|
Plagegeister aller Art und deren Bekämpfung: Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.AWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.08.2013, 13:15 | #1 |
Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Hallo, Mein Malwarebytes findet immer wieder den obengenannten PUP. Könnt ihr mir bei der endgültigen Entsorgung helfen? Logfiles alle im Anhang. Ich habe leider im Moment keine Zeit den Rechner neu aufzusetzen. Lieben Gruß Denis aka DasKnuffel
__________________ PC Betriebssystem: Microsoft Windows 8.1 Smartphone: Hardware: iPhone 5s | Betriebssystem: iOS 8.2 |
19.08.2013, 13:31 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A hi,
__________________Logs bitte zur Not teilen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
19.08.2013, 13:42 | #3 |
Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Mir wird immer angezeigt:
__________________Der Text, den Sie eingegeben haben, besteht aus 439241 Zeichen und ist damit zu lang. Bitte kürzen Sie den Text auf die maximale Länge von 120000 Zeichen. Logs bitte als Archiv an den Beitrag anhängen! Das habe ich doch gemacht? :-/ MBAM von heute: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.19.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 DasKnuffel112 :: DENIS-PC [Administrator] 19.08.2013 13:19:44 mbam-log-2013-08-19 (13-19-44).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P Deaktivierte Suchlaufeinstellungen: Durchsuchte Objekte: 125706 Laufzeit: 38 Minute(n), 14 Sekunde(n) [Abgebrochen] Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\DasKnuffel112\AppData\Roaming\OpenCandy\B0FDA1491B0346EB958472A7C1963557\LatestDLMgr.exe (PUP.Optional.OpenCandy.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.07.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 DasKnuffel112 :: DENIS-PC [Administrator] 07.08.2013 12:42:36 mbam-log-2013-08-07 (12-42-36).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P Deaktivierte Suchlaufeinstellungen: Durchsuchte Objekte: 341271 Laufzeit: 31 Minute(n), 17 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\DasKnuffel112\AppData\Roaming\OpenCandy\B0FDA1491B0346EB958472A7C1963557\mconduitinstaller.exe (PUP.Optional.Conduit.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-08-2013 Ran by DasKnuffel112 (administrator) on 19-08-2013 14:00:52 Running from C:\Users\DasKnuffel112\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Dropbox, Inc.) C:\Users\DasKnuffel112\AppData\Roaming\Dropbox\bin\Dropbox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Users\DasKnuffel112\Documents\Flashutensilien\Google\Nexus 4\N-Cry Toolkit\adb.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-26] (Samsung) HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung) HKCU\...\Run: [GoogleChromeAutoLaunch_05614CF0FEE40B5484FA4B15DD2EA14D] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [846288 2013-07-25] (Google Inc.) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\DasKnuffel112\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6500 E710a-f.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6500 E710a-f.lnk -> C:\Program Files\HP\HP Officejet 6500 E710a-f\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Flagfox - {BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} - C:\Users\DasKnuffel112\AppData\LocalLow\Flagfox\IE\Flagfox.dll (Dave G) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) ==================== Drivers (Whitelisted) ==================== R3 AF9035BDA; C:\Windows\System32\Drivers\AF9035BDA.sys [395520 2013-07-03] (AfaTech ) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-07] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-07] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-07] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-07-03] (DT Soft Ltd) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-08-19] (Acronis) S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-19 13:51 - 2013-08-19 13:51 - 00377856 _____ C:\Users\DasKnuffel112\Desktop\gmer_2.1.19163.exe 2013-08-19 13:50 - 2013-08-19 13:51 - 01575812 _____ (Farbar) C:\Users\DasKnuffel112\Desktop\FRST64.exe 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Acronis 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\ProgramData\Acronis 2013-08-19 13:41 - 2013-08-19 13:41 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-08-19 13:22 - 2013-08-19 13:33 - 156004120 _____ C:\Users\DasKnuffel112\Downloads\tih_s_g_14192.exe 2013-08-19 00:03 - 2013-08-19 00:03 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\TeamViewer 2013-08-18 23:59 - 2013-08-18 23:59 - 00001035 _____ C:\Users\DasKnuffel112\Desktop\Julia Galaxy S3.lnk 2013-08-18 23:58 - 2013-08-18 23:58 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-08-18 23:50 - 2013-08-18 23:50 - 00000000 ____D C:\Program Files (x86)\MarkAny 2013-08-18 19:07 - 2013-08-18 19:08 - 07135170 _____ C:\Users\DasKnuffel112\Downloads\hells-Core_b34-t1-AOSP_4.3_anykernel.zip 2013-08-18 17:45 - 2013-08-18 17:45 - 00000913 _____ C:\Users\DasKnuffel112\Desktop\Denis Google Nexus 4.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00001806 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iTunes 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iPod 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-16 15:51 - 2013-08-16 15:51 - 08589228 _____ C:\Users\DasKnuffel112\Downloads\philz_touch_5.08.5-mako.zip 2013-08-16 15:41 - 2013-08-16 15:41 - 00731597 _____ C:\Users\DasKnuffel112\Downloads\Fastboot.rar 2013-08-15 22:49 - 2013-08-18 10:44 - 00000280 _____ C:\Windows\setupact.log 2013-08-15 22:49 - 2013-08-15 22:49 - 00000000 _____ C:\Windows\setuperr.log 2013-08-14 12:11 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 12:11 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 12:11 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 12:11 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 12:11 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 12:11 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 12:11 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 12:11 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 12:11 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 12:11 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 12:11 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 12:11 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 08:35 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 08:35 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 08:35 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 08:35 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 08:35 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 08:35 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 08:35 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 08:35 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 08:35 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 08:35 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 08:35 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 08:35 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 08:31 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 08:31 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 08:31 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 08:31 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 08:20 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 08:20 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-12 23:02 - 2013-08-12 23:02 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-08-10 23:21 - 2013-08-14 12:02 - 00000000 ____D C:\Windows\system32\MRT 2013-08-10 17:37 - 2013-08-18 23:48 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Samsung 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DasKnuffel112\Documents\samsung 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Samsung 2013-08-10 17:37 - 2013-06-21 02:07 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2013-08-10 17:37 - 2013-06-21 02:07 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller.dll 2013-08-10 17:37 - 2013-06-21 02:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2013-08-10 17:37 - 2013-06-21 02:07 - 00103448 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2013-08-10 17:36 - 2013-08-10 17:36 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2013-08-10 