Plagegeister aller Art und deren Bekämpfung: Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Hallo zusammen! Ich habe leider ein recht mühseliges, zumindest für mich, Problem. Ich bekam am Samstag eine automatisiere Mail von T-Online, dass mein Account Massen-E-Mails versendet und daher gesperrt wurde. In der Mail wurde darauf hingewiesen, dass ich den Account wieder freischalten kann, davor aber meinen Rechner gründlich auf Viren, Trojaner, etc. untersuchen müsste und dann sämtliche Passwörter (am Besten auf einem anderen, völlig virenfreien Rechner) ändern müsste. Ich habe die Mails, deren Zustellungsfehlermeldungen ich erhielt (ca. 3.500!) bis auf die erste und letzte Mail gelöscht und mich dann auf die Suche nach Trojanern oder Viren gemacht. Sollte noch erwähnen, dass bei mir GData-Antivirus im Hintergrund läuft und weder Viren noch sonstige Schädlinge bis jetzt gemeldet hat. Virensignaturen und Progamm wird bei dem ersten Hinweis immer gleich aktualisiert, bzw. Virensignaturen werden automatisch alle Stunde geladen.
Wäre fantastisch, wenn ihr mir weiterhelfen könntet, sollte noch etwas fehlen, dann liefere ich die Angaben gerne nach, sollte aber, soweit ich das jetzt sehe, erst mal die Grundanforderungen erfüllen, oder? ![]() ![]() Geändert von asparagus (20.08.2013 um 11:59 Uhr) Grund: Rechtschreibfehler, nix dramatisches... :-) |
Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Hallo Schrauber,
__________________vielen Dank, dass du dich meines Problems annimmst! Habe jetzt mal, wie von dir beschrieben, FRST 64-Bit geladen und laufen lassen. Beim ersten Lauf kam direkt eine Fehlermeldung seitens GData, dass die Datei NTUSER.DAT aus dem Verzeichnis C:\FRST\Hives\Users\00000001 in Quarantäne verschoben wurde, "Auf Grund bösartigen Verhaltens in Quarantäne verschoben." ![]() Habe dann weiter nichts unternommen und die Datei in Quarantäne gelassen. Danach habe ich dann erneut FRST gestartet und das lief dann komplett durch, ohne Fehlermeldung seitens GDATA Antivirus! Hier die Logs: FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-08-2013 03 Ran by RA (administrator) on 20-08-2013 13:40:29 Running from C:\Users\RA\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech Inc.) C:\Program Files\Logitech\SetPoint\LBTWiz.exe (Celartem, Inc., doing business as Extensis.) C:\Program Files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe () C:\Program Files (x86)\i-Funbox DevTeam\ifb_conn.exe () C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe (Spotify Ltd) C:\Users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Abbott Diabetes Care) C:\Program Files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dropbox, Inc.) C:\Users\RA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\Evernote.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [134160 2007-09-21] (Logitech, Inc.) HKLM\...\Run: [Bluetooth Connection Assistant] - LBTWIZ.EXE -silent [x] HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [FMCore.exe] - C:\Program Files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe [9211392 2011-10-27] (Celartem, Inc., doing business as Extensis.) HKCU\...\Run: [DisplayFusion] - C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software) HKCU\...\Run: [iFunBoxConnector] - C:\Program Files (x86)\i-Funbox DevTeam\ifb_conn.exe [812544 2013-04-23] () HKCU\...\Run: [AirVideoServer] - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe [4935112 2012-07-20] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-06-26] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6581488 2013-08-15] (SUPERAntiSpyware) MountPoints2: {b58c781e-2fe8-11e2-a3b7-0007ca045fc4} - P:\Windows\StartInstall.exe HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [G Data ASM] - C:\Program Files (x86)\G Data\AntiVirus\DelayLoader\AutorunDelayLoader.exe [472016 2013-02-25] (G Data Software AG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-08-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478752 2012-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [G Data AntiVirus Tray] - C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe [1444304 2013-02-25] (G Data Software AG) HKLM-x32\...\Run: [TrojanScanner] - C:\Program Files (x86)\Trojan Remover\Trjscan.exe [1655568 2013-07-19] (Simply Super Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FreeStyle Auto-Assist.lnk ShortcutTarget: FreeStyle Auto-Assist.lnk -> C:\Program Files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe (Abbott Diabetes Care) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\RA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk ShortcutTarget: EvernoteTray.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default FF user.js: detected! => C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\user.js FF Homepage: www.google.de|hxxp://www.creative-nonstop.com/|hxxp://www.existenzgruender.de/selbstaendigkeit/vorbereitung/index.php|hxxp://www.s354533063.website-start.