Program Files (x86)\devolo 2013-07-16 11:45 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-07-15 21:16 - 2013-07-15 21:15 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-15 21:16 - 2013-04-05 11:19 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-07-14 13:22 - 2013-05-31 11:48 - 00000000 ____D C:\Users\Daniel\Tracing 2013-07-14 13:22 - 2013-04-05 11:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\LogMeIn Hamachi 2013-07-14 12:56 - 2013-04-25 10:34 - 00000000 ____D C:\Program Files\CCleaner ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-01 18:01 ==================== End Of Log ============================ |
09.08.2013, 10:32 | #6 |
/// the machine /// TB-Ausbilder | Abuse Brief Telekom: unerwünschte Zugriffe über Internet ZugangESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang |
09.08.2013, 18:22 | #7 |
| Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang Ich wusste ja gar nicht, dass ich Probleme hatte o.O Waren sie groß was war denn jetzt alles für ein Zeug drauf? - ich blick gar nimmer durch. tue nur das was du schreibst Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a05057692878084c9d80dc5d67b488eb # engine=14710 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-09 05:01:11 # local_time=2013-08-09 07:01:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=774 16777213 85 91 2517519 152777543 0 0 # compatibility_mode=5893 16776574 100 94 3731620 16656770 0 0 # scanned=423167 # found=4 # cleaned=0 # scan_time=10223 sh=E308693B75496E172B2A11162E764D2D05F2ADC2 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.PAH trojan" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\15378d9c-736924a2" sh=05C96766100B192C2C92095C095089E3F0A3823E ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.PAH trojan" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\437ab1e3-5074cd99" sh=0070A020B48A68A99394251838E8BC094E1EC8A8 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.ORX trojan" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7\724db3c7-424ddf6c" sh=6484325AD7E2B99BD690645B9F29890CF1429DB6 ft=0 fh=0000000000000000 vn="a variant of J2ME/TrojanSMS.Boxer.A trojan" ac=I fn="D:\DOWNLOADS\my Handy\sony ericsson satio\apps\mahjong.zip" Code:
ATTFilter Results of screen317's Security Check version 0.99.71 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Windows Defender Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 25 Adobe Flash Player 11.8.800.94 Mozilla Firefox (22.0) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-08-2013 Ran by Daniel (administrator) on 09-08-2013 19:19:04 Running from C:\Users\Daniel\Desktop Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AuthenTec, Inc) C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\ifxspmgt.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\ifxtcs.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\IfxPsdSv.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\TouchControl.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\PSDrt.exe (Infineon Technologies AG) C:\Program Files (x86)\Infineon\Security Platform Software\SpTna.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AuthenTec Inc.) C:\Program Files\AuthenTec TrueSuite\BioMonitor.exe () C:\Program Files\AuthenTec TrueSuite\x86\IEWebSiteLogon.exe (AuthenTec, Inc.) C:\Program Files\Common Files\AuthenTec\TrueService.exe (Authentec) C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe () C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [KeepSafe] - C:\Program Files\AuthenTec TrueSuite\KeepSafe\fvsvr.exe [38728 2011-10-21] (Authentec) HKLM\...\Run: [] - [x] HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [764032 2012-08-10] (Qualcomm Atheros) HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-10] (Atheros Communications) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-25] (Synaptics Incorporated) HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [7468784 2013-02-28] (Logitech Inc.) HKLM\...\Run: [Cm106Sound] - C:\Windows\Syswow64\cm106.dll [8151040 2010-07-01] (C-Media Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKCU\...\Run: [Steam] - D:\Spiele\Steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [DAEMON Tools Lite] - D:\Programme\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKCU\...\Run: [EPSON2C67D3 (Epson Stylus SX235)] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.EXE /FU "C:\Users\Daniel\AppData\Local\Temp\E_S43B8.tmp" /EF "HKCU" [x] HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-02] (Intel Corporation) HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\Sound Blaster X-Fi MB 2\THXAudioCP\THXAudio.exe [1517056 2011-08-29] (Creative Technology Ltd) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL, C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] (NVIDIA Corporation) AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\Hotkey.