17:36 - 2013-06-14 19:57 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2013-08-10 17:36 - 2013-06-14 19:56 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2013-08-10 17:35 - 2013-08-18 23:57 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-08-10 17:34 - 2013-08-18 23:56 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Downloaded Installations 2013-08-07 12:16 - 2013-08-07 12:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-07 12:16 - 2013-08-07 12:16 - 00001945 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-08-07 12:16 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-07 12:15 - 2013-08-07 12:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-07 12:15 - 2013-08-07 12:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-07 12:15 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-07 12:15 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-01 13:16 - 2013-08-01 13:16 - 00001071 _____ C:\Users\DasKnuffel112\Desktop\Dropbox.lnk 2013-08-01 13:13 - 2013-08-01 13:13 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-01 13:12 - 2013-08-19 13:24 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Dropbox 2013-07-25 09:45 - 2013-07-25 09:45 - 00007835 _____ C:\Users\DasKnuffel112\Desktop\NCry Toolkit.lnk 2013-07-24 19:47 - 2013-07-24 19:47 - 00000000 ____D C:\Users\DasKnuffel112\Documents\N-Cry-Backups ==================== One Month Modified Files and Folders ======= 2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\FRST 2013-08-19 13:51 - 2013-08-19 13:51 - 00377856 _____ C:\Users\DasKnuffel112\Desktop\gmer_2.1.19163.exe 2013-08-19 13:51 - 2013-08-19 13:50 - 01575812 _____ (Farbar) C:\Users\DasKnuffel112\Desktop\FRST64.exe 2013-08-19 13:44 - 2013-07-03 14:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Acronis 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\ProgramData\Acronis 2013-08-19 13:42 - 2013-07-03 20:51 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Programme 2013-08-19 13:41 - 2013-08-19 13:41 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-08-19 13:33 - 2013-08-19 13:22 - 156004120 _____ C:\Users\DasKnuffel112\Downloads\tih_s_g_14192.exe 2013-08-19 13:25 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-19 13:25 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-19 13:24 - 2013-08-01 13:12 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Dropbox 2013-08-19 13:02 - 2013-07-03 22:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-19 11:00 - 2013-07-03 13:52 - 01294434 _____ C:\Windows\WindowsUpdate.log 2013-08-19 00:03 - 2013-08-19 00:03 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\TeamViewer 2013-08-18 23:59 - 2013-08-18 23:59 - 00001035 _____ C:\Users\DasKnuffel112\Desktop\Julia Galaxy S3.lnk 2013-08-18 23:58 - 2013-08-18 23:58 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-08-18 23:57 - 2013-08-10 17:35 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-08-18 23:57 - 2013-07-03 14:06 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-08-18 23:56 - 2013-08-10 17:34 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Downloaded Installations 2013-08-18 23:50 - 2013-08-18 23:50 - 00000000 ____D C:\Program Files (x86)\MarkAny 2013-08-18 23:48 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Samsung 2013-08-18 20:44 - 2013-07-03 14:33 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-18 19:08 - 2013-08-18 19:07 - 07135170 _____ C:\Users\DasKnuffel112\Downloads\hells-Core_b34-t1-AOSP_4.3_anykernel.zip 2013-08-18 18:57 - 2013-07-03 22:05 - 00000000 ____D C:\Google_Nexus_4_ToolKit 2013-08-18 17:45 - 2013-08-18 17:45 - 00000913 _____ C:\Users\DasKnuffel112\Desktop\Denis Google Nexus 4.lnk 2013-08-18 10:46 - 2013-07-03 15:11 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-18 10:44 - 2013-08-15 22:49 - 00000280 _____ C:\Windows\setupact.log 2013-08-18 10:44 - 2013-07-03 14:06 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-18 10:44 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-17 14:25 - 2013-08-17 14:25 - 00001806 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iTunes 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iPod 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-16 15:51 - 2013-08-16 15:51 - 08589228 _____ C:\Users\DasKnuffel112\Downloads\philz_touch_5.08.5-mako.zip 2013-08-16 15:41 - 2013-08-16 15:41 - 00731597 _____ C:\Users\DasKnuffel112\Downloads\Fastboot.rar 2013-08-15 22:49 - 2013-08-15 22:49 - 00000000 _____ C:\Windows\setuperr.log 2013-08-14 23:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-14 14:47 - 2013-07-03 14:48 - 00000000 ____D C:\Windows\Panther 2013-08-14 14:45 - 2013-07-03 22:01 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-14 14:45 - 2013-07-03 22:01 - 00000000 ____D C:\Program Files\CCleaner 2013-08-14 12:10 - 2013-07-03 14:56 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-14 12:03 - 2010-11-21 08:50 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-14 12:03 - 2010-11-21 08:50 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-14 12:03 - 2009-07-14 07:13 - 01518986 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-14 12:02 - 2013-08-10 23:21 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 12:00 - 2013-07-03 17:10 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-13 16:25 - 2013-07-03 14:31 - 00084984 _____ C:\Users\DASKNU~1\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-13 09:20 - 2009-07-14 06:45 - 00340760 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-12 23:02 - 2013-08-12 23:02 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-08-11 18:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DasKnuffel112\Documents\samsung 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Samsung 2013-08-10 17:36 - 2013-08-10 17:36 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2013-08-10 17:35 - 2013-07-03 22:44 - 00000000 ____D C:\ProgramData\Samsung 2013-08-08 20:46 - 2013-07-03 21:50 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\HpUpdate 2013-08-07 12:16 - 2013-08-07 12:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-07 12:16 - 2013-08-07 12:16 - 00001945 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-08-07 12:16 - 2013-08-07 12:15 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-07 12:16 - 2013-08-07 12:15 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-07 12:15 - 2013-07-03 15:11 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-07 12:15 - 2013-07-03 15:10 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-07 12:15 - 2013-07-03 15:10 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-07 12:06 - 2013-07-18 10:35 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-01 13:16 - 2013-08-01 13:16 - 00001071 _____ C:\Users\DasKnuffel112\Desktop\Dropbox.lnk 2013-08-01 13:13 - 2013-08-01 13:13 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-01 13:13 - 2013-07-03 14:01 - 00000000 ___RD C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-01 13:12 - 2013-07-03 14:00 - 00000000 ____D C:\Users\DasKnuffel112 2013-08-01 13:11 - 2013-07-03 14:33 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Google 2013-08-01 13:11 - 2013-07-03 14:33 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-31 23:55 - 2013-07-03 14:41 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-26 13:44 - 2013-07-03 14:45 - 00000000 ____D C:\Users\DasKnuffel112\Documents\Blue Eagles 2013-07-26 07:13 - 2013-08-14 12:11 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 12:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 12:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 12:11 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 12:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 12:11 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 12:11 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 12:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 12:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 12:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 12:11 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 12:11 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 08:31 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 08:31 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-25 09:45 - 2013-07-25 09:45 - 00007835 _____ C:\Users\DasKnuffel112\Desktop\NCry Toolkit.lnk 2013-07-24 19:47 - 2013-07-24 19:47 - 00000000 ____D C:\Users\DasKnuffel112\Documents\N-Cry-Backups ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 00:24 ==================== End Of Log ============================ Additional.