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF SearchPlugin: C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\searchplugins\rapidshare-filefinder.xml FF Extension: Pocket - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\isreaditlater@ideashower.com FF Extension: Spartipps von SparPilot.com - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\sparpilot@sparpilot.com FF Extension: PriceGong - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829} FF Extension: Flash and Video Download - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} FF Extension: Bitdefender QuickScan - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} FF Extension: Evernote Web Clipper - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} FF Extension: amznUWL2 - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\amznUWL2@amazon.com.xpi FF Extension: artur.dubovoy - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\artur.dubovoy@gmail.com.xpi FF Extension: autofillForms - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\autofillForms@blueimp.net.xpi FF Extension: checkin - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\checkin@my4squarealibi.com.xpi FF Extension: duplicate-this-tab - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\duplicate-this-tab@mozilla.org.xpi FF Extension: exif_viewer - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\exif_viewer@mozilla.doslash.org.xpi FF Extension: firebug - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: fireform - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\fireform@mozilla.org.xpi FF Extension: firefox - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\firefox@red-cog.com.xpi FF Extension: HighlightedTextToFile - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\HighlightedTextToFile@bobbyrne01.org.xpi FF Extension: jid0-4deOYiOeBrYfBB9hS3xTnGoKZC4 - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\jid0-4deOYiOeBrYfBB9hS3xTnGoKZC4@jetpack.xpi FF Extension: picbrowser - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\picbrowser@iodragon.com.xpi FF Extension: readability - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\readability@readability.com.xpi FF Extension: rsDownloader - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\rsDownloader@163.com.xpi FF Extension: snaplinks - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\snaplinks@snaplinks.mozdev.org.xpi FF Extension: testpilot - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\testpilot@labs.mozilla.com.xpi FF Extension: tineye - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\tineye@ideeinc.com.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{5546F97E-11A5-46b0-9082-32AD74AAA920}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{6140bbfd-aa20-11e1-aba7-109add603214}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{62b958b4-9962-4fc2-9983-01a9a42d6f2d}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{791DB184-BFBA-11DA-9C61-0638DF403F48}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{9fb7d178-155a-4318-9173-1a8eaaea7fe4}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{a1109c2a-1187-4027-901d-13097b755625}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{B347DFB4-AC21-11DD-9016-B77D55D89593}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{cd6c4ebf-366e-45a0-98b5-b8217288eed7}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1956304 2013-03-04] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [635344 2013-02-25] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2249944 2013-02-25] (G Data Software AG) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [696808 2013-02-25] (G Data Software AG) R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [598808 2013-06-06] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-07-26] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [133976 2013-07-26] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [62808 2013-07-26] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-07-26] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-08-19] (G Data Software) R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-08-19] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [64856 2013-07-26] (G Data Software AG) R3 PRISM_A00; C:\Windows\System32\DRIVERS\PRISMA00.sys [407136 2009-10-27] (Conexant Systems, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-20 13:38 - 2013-08-20 01:45 - 01576196 _____ (Farbar) C:\Users\RA\Desktop\FRST64.exe 2013-08-20 13:37 - 2013-08-20 13:37 - 00000000 ____D C:\Users\RA\Desktop\FontDoctor-2-6-1 2013-08-20 13:36 - 2012-09-19 20:31 - 05278816 _____ C:\Users\RA\Desktop\FontDoctor-2-6-1.zip 2013-08-20 12:52 - 2013-08-20 12:52 - 00000000 ____D C:\Program Files\7-Zip 2013-08-20 12:18 - 2013-08-20 12:18 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-08-20 12:18 - 2013-08-20 12:18 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-20 12:18 - 2013-08-20 12:18 - 00000000 ____D C:\Program Files\CCleaner 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\rsit 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\Program Files (x86)\trend micro 2013-08-20 12:07 - 2013-08-20 12:17 - 00000000 ____D C:\Users\RA\Desktop\Scan 2013-08-20 11:53 - 2013-08-20 11:53 - 00000217 _____ C:\Users\RA\Desktop\impressum.URL 2013-08-20 11:53 - 2013-08-20 