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Qualcomm Atheros Killer Network Manager.lnk ShortcutTarget: Qualcomm Atheros Killer Network Manager.lnk -> C:\Program Files\Qualcomm Atheros\Killer Network Manager\KillerNetManager.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.mysn.de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.mysn.de SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&r=171 SearchScopes: HKCU - {329EB792-DE35-4B23-8672-4A1BBF302CD5} URL = hxxp://www.bing.com/search?q={searchTerms}&r=171 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\IEBHO.DLL (AuthenTec Inc.) BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\AuthenTec TrueSuite\x86\IEBHO.dll (AuthenTec Inc.) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 02 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 03 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 04 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 05 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 06 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9 18 %SYSTEMROOT%\system32\BfLLR.dll [196096] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 01 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 02 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 03 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 04 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 05 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 06 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Winsock: Catalog9-x64 18 %SYSTEMROOT%\system32\BfLLR.dll [216064] (Bigfoot Networks, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files\AuthenTec TrueSuite\x86\npffwloplugin.dll (AuthenTec, Inc) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.3 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft) FF Extension: DownloadHelper - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\yieiwv0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{FFB96CC1-7EB3-449D-B827-DB661701C6BB}] C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-10] (Qualcomm Atheros Commnucations) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3516408 2013-07-05] (devolo AG) R2 FPLService; C:\Program Files\AuthenTec TrueSuite\TrueSuiteService.exe [2125160 2012-08-24] (AuthenTec, Inc) R2 IFXSpMgtSrv; C:\Program Files (x86)\Infineon\Security Platform Software\ifxspmgt.exe [1141656 2012-08-06] (Infineon Technologies AG) R2 IFXTCS; C:\Program Files (x86)\Infineon\Security Platform Software\ifxtcs.exe [994200 2012-08-06] (Infineon Technologies AG) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-09-18] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-09-18] (Intel Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 PersonalSecureDriveService; C:\Program Files (x86)\Infineon\Security Platform Software\IfxPsdSv.exe [212888 2012-08-06] (Infineon Technologies AG) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-05-24] () R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [45568 2012-09-13] () R2 Qualcomm Atheros Killer Service; C:\Program Files\Qualcomm Atheros\Killer Network Manager\BFNService.exe [490496 2012-09-24] () R3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401256 2012-07-16] (AuthenTec, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R3 akw8x64; C:\Windows\system32\DRIVERS\akw8x64.sys [3203440 2012-09-24] (Qualcomm Atheros, Inc.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] () R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [74096 2012-09-24] (Qualcomm Atheros, Inc.) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-10] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-10] (DT Soft Ltd) R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.) R3 LGSUsbFilt; C:\Windows\system32\DRIVERS\LGSUsbFilt.Sys [44272 2013-01-17] (Logitech Inc.) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2013-07-05] (CACE Technologies) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R1 PersonalSecureDrive; C:\Windows\System32\drivers\psd.sys [44576 2012-02-04] (Infineon Technologies AG) S3 USBMULCD; C:\Windows\system32\drivers\CM10664.sys [1309696 2009-09-25] (C-Media Electronics Inc) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-09 19:13 - 2013-08-09 19:13 - 00000477 _____ C:\Users\Daniel\Desktop\eset.txt 2013-08-09 16:04 - 2013-08-09 16:04 - 00891098 _____ C:\Users\Daniel\Desktop\SecurityCheck.exe 2013-08-09 16:03 - 2013-08-09 16:03 - 00000795 _____ C:\Windows\setupact.log 2013-08-09 16:03 - 2013-08-09 16:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-09 13:59 - 2013-08-09 13:59 - 00000000 ___RD C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-08 21:42 - 2013-08-08 21:42 - 00000998 _____ C:\Users\Daniel\Desktop\JRT.txt 2013-08-08 21:38 - 2013-08-08 21:38 - 00000000 ____D C:\Windows\ERUNT 2013-08-08 21:37 - 2013-08-08 21:37 - 00004571 _____ C:\Users\Daniel\Desktop\AdwCleaner[S1].txt 