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-08-2013 Ran by DasKnuffel112 at 2013-08-19 14:01:19 Running from C:\Users\DasKnuffel112\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acronis True Image WD*Edition (x32 Version: 13.0.14189) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) ArcSoft TotalMedia 3.5 (x32 Version: 3.5.28.291) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.10.0.0) ATI Catalyst Install Manager (Version: 3.0.762.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) Bonjour (Version: 3.0.0.10) DAEMON Tools Lite (x32 Version: 4.47.1.0333) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dropbox (HKCU Version: 2.0.26) eaner (Version: 4.04) Euro Truck Simulator 2 (x32 Version: 1.1.1) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.153) Hama Wireless LAN Adapter (x32 Version: 10.6.0) HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (Version: 28.0.1315.0) HP Officejet 6500 E710a-f Hilfe (x32 Version: 140.0.2.2) HP Photo Creations (x32 Version: 1.0.0.9572) HP Update (x32 Version: 5.003.003.001) HPDiagnosticAlert (x32 Version: 1.00.0000) I.R.I.S. OCR (x32 Version: 12.3.4.0) ImgBurn (x32 Version: 2.5.8.0) iTunes (Version: 11.0.5.5) Landwirtschafts Simulator 2011 (x32 Version: 1.0) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0) MyFreeCodec (HKCU) NVIDIA 3D Vision Controller Driver (x32 Version: 280.19) NVIDIA 3D Vision Controller-Treiber 280.19 (Version: 280.19) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0) NVIDIA Install Application (Version: 2.1002.109.718) NVIDIA PhysX (x32 Version: 9.10.0514) NVIDIA PhysX-Systemsoftware 9.10.0514 (Version: 9.10.0514) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Realtek Ethernet Controller Driver (x32 Version: 7.41.216.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6251) Revo Uninstaller 1.95 (x32 Version: 1.95) Samsung Kies (x32 Version: 2.6.0.13064_2) Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32) Studie zur Verbesserung von HP Officejet 6500 E710a-f Produkten (Version: 28.0.1315.0) TeamViewer 8 (x32 Version: 8.0.20202) Universal Adb Driver (x32 Version: 1.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553092) (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 14-08-2013 09:59:42 Windows Update 18-08-2013 21:57:06 Installiert Samsung Story Album Viewer 19-08-2013 11:38:58 Acronis True Image wird installiert ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {054203BA-99AC-4F18-8A89-14B2A11829E1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0C15FA90-D11C-4ADC-BCE5-E58BDE56B838} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-03] (Google Inc.) Task: {6F9604AC-E8CE-48E8-B255-E85D95737EC5} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710a-f => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {95C19BB9-3F64-408D-9878-35BA49AC54F1} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {98EE4A92-2BA6-420A-8DB4-59FD5808EC5E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {A6E19DD1-0CA1-40F3-83E7-7B9617EBF4AD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-03] (Google Inc.) Task: {B67DA9AB-DC63-434B-8B5E-4B28AFE487DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {DABB7DEE-4659-40F0-BFEA-9B7F6B4AE75B} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {E1732095-BB68-4FFE-906D-143882DFB032} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {F89108FD-DC6C-44D6-AFEE-FA870D887D3C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/19/2013 11:59:06 AM) (Source: .NET Runtime Optimization Service) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x800700d8 Error: (08/19/2013 11:59:06 AM) (Source: .NET Runtime Optimization Service) (User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x800700d8 Error: (08/19/2013 10:49:27 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 38680885 Error: (08/19/2013 10:49:27 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 38680885 Error: (08/19/2013 10:49:27 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/19/2013 00:05:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14399 Error: (08/19/2013 00:05:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14399 Error: (08/19/2013 00:05:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/19/2013 00:05:00 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13354 Error: (08/19/2013 00:05:00 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13354 System errors: ============= Error: (08/19/2013 10:49:27 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (08/18/2013 10:47:44 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/18/2013 10:47:44 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/18/2013 10:45:08 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "TeamViewer 8" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (08/18/2013 10:45:08 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst TeamViewer 8 erreicht. Error: (08/17/2013 02:30:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/17/2013 02:30:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/17/2013 02:26:38 PM) (Source: DCOM) (User: ) Description: {16D99191-6280-4B33-A2F5-04805A0FC582} Error: (08/17/2013 02:08:43 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/17/2013 02:08:43 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Microsoft Office Sessions: ========================= Error: (08/19/2013 11:59:06 AM) (Source: .NET Runtime Optimization Service)(User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x800700d8 C:\Program Files (x86)\Samsung\Kies\Kies.exe Error: (08/19/2013 11:59:06 AM) (Source: .NET Runtime Optimization Service)(User: ) Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x800700d8 C:\Program Files (x86)\Samsung\Kies\Kies.exe Error: (08/19/2013 10:49:27 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 38680885 Error: (08/19/2013 10:49:27 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 38680885 Error: (08/19/2013 10:49:27 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/19/2013 00:05:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14399 Error: (08/19/2013 00:05:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14399 Error: (08/19/2013 00:05:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/19/2013 00:05:00 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13354 Error: (08/19/2013 00:05:00 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13354 ==================== Memory info =========================== Percentage of memory in use: 37% Total physical RAM: 6143.11 MB Available physical RAM: 3834.17 MB Total Pagefile: 12284.41 MB Available Pagefile: 9251.59 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Windows 7 und Programme) (Fixed) (Total:297.99 GB) (Free:236.64 GB) NTFS Drive d: (Daten) (Fixed) (Total:596.17 GB) (Free:523.31 GB) NTFS Drive f: (Externe Julia) (Fixed) (Total:931.51 GB) (Free:906.37 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 000CB3C8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 596 GB) (Disk ID: E4AD24DE) Partition 1: (Not Active) - (Size=596 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: E7725E5F) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Lieben Gruß Denis
__________________ |
20.08.2013, 10:01 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.08.2013, 10:43 | #5 |
Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Hallo schrauber, AswCleaner[S1].txt: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 20/08/2013 um 11:21:32 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzer : DasKnuffel112 - DENIS-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\DasKnuffel112\Desktop\Trojaner-Board\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\Users\DasKnuffel112\AppData\LocalLow\Conduit ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16660 [OK] Die Registrierungsdatenbank ist sauber. ************************* AdwCleaner[S1].txt - [1627 octets] - [20/08/2013 11:21:32] ########## EOF - C:\AdwCleaner[S1].txt - [1687 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.1 (08.19.2013:1) OS: Windows 7 Ultimate x64 Ran by DasKnuffel112 on 20.08.2013 at 11:35:17,55 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\DasKnuffel112\appdata\local\cre" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.08.2013 at 11:39:50,24 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-08-2013 Ran by DasKnuffel112 (administrator) on 20-08-2013 11:42:15 Running from C:\Users\DasKnuffel112\Desktop\Trojaner-Board Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Dropbox, Inc.) C:\Users\DasKnuffel112\AppData\Roaming\Dropbox\bin\Dropbox.exe (Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-26] (Samsung) HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung) HKCU\...\Run: [GoogleChromeAutoLaunch_05614CF0FEE40B5484FA4B15DD2EA14D] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [846288 2013-07-25] (Google Inc.) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\DasKnuffel112\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6500 E710a-f.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6500 E710a-f.lnk -> C:\Program Files\HP\HP Officejet 6500 E710a-f\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Flagfox - {BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} - C:\Users\DasKnuffel112\AppData\LocalLow\Flagfox\IE\Flagfox.dll (Dave G) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) ==================== Drivers (Whitelisted) ==================== R3 AF9035BDA; C:\Windows\System32\Drivers\AF9035BDA.sys [395520 2013-07-03] (AfaTech ) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-07] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-07] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-07] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-07-03] (DT Soft Ltd) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-08-19] (Acronis) S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-19 14:32 - 2013-08-19 14:32 - 00007226 _____ C:\Users\DasKnuffel112\Desktop\NCry.exe.lnk 2013-08-19 14:26 - 2013-08-19 16:21 - 00001764 _____ C:\Windows\PFRO.log 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\samsung 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\N-Cry-Backups 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\My Games 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Flashutensilien 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Euro Truck Simulator 2 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Blue Eagles 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Bewerbungsmappe 2013-08-19 14:17 - 2012-09-23 15:03 - 00109546 _____ D:\DasKnuffel112\Documents\Senderliste.chl 2013-08-19 14:15 - 2013-08-20 11:42 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Trojaner-Board 2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\FRST 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Acronis 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\ProgramData\Acronis 2013-08-19 13:41 - 2013-08-19 13:41 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-08-19 00:03 - 2013-08-19 00:03 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\TeamViewer 2013-08-18 23:59 - 2013-08-18 23:59 - 00001035 _____ C:\Users\DasKnuffel112\Desktop\Julia Galaxy S3.lnk 2013-08-18 23:58 - 2013-08-18 23:58 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-08-18 23:50 - 2013-08-18 23:50 - 00000000 ____D C:\Program Files (x86)\MarkAny 2013-08-18 17:45 - 2013-08-18 17:45 - 00000913 _____ C:\Users\DasKnuffel112\Desktop\Denis Google Nexus 4.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00001806 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iTunes 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iPod 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-15 22:49 - 2013-08-20 11:30 - 00000448 _____ C:\Windows\setupact.log 2013-08-15 22:49 - 2013-08-15 22:49 - 00000000 _____ C:\Windows\setuperr.log 2013-08-14 12:11 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 12:11 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 12:11 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 12:11 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 12:11 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 12:11 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 12:11 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 12:11 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 12:11 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 12:11 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 12:11 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 12:11 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 08:35 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 08:35 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 08:35 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 08:35 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 08:35 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 08:35 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 08:35 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 08:35 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 08:35 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 08:35 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 08:35 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 08:35 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 08:31 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 08:31 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 08:31 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 08:31 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 08:20 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 08:20 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-12 23:02 - 2013-08-12 23:02 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-08-10 23:21 - 2013-08-14 12:02 - 00000000 ____D C:\Windows\system32\MRT 2013-08-10 17:37 - 2013-08-18 23:48 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Samsung 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Samsung 2013-08-10 17:37 - 2013-06-21 02:07 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2013-08-10 17:37 - 2013-06-21 02:07 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller.dll 2013-08-10 17:37 - 2013-06-21 02:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2013-08-10 17:37 - 2013-06-21 02:07 - 00103448 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2013-08-10 17:36 - 2013-08-10 17:36 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2013-08-10 17:36 - 2013-06-14 19:57 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2013-08-10 17:36 - 2013-06-14 19:56 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2013-08-10 17:35 - 2013-08-18 23:57 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-08-10 17:34 - 2013-08-18 23:56 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Downloaded Installations 2013-08-07 12:16 - 2013-08-07 12:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-07 12:16 - 2013-08-07 12:16 - 00001945 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-08-07 12:16 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-07 12:15 - 2013-08-07 12:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-07 12:15 - 2013-08-07 12:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-07 12:15 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-07 12:15 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-01 13:16 - 2013-08-01 13:16 - 00001071 _____ C:\Users\DasKnuffel112\Desktop\Dropbox.lnk 2013-08-01 13:13 - 2013-08-01 13:13 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-01 13:12 - 2013-08-20 11:32 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Dropbox ==================== One Month Modified Files and Folders ======= 2013-08-20 11:38 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-20 11:38 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-20 11:35 - 2013-08-20 11:35 - 00000000 ____D C:\Windows\ERUNT 2013-08-20 11:32 - 2013-08-01 13:12 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Dropbox 2013-08-20 11:31 - 2013-07-03 14:33 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-20 11:30 - 2013-08-15 22:49 - 00000448 _____ C:\Windows\setupact.log 2013-08-20 11:30 - 2013-07-03 14:06 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-20 11:30 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-20 11:22 - 2013-07-03 13:52 - 01358130 _____ C:\Windows\WindowsUpdate.log 2013-08-20 11:02 - 2013-07-03 22:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-20 10:44 - 