11:53 - 00000198 _____ C:\Users\RA\Desktop\Meschert Elektro-Technik GbR » Hier entsteht die Website der Meschert Elektro-Technik GbR.URL 2013-08-20 11:51 - 2013-07-22 11:36 - 00000761 _____ C:\Windows\system32\Drivers\etc\hosts.trb 2013-08-20 11:49 - 2013-08-20 11:49 - 00001139 _____ C:\Users\Public\Desktop\Trojan Remover.lnk 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\Documents\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\AppData\Roaming\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\ProgramData\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2013-08-20 09:48 - 2013-08-20 09:48 - 00000242 _____ C:\Users\RA\Desktop\Formular-Management-System der Bundesfinanzverwaltung (Fragebogen zur steuerlichen Erfassung Aufnahme einer gewerblichen, se.URL 2013-08-20 09:22 - 2013-07-25 15:45 - 23334896 _____ (Simply Super Software ) C:\Users\RA\Desktop\trjsetup_688.exe 2013-08-20 01:08 - 2013-08-20 02:00 - 00000504 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job 2013-08-20 01:08 - 2013-08-20 01:08 - 00003570 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb 2013-08-20 01:07 - 2013-08-20 01:07 - 00001808 _____ C:\Users\RA\Desktop\SUPERAntiSpyware Professional.lnk 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-08-19 16:44 - 2013-08-19 16:44 - 00000000 ____D C:\Users\RA\AppData\Roaming\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-19 16:43 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-19 16:36 - 2013-08-19 13:54 - 27088288 _____ (SUPERAntiSpyware) C:\Users\RA\Desktop\SUPERAntiSpywarePro.exe 2013-08-19 15:48 - 2013-08-19 15:48 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2013-08-15 19:54 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 19:54 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 19:54 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 19:54 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 19:54 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 19:54 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 19:54 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 19:54 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 19:54 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 19:54 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 19:54 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 19:54 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 19:39 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 19:39 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-15 19:39 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 19:39 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 19:39 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-15 19:39 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-15 19:38 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-15 19:38 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-15 19:38 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 19:38 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 19:38 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-15 19:38 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-15 19:38 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-15 19:38 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-15 19:38 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-15 19:38 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-15 19:38 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-15 19:38 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-15 19:38 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-15 19:38 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-15 19:35 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-11 12:04 - 2013-08-11 12:04 - 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-08-11 09:34 - 2013-08-11 09:34 - 37722096 _____ C:\Users\RA\Desktop\Unbenannt_HDR2.psd 2013-08-11 09:33 - 2013-08-11 09:33 - 120030172 _____ C:\Users\RA\Desktop\Unbenannt_HDR3.psd 2013-08-07 21:40 - 2013-08-07 21:40 - 00000000 ____D C:\Users\RA\Desktop\Flyer 2013-08-03 23:28 - 2013-08-03 23:29 - 00000000 ____D C:\Program Files (x86)\SetEdit8500 2013-08-02 18:51 - 2013-08-02 18:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Google 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\Software 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\NikLicenseFiles 2013-08-02 18:26 - 2013-08-20 13:36 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-02 18:26 - 2013-08-20 13:02 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-02 18:26 - 2013-08-02 18:31 - 00004098 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-02 18:26 - 2013-08-02 18:31 - 00003846 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-02 18:26 - 2013-08-02 18:27 - 00000000 ____D C:\Users\RA\AppData\Local\Google 2013-08-02 18:26 - 2013-08-02 18:27 - 00000000 ____D C:\ProgramData\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-02 00:26 - 2013-08-02 00:26 - 00000000 ____D C:\Users\RA\Desktop\HAUS 2013-07-29 23:23 - 2013-07-29 23:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\WTablet 2013-07-26 09:45 - 2013-07-26 09:45 - 00133976 