2013-08-08 21:36 - 2013-08-08 21:36 - 00000438 _____ C:\Windows\PFRO.log 2013-08-08 21:34 - 2013-08-08 21:34 - 00004571 _____ C:\AdwCleaner[S1].txt 2013-08-08 21:06 - 2013-08-08 21:06 - 00001054 _____ C:\Users\Daniel\Desktop\mbam.txt 2013-08-08 20:58 - 2013-08-08 20:58 - 00957230 _____ (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe 2013-08-08 20:57 - 2013-08-08 20:57 - 00666633 _____ C:\Users\Daniel\Desktop\adwcleaner.exe 2013-08-08 18:54 - 2013-08-08 18:54 - 00038414 _____ C:\Users\Daniel\Desktop\FRST 1.txt 2013-08-08 18:54 - 2013-08-08 18:54 - 00030316 _____ C:\Users\Daniel\Desktop\Addition.txt 2013-08-08 18:53 - 2013-08-08 18:53 - 00000000 ____D C:\FRST 2013-08-08 18:52 - 2013-08-08 18:52 - 01790059 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-08-08 16:16 - 2013-08-09 17:34 - 00076117 _____ C:\Windows\WindowsUpdate.log 2013-08-08 06:35 - 2013-08-08 06:35 - 00136332 _____ C:\Users\Daniel\Desktop\OTL.Txt 2013-08-07 21:22 - 2013-08-07 21:22 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-07 21:22 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-07 21:10 - 2013-08-07 21:10 - 00000000 ____D C:\Windows\system32\MRT 2013-08-05 10:53 - 2013-08-05 10:53 - 00000000 ____D C:\Users\Daniel\Desktop\kofler 2013-08-04 20:45 - 2013-08-04 20:45 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2013-08-02 12:33 - 2013-08-02 13:25 - 00004543 _____ C:\Users\Daniel\AppData\Roaming\CamStudio.cfg 2013-08-02 12:33 - 2013-08-02 13:25 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamShapes.ini 2013-08-02 12:33 - 2013-08-02 13:25 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamLayout.ini 2013-08-02 12:33 - 2013-08-02 13:25 - 00000083 _____ C:\Users\Daniel\AppData\Roaming\Camdata.ini 2013-08-02 12:31 - 2013-08-02 12:31 - 00001051 _____ C:\Users\Public\Desktop\CamStudio.lnk 2013-08-02 12:31 - 2013-08-02 12:31 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2013-08-01 17:26 - 2013-08-01 17:26 - 00000000 ____D C:\NvidiaLogging 2013-08-01 17:25 - 2013-05-14 21:28 - 00039712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-08-01 17:25 - 2013-05-14 21:27 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-08-01 17:25 - 2013-05-14 21:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-07-26 13:58 - 2013-07-26 13:58 - 00000000 ____D C:\Users\Daniel\Documents\NBGI 2013-07-26 13:56 - 2013-07-26 13:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\NBGI 2013-07-22 10:44 - 2013-07-22 11:20 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\burnaware.ini 2013-07-22 10:34 - 2013-07-22 10:34 - 00000000 ____D C:\Program Files (x86)\BurnAware Free 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DVDVideoSoft 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-21 13:39 - 2013-07-21 13:39 - 00000000 ____D C:\Users\Daniel\Documents\EA Games 2013-07-21 13:36 - 2013-07-21 13:36 - 00000000 ____D C:\Users\Daniel\AppData\Local\EA Games 2013-07-20 18:33 - 2013-07-20 18:33 - 00281248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-17 02:42 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-17 02:42 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-17 02:42 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-17 02:42 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-17 02:42 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-17 02:42 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-17 02:42 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-17 02:42 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-17 02:42 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-17 02:42 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-17 02:42 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-17 02:42 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-17 02:42 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-17 02:42 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-17 02:42 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-17 02:42 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-17 02:42 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-17 02:42 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-17 02:42 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-17 02:42 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-17 02:42 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-17 02:42 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-17 02:42 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-17 02:42 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-17 02:42 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-17 02:42 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-17 02:42 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-17 02:42 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-16 12:47 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-16 12:46 