2013-07-03 14:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-19 16:22 - 2013-07-03 15:11 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-19 16:21 - 2013-08-19 14:26 - 00001764 _____ C:\Windows\PFRO.log 2013-08-19 14:32 - 2013-08-19 14:32 - 00007226 _____ C:\Users\DasKnuffel112\Desktop\NCry.exe.lnk 2013-08-19 14:31 - 2013-07-03 14:00 - 00000000 ____D C:\Users\DasKnuffel112 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\samsung 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\N-Cry-Backups 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\My Games 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Flashutensilien 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Euro Truck Simulator 2 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Blue Eagles 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Bewerbungsmappe 2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\FRST 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Acronis 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\ProgramData\Acronis 2013-08-19 13:42 - 2013-07-03 20:51 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Programme 2013-08-19 13:41 - 2013-08-19 13:41 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-08-19 00:03 - 2013-08-19 00:03 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\TeamViewer 2013-08-18 23:59 - 2013-08-18 23:59 - 00001035 _____ C:\Users\DasKnuffel112\Desktop\Julia Galaxy S3.lnk 2013-08-18 23:58 - 2013-08-18 23:58 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-08-18 23:57 - 2013-08-10 17:35 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-08-18 23:57 - 2013-07-03 14:06 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-08-18 23:56 - 2013-08-10 17:34 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Downloaded Installations 2013-08-18 23:50 - 2013-08-18 23:50 - 00000000 ____D C:\Program Files (x86)\MarkAny 2013-08-18 23:48 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Samsung 2013-08-18 18:57 - 2013-07-03 22:05 - 00000000 ____D C:\Google_Nexus_4_ToolKit 2013-08-18 17:45 - 2013-08-18 17:45 - 00000913 _____ C:\Users\DasKnuffel112\Desktop\Denis Google Nexus 4.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00001806 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iTunes 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iPod 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-15 22:49 - 2013-08-15 22:49 - 00000000 _____ C:\Windows\setuperr.log 2013-08-14 23:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-14 14:47 - 2013-07-03 14:48 - 00000000 ____D C:\Windows\Panther 2013-08-14 14:45 - 2013-07-03 22:01 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-14 14:45 - 2013-07-03 22:01 - 00000000 ____D C:\Program Files\CCleaner 2013-08-14 12:10 - 2013-07-03 14:56 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-14 12:03 - 2010-11-21 08:50 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-14 12:03 - 2010-11-21 08:50 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-14 12:03 - 2009-07-14 07:13 - 01518986 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-14 12:02 - 2013-08-10 23:21 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 12:00 - 2013-07-03 17:10 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-13 16:25 - 2013-07-03 14:31 - 00084984 _____ C:\Users\DASKNU~1\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-13 09:20 - 2009-07-14 06:45 - 00340760 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-12 23:02 - 2013-08-12 23:02 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-08-11 18:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Samsung 2013-08-10 17:36 - 2013-08-10 17:36 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2013-08-10 17:35 - 2013-07-03 22:44 - 00000000 ____D C:\ProgramData\Samsung 2013-08-08 20:46 - 2013-07-03 21:50 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\HpUpdate 2013-08-07 12:16 - 2013-08-07 12:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-07 12:16 - 2013-08-07 12:16 - 00001945 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-08-07 12:16 - 2013-08-07 12:15 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-07 12:16 - 2013-08-07 12:15 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-07 12:15 - 2013-07-03 15:11 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-07 12:15 - 2013-07-03 15:10 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-07 12:15 - 2013-07-03 15:10 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-07 12:06 - 2013-07-18 10:35 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-01 13:16 - 2013-08-01 13:16 - 00001071 _____ C:\Users\DasKnuffel112\Desktop\Dropbox.lnk 2013-08-01 13:13 - 2013-08-01 13:13 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-01 13:13 - 2013-07-03 14:01 - 00000000 ___RD C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-01 13:11 - 2013-07-03 14:33 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Google 2013-08-01 13:11 - 2013-07-03 14:33 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-31 23:55 - 2013-07-03 14:41 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-26 07:13 - 2013-08-14 12:11 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 12:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 12:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 12:11 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 12:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 12:11 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 12:11 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 12:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 12:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 12:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 12:11 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 12:11 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 08:31 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 08:31 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 00:24 ==================== End Of Log ============================ --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-08-2013 Ran by DasKnuffel112 at 2013-08-20 11:42:39 Running from C:\Users\DasKnuffel112\Desktop\Trojaner-Board Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acronis True Image WD*Edition (x32 Version: 13.0.14189) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) ArcSoft TotalMedia 3.5 (x32 Version: 3.5.28.291) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.10.0.0) ATI Catalyst Install Manager (Version: 3.0.762.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) Bonjour (Version: 3.0.0.10) DAEMON Tools Lite (x32 Version: 4.47.1.0333) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dropbox (HKCU Version: 2.0.26) eaner (Version: 4.04) Euro Truck Simulator 2 (x32 Version: 1.1.1) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.153) Hama Wireless LAN Adapter (x32 Version: 10.6.0) HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (Version: 28.0.1315.0) HP Officejet 6500 E710a-f Hilfe (x32 Version: 140.0.2.2) HP Photo Creations (x32 Version: 1.0.0.9572) HP Update (x32 Version: 5.003.003.001) HPDiagnosticAlert (x32 Version: 1.00.0000) I.R.I.S. OCR (x32 Version: 12.3.4.0) ImgBurn (x32 Version: 2.5.8.0) iTunes (Version: 11.0.5.5) Landwirtschafts Simulator 2011 (x32 Version: 1.0) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0) MyFreeCodec (HKCU) NVIDIA 3D Vision Controller Driver (x32 Version: 280.19) NVIDIA 3D Vision Controller-Treiber 280.19 (Version: 280.19) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0) NVIDIA Install Application (Version: 2.1002.109.718) NVIDIA PhysX (x32 Version: 9.10.0514) NVIDIA PhysX-Systemsoftware 9.10.0514 (Version: 9.10.0514) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Realtek Ethernet Controller Driver (x32 Version: 7.41.216.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6251) Revo Uninstaller 1.95 (x32 Version: 1.95) Samsung Kies (x32 Version: 2.6.0.13064_2) Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32) Studie zur Verbesserung von HP Officejet 6500 E710a-f Produkten (Version: 28.0.1315.0) TeamViewer 8 (x32 Version: 8.0.20202) Universal Adb Driver (x32 Version: 1.