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00062808 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\TabletPlugins 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\Tablet 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files (x86)\TabletPlugins 2013-07-26 09:36 - 2013-06-06 19:31 - 01959192 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01952536 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01820952 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01817880 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01614104 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01606936 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01493272 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01489176 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll 2013-07-26 09:36 - 2013-04-30 19:18 - 00085304 _____ (Wacom Technology) C:\Windows\system32\Drivers\wachidrouter.sys 2013-07-26 09:36 - 2013-04-30 19:18 - 00014136 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys 2013-07-26 09:36 - 2012-12-21 00:20 - 00015344 _____ (Wacom Technology) C:\Windows\system32\Drivers\wacomrouterfilter.sys 2013-07-25 21:29 - 2013-07-25 21:29 - 00000000 ____D C:\Users\RA\Desktop\ProcessExplorer 2013-07-25 21:09 - 2013-07-25 21:38 - 00000000 ____D C:\Windows\pss 2013-07-25 20:55 - 2013-07-25 20:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf 2013-07-25 12:03 - 2013-08-01 11:12 - 00000000 ____D C:\Users\RA\Desktop\Weierhof 2013-07-22 09:38 - 2013-07-22 09:38 - 00000000 ____D C:\ProgramData\RIBS ==================== One Month Modified Files and Folders ======= 2013-08-20 13:38 - 2013-08-20 13:38 - 00000000 ____D C:\FRST 2013-08-20 13:37 - 2013-08-20 13:37 - 00000000 ____D C:\Users\RA\Desktop\FontDoctor-2-6-1 2013-08-20 13:36 - 2013-08-02 18:26 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-20 13:09 - 2012-10-26 23:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-20 13:09 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-20 13:09 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-20 13:08 - 2012-10-26 23:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-20 13:06 - 2012-10-30 14:50 - 00000000 ____D C:\Users\RA\AppData\Roaming\Dropbox 2013-08-20 13:06 - 2012-10-26 21:53 - 00000000 ____D C:\Users\RA\AppData\Local\Adobe 2013-08-20 13:05 - 2012-10-31 20:12 - 00000000 ___HD C:\jexepackres 2013-08-20 13:02 - 2013-08-02 18:26 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-20 13:01 - 2013-05-17 17:44 - 00016829 _____ C:\Windows\setupact.log 2013-08-20 13:01 - 2013-05-17 17:43 - 00195946 _____ C:\Windows\PFRO.log 2013-08-20 13:01 - 2012-11-15 19:07 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-20 13:01 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-20 12:59 - 2012-10-26 20:20 - 01642364 _____ C:\Windows\WindowsUpdate.log 2013-08-20 12:52 - 2013-08-20 12:52 - 00000000 ____D C:\Program Files\7-Zip 2013-08-20 12:18 - 2013-08-20 12:18 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-08-20 12:18 - 2013-08-20 12:18 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-20 12:18 - 2013-08-20 12:18 - 00000000 ____D C:\Program Files\CCleaner 2013-08-20 12:17 - 2013-08-20 12:07 - 00000000 ____D C:\Users\RA\Desktop\Scan 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\rsit 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\Program Files (x86)\trend micro 2013-08-20 11:53 - 2013-08-20 11:53 - 00000217 _____ C:\Users\RA\Desktop\impressum.URL 2013-08-20 11:53 - 2013-08-20 11:53 - 00000198 _____ C:\Users\RA\Desktop\Meschert Elektro-Technik GbR » Hier entsteht die Website der Meschert Elektro-Technik GbR.URL 2013-08-20 11:53 - 2012-11-08 15:31 - 00000000 ____D C:\Users\RA\AppData\Local\CrashDumps 2013-08-20 11:49 - 2013-08-20 11:49 - 00001139 _____ C:\Users\Public\Desktop\Trojan Remover.lnk 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\Documents\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\AppData\Roaming\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\ProgramData\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2013-08-20 09:48 - 2013-08-20 09:48 - 00000242 _____ C:\Users\RA\Desktop\Formular-Management-System der Bundesfinanzverwaltung (Fragebogen zur steuerlichen Erfassung Aufnahme einer gewerblichen, se.URL 2013-08-20 02:00 - 2013-08-20 01:08 - 00000504 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job 2013-08-20 01:45 - 2013-08-20 13:38 - 01576196 _____ (Farbar) C:\Users\RA\Desktop\FRST64.exe 2013-08-20 01:08 - 2013-08-20 01:08 - 00003570 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb 2013-08-20 01:07 - 2013-08-20 01:07 - 00001808 _____ C:\Users\RA\Desktop\SUPERAntiSpyware Professional.lnk 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-08-19 16:44 - 2013-08-19 16:44 - 00000000 ____D C:\Users\RA\AppData\Roaming\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-19 15:48 - 2013-08-19 15:48 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2013-08-19 13:54 - 2013-08-19 16:36 - 27088288 _____ (SUPERAntiSpyware) C:\Users\RA\Desktop\SUPERAntiSpywarePro.exe 2013-08-15 22:29 - 2013-06-18 00:41 - 00128440 _____ C:\Users\RA\Documents\500pxPublisher.log 