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-16 12:46 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-16 12:46 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-16 12:46 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-16 12:46 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-16 12:46 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-16 12:46 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-16 12:46 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-16 12:46 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-16 12:46 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-16 12:46 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-16 12:45 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-16 12:45 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-16 12:06 - 2013-07-16 12:06 - 00000000 ___RD C:\Users\Daniel\Documents\Notes 2013-07-16 11:49 - 2013-07-05 14:53 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys 2013-07-15 21:15 - 2013-07-15 21:16 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-10 08:11 - 2005-01-12 16:53 - 01233920 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4.dll 2013-07-10 08:11 - 2005-01-12 16:53 - 00082432 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4r.dll 2013-07-10 08:11 - 2005-01-12 16:53 - 00044544 ____R (Microsoft Corporation) C:\Users\Daniel\AppData\Roaming\msxml4a.dll 115 ==================== One Month Modified Files and Folders ======= 2013-08-09 19:17 - 2013-08-09 19:17 - 00000812 _____ C:\Users\Daniel\Desktop\checkup.txt 2013-08-09 19:13 - 2013-08-09 19:13 - 00000477 _____ C:\Users\Daniel\Desktop\eset.txt 2013-08-09 19:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-09 18:57 - 2013-04-05 11:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-09 17:34 - 2013-08-08 16:16 - 00076117 _____ C:\Windows\WindowsUpdate.log 2013-08-09 16:07 - 2012-07-26 12:27 - 00754172 _____ C:\Windows\system32\perfh007.dat 2013-08-09 16:07 - 2012-07-26 12:27 - 00156362 _____ C:\Windows\system32\perfc007.dat 2013-08-09 16:07 - 2012-07-26 09:28 - 01748838 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-09 16:04 - 2013-08-09 16:04 - 00891098 _____ C:\Users\Daniel\Desktop\SecurityCheck.exe 2013-08-09 16:03 - 2013-08-09 16:03 - 00000795 _____ C:\Windows\setupact.log 2013-08-09 16:03 - 2013-08-09 16:03 - 00000000 _____ C:\Windows\setuperr.log 2013-08-09 16:03 - 2013-04-06 14:32 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2013-08-09 13:59 - 2013-08-09 13:59 - 00000000 ___RD C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-09 13:59 - 2013-04-03 16:53 - 00000000 ____D C:\ProgramData\Bigfoot Networks 2013-08-08 21:42 - 2013-08-08 21:42 - 00000998 _____ C:\Users\Daniel\Desktop\JRT.txt 2013-08-08 21:38 - 2013-08-08 21:38 - 00000000 ____D C:\Windows\ERUNT 2013-08-08 21:37 - 2013-08-08 21:37 - 00004571 _____ C:\Users\Daniel\Desktop\AdwCleaner[S1].txt 2013-08-08 21:36 - 2013-08-08 21:36 - 00000438 _____ C:\Windows\PFRO.log 2013-08-08 21:36 - 2013-04-03 16:42 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-08 21:36 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-08 21:35 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-08-08 21:34 - 2013-08-08 21:34 - 00004571 _____ C:\AdwCleaner[S1].txt 2013-08-08 21:34 - 2013-04-05 11:38 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\CheckPoint 2013-08-08 21:06 - 2013-08-08 21:06 - 00001054 _____ C:\Users\Daniel\Desktop\mbam.txt 2013-08-08 21:01 - 2013-06-06 15:27 - 00000125 _____ C:\Users\Daniel\Desktop\netzwerk key.txt 2013-08-08 20:58 - 2013-08-08 20:58 - 00957230 _____ (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe 2013-08-08 20:57 - 2013-08-08 20:57 - 00666633 _____ C:\Users\Daniel\Desktop\adwcleaner.exe 2013-08-08 18:54 - 2013-08-08 18:54 - 00038414 _____ C:\Users\Daniel\Desktop\FRST 1.txt 2013-08-08 18:54 - 2013-08-08 18:54 - 00030316 _____ C:\Users\Daniel\Desktop\Addition.txt 2013-08-08 18:53 - 2013-08-08 18:53 - 00000000 ____D C:\FRST 2013-08-08 18:52 - 2013-08-08 18:52 - 01790059 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-08-08 16:16 - 2013-04-05 12:46 - 00180224 ___SH C:\Users\Daniel\Desktop\Thumbs.db 2013-08-08 06:35 - 2013-08-08 06:35 - 00136332 _____ C:\Users\Daniel\Desktop\OTL.Txt 2013-08-07 22:41 - 2013-05-17 14:05 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Winamp 2013-08-07 22:38 - 2013-04-05 11:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-08-07 21:22 - 2013-08-07 21:22 - 00001116 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-07 21:22 - 2013-08-07 21:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-07 21:10 - 2013-08-07 21:10 - 00000000 ____D C:\Windows\system32\MRT 2013-08-07 06:44 - 2013-04-18 10:59 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\ICQ 2013-08-06 16:48 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-05 10:53 - 2013-08-05 10:53 - 00000000 ____D C:\Users\Daniel\Desktop\kofler 