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553092) (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 14-08-2013 09:59:42 Windows Update 18-08-2013 21:57:06 Installiert Samsung Story Album Viewer 19-08-2013 11:38:58 Acronis True Image wird installiert 20-08-2013 07:14:17 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {054203BA-99AC-4F18-8A89-14B2A11829E1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0C15FA90-D11C-4ADC-BCE5-E58BDE56B838} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-03] (Google Inc.) Task: {6F9604AC-E8CE-48E8-B255-E85D95737EC5} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710a-f => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {95C19BB9-3F64-408D-9878-35BA49AC54F1} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {98EE4A92-2BA6-420A-8DB4-59FD5808EC5E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {A6E19DD1-0CA1-40F3-83E7-7B9617EBF4AD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-03] (Google Inc.) Task: {B67DA9AB-DC63-434B-8B5E-4B28AFE487DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {DABB7DEE-4659-40F0-BFEA-9B7F6B4AE75B} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {F89108FD-DC6C-44D6-AFEE-FA870D887D3C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15] (Adobe Systems Incorporated) Task: {F9376BE4-0F49-4D20-8EE5-56E40E30EE99} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 31% Total physical RAM: 6143.11 MB Available physical RAM: 4205.04 MB Total Pagefile: 12284.41 MB Available Pagefile: 10092.57 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Windows 7 und Programme) (Fixed) (Total:297.99 GB) (Free:249.19 GB) NTFS Drive d: (Daten) (Fixed) (Total:596.17 GB) (Free:508.63 GB) NTFS Drive f: (Externe Julia) (Fixed) (Total:931.51 GB) (Free:906.37 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 000CB3C8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 596 GB) (Disk ID: E4AD24DE) Partition 1: (Not Active) - (Size=596 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: E7725E5F) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================
__________________ PC Betriebssystem: Microsoft Windows 8.1 Smartphone: Hardware: iPhone 5s | Betriebssystem: iOS 8.2 |
20.08.2013, 12:55 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.AESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A |
20.08.2013, 14:58 | #7 |
Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.ACode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=506039707a774142b66234055a980ddc # engine=14839 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-20 01:48:17 # local_time=2013-08-20 03:48:17 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 91 1135924 153716369 0 0 # compatibility_mode=5893 16776573 100 94 15965 128636347 0 0 # scanned=120414 # found=0 # cleaned=0 # scan_time=4368 Code:
ATTFilter UNSUPPORTED OPERATING SYSTEM! ABORTED! FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-08-2013 Ran by DasKnuffel112 (administrator) on 20-08-2013 15:55:57 Running from C:\Users\DasKnuffel112\Desktop\Trojaner-Board Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Dropbox, Inc.) C:\Users\DasKnuffel112\AppData\Roaming\Dropbox\bin\Dropbox.exe (Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTShellHlp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () D:\DasKnuffel112\Documents\Flashutensilien\Google\Nexus 4\N-Cry Toolkit\adb.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-26] (Samsung) HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung) HKCU\...\Run: [GoogleChromeAutoLaunch_05614CF0FEE40B5484FA4B15DD2EA14D] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [846288 2013-07-25] (Google Inc.) HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.) Startup: C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\DasKnuffel112\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6500 E710a-f.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6500 E710a-f.lnk -> C:\Program Files\HP\HP Officejet 6500 E710a-f\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Flagfox - {BA7B8F39-DF7F-4A98-83E9-57CE6ED9CA24} - C:\Users\DasKnuffel112\AppData\LocalLow\Flagfox\IE\Flagfox.dll (Dave G) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 ==================== Services (Whitelisted) ================= R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) ==================== Drivers (Whitelisted) ==================== R3 AF9035BDA; C:\Windows\System32\Drivers\AF9035BDA.sys [395520 2013-07-03] (AfaTech ) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-07] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-07] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-07] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-07-03] (DT Soft Ltd) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-08-19] (Acronis) S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-20 14:29 - 2013-08-20 14:29 - 00000000 ____D C:\Program Files (x86)\ESET 2013-08-20 11:35 - 2013-08-20 11:35 - 00000000 ____D C:\Windows\ERUNT 2013-08-19 14:32 - 2013-08-19 14:32 - 00007226 _____ C:\Users\DasKnuffel112\Desktop\NCry.exe.lnk 2013-08-19 14:26 - 2013-08-19 16:21 - 00001764 _____ C:\Windows\PFRO.log 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\samsung 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\N-Cry-Backups 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\My Games 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Flashutensilien 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Euro Truck Simulator 2 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Blue Eagles 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Bewerbungsmappe 2013-08-19 14:17 - 2012-09-23 15:03 - 00109546 _____ D:\DasKnuffel112\Documents\Senderliste.chl 2013-08-19 14:15 - 2013-08-20 15:54 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Trojaner-Board 2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\FRST 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Acronis 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\ProgramData\Acronis 2013-08-19 13:41 - 2013-08-19 13:41 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-08-19 00:03 - 2013-08-19 00:03 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\TeamViewer 2013-08-18 23:59 - 2013-08-18 23:59 - 00001035 _____ C:\Users\DasKnuffel112\Desktop\Julia Galaxy S3.lnk 2013-08-18 23:58 - 2013-08-18 23:58 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-08-18 23:50 - 2013-08-18 23:50 - 00000000 ____D C:\Program Files (x86)\MarkAny 2013-08-18 17:45 - 2013-08-18 17:45 - 00000913 _____ C:\Users\DasKnuffel112\Desktop\Denis Google Nexus 4.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00001806 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iTunes 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iPod 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-15 22:49 - 2013-08-20 11:30 - 00000448 _____ C:\Windows\setupact.log 2013-08-15 22:49 - 2013-08-15 22:49 - 00000000 _____ C:\Windows\setuperr.log 2013-08-14 12:11 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 12:11 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 12:11 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 12:11 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 12:11 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 12:11 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 12:11 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 12:11 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 12:11 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 12:11 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 12:11 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 12:11 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 12:11 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 12:11 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 08:35 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 08:35 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 08:35 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 08:35 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 08:35 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 08:35 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 08:35 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 08:35 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 08:35 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 08:35 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 08:35 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 08:35 