2013-08-15 19:51 - 2012-10-31 12:43 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-15 19:48 - 2013-07-11 14:14 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 19:44 - 2012-11-09 20:20 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-13 01:13 - 2013-04-19 21:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\vlc 2013-08-13 00:19 - 2013-05-04 01:06 - 00000000 ____D C:\Users\RA\Desktop\[[ SORT ]] 2013-08-13 00:18 - 1970-02-28 23:31 - 00000000 ____D C:\Users\RA\Desktop\CASTLE ___ 2013-07- 2013-08-11 12:04 - 2013-08-11 12:04 - 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-08-11 09:34 - 2013-08-11 09:34 - 37722096 _____ C:\Users\RA\Desktop\Unbenannt_HDR2.psd 2013-08-11 09:33 - 2013-08-11 09:33 - 120030172 _____ C:\Users\RA\Desktop\Unbenannt_HDR3.psd 2013-08-11 09:02 - 2012-10-26 23:09 - 00000000 ____D C:\Users\RA\AppData\Local\Thunderbird 2013-08-07 21:40 - 2013-08-07 21:40 - 00000000 ____D C:\Users\RA\Desktop\Flyer 2013-08-07 20:24 - 2013-06-27 14:04 - 00000000 ____D C:\Users\RA\Desktop\WordPress- 2013-08-07 17:03 - 2012-11-01 02:33 - 00000000 ____D C:\Users\RA\AppData\Roaming\FileZilla 2013-08-03 23:29 - 2013-08-03 23:28 - 00000000 ____D C:\Program Files (x86)\SetEdit8500 2013-08-03 21:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-02 20:13 - 2013-02-07 10:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Mp3tag 2013-08-02 18:51 - 2013-08-02 18:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Google 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\Software 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\NikLicenseFiles 2013-08-02 18:31 - 2013-08-02 18:26 - 00004098 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-02 18:31 - 2013-08-02 18:26 - 00003846 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-02 18:27 - 2013-08-02 18:26 - 00000000 ____D C:\Users\RA\AppData\Local\Google 2013-08-02 18:27 - 2013-08-02 18:26 - 00000000 ____D C:\ProgramData\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-02 17:25 - 2012-10-26 20:22 - 00000000 ____D C:\Users\RA\AppData\Local\VirtualStore 2013-08-02 11:27 - 2012-11-15 21:55 - 00000000 ____D C:\Users\RA\Documents\theRenamer 2013-08-02 00:26 - 2013-08-02 00:26 - 00000000 ____D C:\Users\RA\Desktop\HAUS 2013-08-01 11:12 - 2013-07-25 12:03 - 00000000 ____D C:\Users\RA\Desktop\Weierhof 2013-07-31 10:58 - 2012-11-09 09:50 - 00000000 ____D C:\Users\RA\AppData\Roaming\iFunbox_UserCache 2013-07-30 14:55 - 2012-10-29 11:03 - 00001456 _____ C:\Users\RA\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2013-07-30 11:31 - 2013-01-23 11:10 - 00000000 ____D C:\Users\RA\AppData\Roaming\Skype 2013-07-29 23:23 - 2013-07-29 23:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\WTablet 2013-07-29 11:20 - 2013-07-15 14:05 - 00000000 ____D C:\Users\RA\Desktop\[GRÜNDUNG] 2013-07-26 09:45 - 2013-07-26 09:45 - 00133976 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00062808 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2013-07-26 09:45 - 2012-10-26 22:52 - 00000000 ____D C:\ProgramData\G DATA 2013-07-26 09:43 - 2012-10-26 22:52 - 00000000 ____D C:\Program Files (x86)\G Data 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\TabletPlugins 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\Tablet 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files (x86)\TabletPlugins 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com 2013-07-26 09:30 - 2012-10-26 20:22 - 00000000 ___RD C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-26 07:13 - 2013-08-15 19:54 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-15 19:54 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-15 19:54 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-15 19:54 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-15 19:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-15 19:54 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-15 19:54 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-15 19:54 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-15 19:54 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-15 19:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-15 19:54 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-15 19:54 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 21:38 - 2013-07-25 21:09 - 00000000 ____D C:\Windows\pss 2013-07-25 21:29 - 2013-07-25 21:29 - 00000000 ____D C:\Users\RA\Desktop\ProcessExplorer 2013-07-25 20:55 - 2013-07-25 20:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf 2013-07-25 15:45 - 2013-08-20 09:22 - 23334896 _____ (Simply Super Software ) C:\Users\RA\Desktop\trjsetup_688.exe 2013-07-25 11:58 - 2013-03-27 11:12 - 00000000 ___RD C:\Users\RA\Desktop\facebook 2013-07-25 11:25 - 2013-08-15 19:38 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-15 19:38 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 22:27 - 2012-10-26 22:21 - 00187400 _____ C:\Users\RA\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-24 22:25 - 2009-07-14 06:45 - 06132088 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-23 16:17 - 2012-10-26 21:57 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-23 16:02 - 