2013-08-04 20:45 - 2013-08-04 20:45 - 00000000 ____D C:\Users\Daniel\AppData\Local\Skyrim 2013-08-04 20:45 - 2013-04-05 13:33 - 00000000 ____D C:\Users\Daniel\Documents\my games 2013-08-04 02:13 - 2013-04-05 16:32 - 00000000 ____D C:\Users\Daniel 2013-08-02 13:25 - 2013-08-02 12:33 - 00004543 _____ C:\Users\Daniel\AppData\Roaming\CamStudio.cfg 2013-08-02 13:25 - 2013-08-02 12:33 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamShapes.ini 2013-08-02 13:25 - 2013-08-02 12:33 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\CamLayout.ini 2013-08-02 13:25 - 2013-08-02 12:33 - 00000083 _____ C:\Users\Daniel\AppData\Roaming\Camdata.ini 2013-08-02 12:31 - 2013-08-02 12:31 - 00001051 _____ C:\Users\Public\Desktop\CamStudio.lnk 2013-08-02 12:31 - 2013-08-02 12:31 - 00000000 ____D C:\Program Files (x86)\CamStudio 2.7 2013-08-01 19:06 - 2013-04-05 13:01 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\.minecraft 2013-08-01 18:26 - 2013-04-05 11:43 - 00000000 ___RD C:\Users\Daniel\Desktop\Spiele 2013-08-01 18:10 - 2013-04-06 16:00 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Origin 2013-08-01 18:10 - 2013-04-06 16:00 - 00000000 ____D C:\Users\Daniel\AppData\Local\Origin 2013-08-01 17:26 - 2013-08-01 17:26 - 00000000 ____D C:\NvidiaLogging 2013-08-01 17:26 - 2013-04-03 16:42 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-01 17:26 - 2013-04-03 16:41 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-07-29 14:24 - 2013-06-04 12:31 - 00000078 _____ C:\Users\Daniel\Desktop\rome total war multiplayer.txt 2013-07-28 17:09 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-07-28 11:33 - 2013-04-18 11:03 - 00000000 ____D C:\Users\Daniel\Documents\ICQ 2013-07-27 18:53 - 2013-04-05 22:20 - 00000000 ____D C:\Users\Daniel\AppData\Local\Paint.NET 2013-07-26 13:58 - 2013-07-26 13:58 - 00000000 ____D C:\Users\Daniel\Documents\NBGI 2013-07-26 13:56 - 2013-07-26 13:56 - 00000000 ____D C:\Users\Daniel\AppData\Local\NBGI 2013-07-23 20:17 - 2013-04-05 16:38 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-717783921-2200971646-309864134-1002 2013-07-22 11:20 - 2013-07-22 10:44 - 00000408 _____ C:\Users\Daniel\AppData\Roaming\burnaware.ini 2013-07-22 10:44 - 2013-04-05 11:13 - 00000000 ___RD C:\Users\Daniel\Desktop\Programme 2013-07-22 10:34 - 2013-07-22 10:34 - 00000000 ____D C:\Program Files (x86)\BurnAware Free 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DVDVideoSoft 2013-07-21 18:17 - 2013-07-21 18:17 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-07-21 13:39 - 2013-07-21 13:39 - 00000000 ____D C:\Users\Daniel\Documents\EA Games 2013-07-21 13:36 - 2013-07-21 13:36 - 00000000 ____D C:\Users\Daniel\AppData\Local\EA Games 2013-07-20 23:55 - 2013-04-10 17:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\DAEMON Tools Lite 2013-07-20 18:33 - 2013-07-20 18:33 - 00281248 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-17 16:34 - 2012-07-26 12:29 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-17 16:34 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-17 03:24 - 2013-07-17 03:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-07-16 12:06 - 2013-07-16 12:06 - 00000000 ___RD C:\Users\Daniel\Documents\Notes 2013-07-16 12:06 - 2013-06-04 17:21 - 00000000 ____D C:\Program Files (x86)\devolo 2013-07-16 11:45 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2013-07-15 21:16 - 2013-07-15 21:15 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-15 21:16 - 2013-04-05 11:19 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-07-14 13:22 - 2013-05-31 11:48 - 00000000 ____D C:\Users\Daniel\Tracing 2013-07-14 13:22 - 2013-04-05 11:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\LogMeIn Hamachi 2013-07-14 12:56 - 2013-04-25 10:34 - 00000000 ____D C:\Program Files\CCleaner ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-01 18:01 ==================== End Of Log ============================ |
10.08.2013, 09:37 | #8 |
/// the machine /// TB-Ausbilder | Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang En haufen Adware Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.08.2013, 12:08 | #9 |
| Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang ok alles erledigt. danke für die super hilfe. bei den sachen die drauf waren, könnte eine für die unerlaubten zugriffe verantwortlich gewesen sein? |
10.08.2013, 21:12 | #10 |
/// the machine /// TB-Ausbilder | Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang Joah Adware ist für alles gut
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Abuse Brief Telekom: unerwünschte Zugriffe über Internet Zugang |
abuse, anti-malware, brief, durchgeführt, erfolgreich, gestern, hallo zusammen, internet, j2me/trojansms.boxer.a, java/exploit.agent.orx, java/exploit.agent.pah, malwarebytes, sauber, stehe, telekom, unerwünschte, unternehmen, virenscan, virenscanner, wahnsinnig, zusammen |