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 08:35 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 08:35 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 08:35 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 08:31 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 08:31 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 08:31 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 08:31 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 08:20 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 08:20 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-12 23:02 - 2013-08-12 23:02 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-08-10 23:21 - 2013-08-14 12:02 - 00000000 ____D C:\Windows\system32\MRT 2013-08-10 17:37 - 2013-08-18 23:48 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Samsung 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Samsung 2013-08-10 17:37 - 2013-06-21 02:07 - 01490656 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01007.dll 2013-08-10 17:37 - 2013-06-21 02:07 - 00708168 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller.dll 2013-08-10 17:37 - 2013-06-21 02:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys 2013-08-10 17:37 - 2013-06-21 02:07 - 00103448 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys 2013-08-10 17:36 - 2013-08-10 17:36 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2013-08-10 17:36 - 2013-06-14 19:57 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2013-08-10 17:36 - 2013-06-14 19:56 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2013-08-10 17:35 - 2013-08-18 23:57 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-08-10 17:34 - 2013-08-18 23:56 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Downloaded Installations 2013-08-07 12:16 - 2013-08-07 12:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-07 12:16 - 2013-08-07 12:16 - 00001945 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-08-07 12:16 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-07 12:15 - 2013-08-07 12:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-07 12:15 - 2013-08-07 12:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-07 12:15 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-07 12:15 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-07 12:15 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-01 13:16 - 2013-08-01 13:16 - 00001071 _____ C:\Users\DasKnuffel112\Desktop\Dropbox.lnk 2013-08-01 13:13 - 2013-08-01 13:13 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-01 13:12 - 2013-08-20 13:08 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Dropbox ==================== One Month Modified Files and Folders ======= 2013-08-20 15:54 - 2013-08-19 14:15 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Trojaner-Board 2013-08-20 15:44 - 2013-07-03 14:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-20 15:10 - 2013-08-20 15:01 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Interner Speicher 2013-08-20 15:02 - 2013-07-03 22:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-20 14:29 - 2013-08-20 14:29 - 00000000 ____D C:\Program Files (x86)\ESET 2013-08-20 13:08 - 2013-08-01 13:12 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Dropbox 2013-08-20 11:38 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-20 11:38 - 2009-07-14 06:45 - 00021072 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-20 11:35 - 2013-08-20 11:35 - 00000000 ____D C:\Windows\ERUNT 2013-08-20 11:34 - 2013-07-03 13:52 - 01358130 _____ C:\Windows\WindowsUpdate.log 2013-08-20 11:31 - 2013-07-03 14:33 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-20 11:30 - 2013-08-15 22:49 - 00000448 _____ C:\Windows\setupact.log 2013-08-20 11:30 - 2013-07-03 14:06 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-20 11:30 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-19 16:22 - 2013-07-03 15:11 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-19 16:21 - 2013-08-19 14:26 - 00001764 _____ C:\Windows\PFRO.log 2013-08-19 14:32 - 2013-08-19 14:32 - 00007226 _____ C:\Users\DasKnuffel112\Desktop\NCry.exe.lnk 2013-08-19 14:31 - 2013-07-03 14:00 - 00000000 ____D C:\Users\DasKnuffel112 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\samsung 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\N-Cry-Backups 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\My Games 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Flashutensilien 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Euro Truck Simulator 2 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Blue Eagles 2013-08-19 14:17 - 2013-08-19 14:17 - 00000000 ____D D:\DasKnuffel112\Documents\Bewerbungsmappe 2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\FRST 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Acronis 2013-08-19 13:42 - 2013-08-19 13:42 - 00000000 ____D C:\ProgramData\Acronis 2013-08-19 13:42 - 2013-07-03 20:51 - 00000000 ____D C:\Users\DasKnuffel112\Desktop\Programme 2013-08-19 13:41 - 2013-08-19 13:41 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00210016 _____ (Acronis) C:\Windows\system32\Drivers\vididr.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-08-19 13:40 - 2013-08-19 13:40 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-08-19 00:03 - 2013-08-19 00:03 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\TeamViewer 2013-08-18 23:59 - 2013-08-18 23:59 - 00001035 _____ C:\Users\DasKnuffel112\Desktop\Julia Galaxy S3.lnk 2013-08-18 23:58 - 2013-08-18 23:58 - 00000000 ____D C:\Users\Public\Documents\CrashDump 2013-08-18 23:57 - 2013-08-10 17:35 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-08-18 23:57 - 2013-07-03 14:06 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-08-18 23:56 - 2013-08-10 17:34 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Downloaded Installations 2013-08-18 23:50 - 2013-08-18 23:50 - 00000000 ____D C:\Program Files (x86)\MarkAny 2013-08-18 23:48 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Samsung 2013-08-18 18:57 - 2013-07-03 22:05 - 00000000 ____D C:\Google_Nexus_4_ToolKit 2013-08-18 17:45 - 2013-08-18 17:45 - 00000913 _____ C:\Users\DasKnuffel112\Desktop\Denis Google Nexus 4.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00001806 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iTunes 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files\iPod 2013-08-17 14:25 - 2013-08-17 14:25 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-08-15 22:49 - 2013-08-15 22:49 - 00000000 _____ C:\Windows\setuperr.log 2013-08-14 23:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-14 14:47 - 2013-07-03 14:48 - 00000000 ____D C:\Windows\Panther 2013-08-14 14:45 - 2013-07-03 22:01 - 00000845 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-14 14:45 - 2013-07-03 22:01 - 00000000 ____D C:\Program Files\CCleaner 2013-08-14 12:10 - 2013-07-03 14:56 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-14 12:03 - 2010-11-21 08:50 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-14 12:03 - 2010-11-21 08:50 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-14 12:03 - 2009-07-14 07:13 - 01518986 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-14 12:02 - 2013-08-10 23:21 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 12:00 - 2013-07-03 17:10 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-13 16:25 - 2013-07-03 14:31 - 00084984 _____ C:\Users\DASKNU~1\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-13 09:20 - 2009-07-14 06:45 - 00340760 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-12 23:02 - 2013-08-12 23:02 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2013-08-11 18:04 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01007.Wdf 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log 2013-08-10 17:37 - 2013-08-10 17:37 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Samsung 2013-08-10 17:36 - 2013-08-10 17:36 - 00000000 ____D C:\Program Files (x86)\MyFree Codec 2013-08-10 17:35 - 2013-07-03 22:44 - 00000000 ____D C:\ProgramData\Samsung 2013-08-08 20:46 - 2013-07-03 21:50 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\HpUpdate 2013-08-07 12:16 - 2013-08-07 12:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-07 12:16 - 2013-08-07 12:16 - 00001945 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-08-07 12:16 - 2013-08-07 12:15 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-07 12:16 - 2013-08-07 12:15 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-07 12:16 - 2013-07-03 15:12 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-07 12:15 - 2013-07-03 15:11 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-07 12:15 - 2013-07-03 15:10 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-07 12:15 - 2013-07-03 15:10 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-07 12:06 - 2013-07-18 10:35 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-08-01 13:16 - 2013-08-01 13:16 - 00001071 _____ C:\Users\DasKnuffel112\Desktop\Dropbox.lnk 2013-08-01 13:13 - 2013-08-01 13:13 - 00000000 ____D C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-01 13:13 - 2013-07-03 14:01 - 00000000 ___RD C:\Users\DasKnuffel112\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-01 13:11 - 2013-07-03 14:33 - 00000000 ____D C:\Users\DASKNU~1\AppData\Local\Google 2013-08-01 13:11 - 2013-07-03 14:33 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-31 23:55 - 2013-07-03 14:41 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-26 07:13 - 2013-08-14 12:11 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 12:11 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 12:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 12:11 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 12:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 12:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 12:11 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 12:11 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 12:11 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 12:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 12:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 12:11 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 12:11 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 12:11 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 08:31 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 08:31 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-12 00:24 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-08-2013 Ran by DasKnuffel112 at 2013-08-20 15:56:21 Running from C:\Users\DasKnuffel112\Desktop\Trojaner-Board Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acronis True Image WD*Edition (x32 Version: 13.0.14189) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (x32 Version: 2.1.3.127) ArcSoft TotalMedia 3.5 (x32 Version: 3.5.28.291) Asmedia ASM104x USB 3.0 Host Controller Driver (x32 Version: 1.10.0.0) ATI Catalyst Install Manager (Version: 3.0.762.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) Bonjour (Version: 3.0.0.10) DAEMON Tools Lite (x32 Version: 4.47.1.0333) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dropbox (HKCU Version: 2.0.26) eaner (Version: 4.04) ESET Online Scanner v3 (x32) Euro Truck Simulator 2 (x32 Version: 1.1.1) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.153) Hama Wireless LAN Adapter (x32 Version: 10.6.0) HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (Version: 28.0.1315.0) HP Officejet 6500 E710a-f Hilfe (x32 Version: 140.0.2.2) HP Photo Creations (x32 Version: 1.0.0.9572) HP Update (x32 Version: 5.003.003.001) HPDiagnosticAlert (x32 Version: 1.00.0000) I.R.I.S. OCR (x32 Version: 12.3.4.0) ImgBurn (x32 Version: 2.5.8.0) iTunes (Version: 11.0.5.5) Landwirtschafts Simulator 2011 (x32 Version: 1.0) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0) MyFreeCodec (HKCU) NVIDIA 3D Vision Controller Driver (x32 Version: 280.19) NVIDIA 3D Vision Controller-Treiber 280.19 (Version: 280.19) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0) NVIDIA Install Application (Version: 2.1002.109.718) NVIDIA PhysX (x32 Version: 9.10.0514) NVIDIA PhysX-Systemsoftware 9.10.0514 (Version: 9.10.0514) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Realtek Ethernet Controller Driver (x32 Version: 7.41.216.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6251) Revo Uninstaller 1.95 (x32 Version: 1.95) Samsung Kies (x32 Version: 2.6.0.13064_2) Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32) Studie zur Verbesserung von HP Officejet 6500 E710a-f Produkten (Version: 28.0.1315.0) TeamViewer 8 (x32 Version: 8.0.20202) Universal Adb Driver (x32 Version: 1.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553092) (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 14-08-2013 09:59:42 Windows Update 18-08-2013 21:57:06 Installiert Samsung Story Album Viewer 19-08-2013 11:38:58 Acronis True Image wird installiert 20-08-2013 07:14:17 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {054203BA-99AC-4F18-8A89-14B2A11829E1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0C15FA90-D11C-4ADC-BCE5-E58BDE56B838} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-03] (Google Inc.) Task: {6F9604AC-E8CE-48E8-B255-E85D95737EC5} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710a-f => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {95C19BB9-3F64-408D-9878-35BA49AC54F1} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {98EE4A92-2BA6-420A-8DB4-59FD5808EC5E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {A6E19DD1-0CA1-40F3-83E7-7B9617EBF4AD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-03] (Google Inc.) Task: {B67DA9AB-DC63-434B-8B5E-4B28AFE487DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {DABB7DEE-4659-40F0-BFEA-9B7F6B4AE75B} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {F89108FD-DC6C-44D6-AFEE-FA870D887D3C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15] (Adobe Systems Incorporated) Task: {F9376BE4-0F49-4D20-8EE5-56E40E30EE99} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/20/2013 03:54:18 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/20/2013 03:53:19 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (08/20/2013 11:47:06 AM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= Error: (08/20/2013 03:54:18 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestD:\DasKnuffel112\Downloads\esetsmartinstaller_enu.exe Error: (08/20/2013 03:53:19 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 6143.11 MB Available physical RAM: 3715.07 MB Total Pagefile: 12284.41 MB Available Pagefile: 9614.38 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Windows 7 und Programme) (Fixed) (Total:297.99 GB) (Free:247.22 GB) NTFS Drive d: (Daten) (Fixed) (Total:596.17 GB) (Free:508.63 GB) NTFS Drive f: (Externe Julia) (Fixed) (Total:931.51 GB) (Free:906.37 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 000CB3C8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 596 GB) (Disk ID: E4AD24DE) Partition 1: (Not Active) - (Size=596 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: E7725E5F) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Bemerke im Moment keine Probleme! Edit: Nach einem Neustart lief Securitycheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.72 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Reader XI Google Chrome 28.0.1500.72 Google Chrome 28.0.1500.95 ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
__________________ PC Betriebssystem: Microsoft Windows 8.1 Smartphone: Hardware: iPhone 5s | Betriebssystem: iOS 8.2 Geändert von DasKnuffel (20.08.2013 um 15:09 Uhr) |
20.08.2013, 15:11 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.08.2013, 19:22 | #9 |
Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Super, ich danke dir. Hat alles geklappt. Spende an euch ist unterwegs Hab noch einen abschließenden Scan mit Malwarebytes gemacht Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.20.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 DasKnuffel112 :: DENIS-PC [Administrator] 20.08.2013 18:30:07 mbam-log-2013-08-20 (18-30-07).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P Deaktivierte Suchlaufeinstellungen: Durchsuchte Objekte: 348434 Laufzeit: 32 Minute(n), 48 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Denis
__________________ PC Betriebssystem: Microsoft Windows 8.1 Smartphone: Hardware: iPhone 5s | Betriebssystem: iOS 8.2 |
21.08.2013, 09:19 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: Malwarebytes findet immer wieder PUP.Optional.Conduit.A |
endgültigen, entsorgung, immer wieder, malwarebytes, neu, pup.optional.conduit.a, rechner, windows, windows 7 |