2012-10-26 21:58 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-23 16:00 - 2012-10-26 21:58 - 00000000 ____D C:\Program Files\Adobe 2013-07-23 14:55 - 2012-10-26 21:53 - 00000000 ____D C:\Users\RA\AppData\Roaming\Adobe 2013-07-23 12:57 - 2012-10-26 21:54 - 00000000 ____D C:\ProgramData\Adobe 2013-07-23 12:31 - 2012-10-26 20:21 - 00000000 ____D C:\Users\RA 2013-07-22 11:45 - 2012-10-26 23:29 - 00000000 ____D C:\Users\RA\AppData\Roaming\Apple Computer 2013-07-22 11:41 - 2012-10-26 23:21 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-22 11:36 - 2013-08-20 11:51 - 00000761 _____ C:\Windows\system32\Drivers\etc\hosts.trb 2013-07-22 09:38 - 2013-07-22 09:38 - 00000000 ____D C:\ProgramData\RIBS ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-05 12:47 ==================== End Of Log ============================ --- --- --- und Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-08-2013 03 Ran by RA at 2013-08-20 13:57:33 Running from C:\Users\RA\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 64 Bit HP CIO Components Installer (Version: 13.2.1) 7-Zip 9.30 (x64 edition) (Version: Adobe Acrobat XI Pro (x32 Version: 11.0) Adobe Acrobat XI Pro (x32 Version: 11.0.02) Adobe After Effects CC (x32 Version: 12) Adobe AIR (x32 Version: Adobe Bridge CC (64 Bit) (x32 Version: 6.0) Adobe Connect 9 Add-in (HKCU Version: 11,2,381,0) Adobe Creative Cloud (x32 Version: Adobe Download Assistant (x32 Version: 1.2.3) Adobe Dreamweaver CC (x32 Version: 13) Adobe Edge Animate (x32 Version: 1.5) Adobe Edge Animate CC (x32 Version: 2.0) Adobe Edge Code CC (x32 Version: 0.94) Adobe Edge Inspect CC (x32 Version: 1.0.408) Adobe Edge Reflow CC Preview (x32 Version: 0.23.10993) Adobe Exchange Panel (x32 Version: 1) Adobe ExtendScript Toolkit CC (x32 Version: Adobe Extension Manager CC (x32 Version: 7.1) Adobe Flash Builder 4.7 (64 Bit) (x32 Version: 4.7) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Flash Professional CC (x32 Version: 13.0) Adobe Help Manager (x32 Version: 4.0.244) Adobe Illustrator CC (x32 Version: 17.0) Adobe InCopy CC (x32 Version: 9.0) Adobe InDesign CC (x32 Version: 9.0) Adobe Media Player (x32 Version: 1.8) Adobe Muse (x32 Version: 4.1) Adobe Muse (x32 Version: 4.1.8) Adobe Photoshop CC (x32 Version: 14.0) Adobe Photoshop Lightroom 4.2 64-bit (Version: 4.2.1) Adobe Photoshop Lightroom 5 64-bit (Version: 5.0.1) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Adobe Touch App Plugins (x32 Version: 1.0) Adobe Widget Browser (x32 Version: 2.0 Build 348) Adobe Widget Browser (x32 Version: 2.0.348) Adobe® Content Viewer (x32 Version: 3.2.0) Air Video Server 2.4.6-beta3 (x32 Version: 2.4.6-beta3) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: Apple Software Update (x32 Version: Attribute Changer 7.10c (x32 Version: 7.10c) Axialis IconWorkshop 6.33 (x32 Version: 6.33) Biet-O-Matic v2.14.12 (x32 Version: 2.14.12) bl (x32 Version: 1.0.0) BMWi-Businessplaner Gründung (x32 Version: 1.0.2) Bonjour (Version: Bonjour-Druckdienste (Version: Bonjour-Druckdienste (Version: Camtasia Studio 8 (x32 Version: Canon Auto Update Service (x32 Version: CANON iMAGE GATEWAY MyCamera Download Plugin (x32 Version: CANON iMAGE GATEWAY Task for ZoomBrowser EX (x32 Version: Canon MOV Decoder (x32 Version: Canon MOV Encoder (x32 Version: Canon MovieEdit Task for ZoomBrowser EX (x32 Version: Canon MP Navigator EX 1.0 (x32) Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX (x32 Version: Canon Utilities ZoomBrowser EX (x32 Version: Canon ZoomBrowser EX Memory Card Utility (x32 Version: CCleaner (Version: 4.04) CDDRV_Installer (Version: 4.24.15) Directory Lister Pro v1.49 (x32 Version: 1.49) DisplayFusion 5.0.1 (x32 Version: Dropbox (HKCU Version: 1.4.20) Evernote v. 4.6.7 (x32 Version: ExposurePlot 1.1.5a (x32) Extensis Suitcase Fusion 3 (x32 Version: 14.2.0) FileZilla Client (x32 Version: FreeStyle Auto-Assist (x32) G Data AntiVirus 2014 (x32 Version: GeoSetter 3.4.16 (x32) Google Update Helper (x32 Version: HandBrake 0.9.8 (x32 Version: 0.9.8) iFunbox (v2.0.2150.728), iFunbox DevTeam (x32 Version: v2.0.2150.728) ipswDownloader 1.6 (x32 Version: 1.6) iTunes (Version: Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: KhalInstallWrapper (Version: 4.24.99) K-Lite Codec Pack 5.2.0 (Full) (x32 Version: 5.2.0) Lightroom 5.0 (x32 Version: 5.0) Logitech SetPoint (x32 Version: 4.24) Malwarebytes Anti-Malware Version (x32 Version: MetroTwit (HKCU Version: Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) MozBackup 1.5.1 (x32) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7) Mp3tag v2.54 (x32 Version: v2.54) Nik Collection (x32 Version: Notepad++ (x32 Version: 6.2) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) or Autopano Giga 2.6 (Version: V2.6.4) PDF Settings CC (x32 Version: 12.0) ph (x32 Version: 1.0.0) PxMergeModule (x32 Version: 1.00.0000) QuickTime (x32 Version: Recuva (Version: 1.47) Safari (x32 Version: SilverFast CanonSDK 6.6.2r5 (x32) Skype™ 6.1 (x32 Version: 6.1.129) Spotify (HKCU Version: StreamTransport version: (x32) SUPERAntiSpyware (Version: 5.6.1032) TeamViewer 7 (x32 Version: 7.0.17271) theRenamer 7.58 (x32) Trojan Remover 6.8.8 (x32 Version: 6.8.8) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2768023) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817642) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (Version: 6.3.6w3) Webocton - Scriptly (x32 Version: WebTablet FB Plugin 32 bit (x32 Version: WebTablet FB Plugin 64 bit (Version: Yahoo! Detect (x32) ==================== Restore Points ========================= 07-08-2013 08:03:17 Windows Update 11-08-2013 06:54:33 Windows Update 15-08-2013 17:40:04 Windows Update 20-08-2013 08:48:31 Windows Update 20-08-2013 10:49:50 Installed 7-Zip 9.30 (x64 edition) ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-08-20 11:51 - 00000975 ____A C:\Windows\system32\Drivers\etc\hosts localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05038D52-B7F7-447D-BB6D-BE3C3EE86462} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02] (Google Inc.) Task: {140FE688-9A46-4AC0-B53E-A7E8A374E5BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {16FD5339-9FD9-4F09-8B0D-C6676AE4E3EF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {1FD7E82F-D5E8-417E-85EE-76F3AB065A88} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {69F0E039-1FAE-424B-989B-E3188B31AAD9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) Task: {6FBA5E25-A5ED-4CCA-8E58-975D0D3B67FB} - System32\Tasks\AdobeAAMUpdater-1.0-RA-PC-RA => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {7B1CA893-A231-4797-8D15-CF4F79DD3B59} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02] (Google Inc.) Task: {97C170EF-50DF-487B-9CF2-642BD30531A0} - System32\Tasks\AdobeAAMUpdater-1.0-RA-PC-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {D512B88E-1481-4F38-B816-DC8334646AD7} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {D600E553-C31B-44A2-9D11-FC5232A38A45} - System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/20/2013 11:53:05 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Rmvtrjan.exe, Version:, Zeitstempel: 0x51e96b81 Name des fehlerhaften Moduls: USER32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba59 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001872e ID des fehlerhaften Prozesses: 0x68c Startzeit der fehlerhaften Anwendung: 0xRmvtrjan.exe0 Pfad der fehlerhaften Anwendung: Rmvtrjan.exe1 Pfad des fehlerhaften Moduls: Rmvtrjan.exe2 Berichtskennung: Rmvtrjan.exe3 Error: (08/19/2013 04:02:34 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: mmc.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc808 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b8479b Ausnahmecode: 0x00000000 Fehleroffset: 0x0000000000009e5d ID des fehlerhaften Prozesses: 0x91c Startzeit der fehlerhaften Anwendung: 0xmmc.exe0 Pfad der fehlerhaften Anwendung: mmc.exe1 Pfad des fehlerhaften Moduls: mmc.exe2 Berichtskennung: mmc.exe3 Error: (08/15/2013 09:41:09 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2bcac Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000003c010 ID des fehlerhaften Prozesses: 0xf68 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/13/2013 00:47:56 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: StreamTransport.exe, Version:, Zeitstempel: 0x2a425e19 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0x0eedfade Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x1c80 Startzeit der fehlerhaften Anwendung: 0xStreamTransport.exe0 Pfad der fehlerhaften Anwendung: StreamTransport.exe1 Pfad des fehlerhaften Moduls: StreamTransport.exe2 Berichtskennung: StreamTransport.exe3 Error: (08/11/2013 04:59:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MediaCoreIF.DLL, Version:, Zeitstempel: 0x51a64846 Ausnahmecode: 0xc000041d Fehleroffset: 0x0000000000201ac8 ID des fehlerhaften Prozesses: 0x1ab4 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/11/2013 04:51:15 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MediaCoreIF.DLL, Version:, Zeitstempel: 0x51a64846 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000201ac8 ID des fehlerhaften Prozesses: 0x1ab4 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/11/2013 04:01:23 PM) (Source: Application Hang) (User: ) Description: Programm lightroom.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 14d0 Startzeit: 01ce969a7edab799 Endzeit: 79 Anwendungspfad: C:\Program Files\Adobe\Adobe Photoshop Lightroom 5\lightroom.exe Berichts-ID: 7dbd60e1-028e-11e3-8bf0-0007ca045fc4 Error: (08/11/2013 03:53:37 PM) (Source: Application Hang) (User: ) Description: Programm lightroom.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 17cc Startzeit: 01ce96791c0d6338 Endzeit: 4120 Anwendungspfad: C:\Program Files\Adobe\Adobe Photoshop Lightroom 5\lightroom.exe Berichts-ID: 556d243a-028d-11e3-8bf0-0007ca045fc4 Error: (08/07/2013 10:02:07 AM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (08/07/2013 10:02:07 AM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=3800} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (08/20/2013 01:04:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 01:04:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/19/2013 03:53:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (08/19/2013 03:48:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/19/2013 03:48:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/16/2013 10:43:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/16/2013 10:43:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/15/2013 07:24:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/15/2013 07:24:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/13/2013 09:31:53 AM) (Source: DCOM) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 63% Total physical RAM: 4094.49 MB Available physical RAM: 1499.52 MB Total Pagefile: 8187.17 MB Available Pagefile: 4776.45 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:298.09 GB) (Free:111.64 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (MUSIK) (Fixed) (Total:200.2 GB) (Free:95.84 GB) NTFS Drive e: (ARBEIT) (Fixed) (Total:74.53 GB) (Free:43.7 GB) NTFS Drive f: (PRIVAT) (Fixed) (Total:100.59 GB) (Free:71.3 GB) NTFS Drive g: (RAM) (Fixed) (Total:50.29 GB) (Free:50.16 GB) NTFS Drive h: (FONTS) (Fixed) (Total:114.68 GB) (Free:105.77 GB) NTFS Drive o: (My Book) (Fixed) (Total:931.28 GB) (Free:349.63 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 8D33E5C1) Partition 1: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=101 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=115 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D578C98E) Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 75 GB) (Disk ID: B5495A2E) Partition 1: (Not Active) - (Size=75 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (Size: 932 GB) (Disk ID: E8900690) Partition 1: (Not Active) - (Size=932 GB) - (Type=0C) ==================== End Of Log ============================ Ich hoffe das hilft erst mal weiter... :-) |
![]() | #4 | |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner?Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM!
![]() | #5 | |
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Hallo Schrauber, hat leider ein wenig gedauert, habe nicht gleich deine Nachricht gesehen. Hier also nun der Log von ComboFix Code:
ATTFilter ComboFix 13-08-19.02 - RA 20.08.2013 15:12:06.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4094.1845 [GMT 2:00] ausgeführt von:: c:\users\RA\Desktop\ComboFix.exe AV: G Data AntiVirus 2014 *Disabled/Updated* {39B780B4-63C2-05B0-3B40-8F7A21E4F496} SP: G Data AntiVirus 2014 *Disabled/Updated* {82D66150-45F8-0A3E-01F0-B4085A63BE2B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\SysWow64\is-NH2V0.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-20 bis 2013-08-20 )))))))))))))))))))))))))))))) . . 2013-08-20 13:28 . 2013-08-20 13:28 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-08-20 13:28 . 2013-08-20 13:28 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-20 13:28 . 2013-08-20 13:28 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2013-08-20 11:38 . 2013-08-20 11:38 -------- d-----w- C:\FRST 2013-08-20 10:52 . 2013-08-20 10:52 -------- d-----w- c:\program files\7-Zip 2013-08-20 10:18 . 2013-08-20 10:18 -------- d-----w- c:\program files\CCleaner 2013-08-20 10:09 . 2013-08-20 10:09 -------- d-----w- C:\rsit 2013-08-20 10:09 . 2013-08-20 10:09 -------- d-----w- c:\program files (x86)\trend micro 2013-08-20 09:49 . 2013-08-20 09:49 -------- d-----w- c:\users\RA\AppData\Roaming\Simply Super Software 2013-08-20 09:49 . 2013-08-20 09:49 -------- d-----w- c:\programdata\Simply Super Software 2013-08-20 09:49 . 2013-08-20 09:49 -------- d-----w- c:\program files (x86)\Trojan Remover 2013-08-20 08:49 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{342C5578-6CE3-4153-B66C-35D51C6DD25F}\mpengine.dll 2013-08-19 23:07 . 2013-08-19 23:07 -------- d-----w- c:\users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-19 23:07 . 2013-08-19 23:07 -------- d-----w- c:\program files\SUPERAntiSpyware 2013-08-19 23:07 . 2013-08-19 23:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2013-08-19 14:44 . 2013-08-19 14:44 -------- d-----w- c:\users\RA\AppData\Roaming\Malwarebytes 2013-08-19 14:43 . 2013-08-19 14:43 -------- d-----w- c:\programdata\Malwarebytes 2013-08-19 14:43 . 2013-08-19 14:43 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-08-19 14:43 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-08-19 13:48 . 2013-08-19 13:48 107128 ----a-w- c:\windows\system32\drivers\GRD.sys 2013-08-15 17:39 . 2013-07-09 05:51 1217024 ----a-w- c:\windows\system32\rpcrt4.dll 2013-08-15 17:39 . 2013-07-09 04:52 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2013-08-15 17:39 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll 2013-08-15 17:39 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-15 17:39 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll 2013-08-15 17:39 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-15 17:39 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-08-15 17:39 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-08-15 17:39 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-08-15 17:39 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-08-15 17:39 . 2013-07-19 01:58 2048 ----a-w- c:\windows\system32\tzres.dll 2013-08-15 17:39 . 2013-07-19 01:41 2048 ----a-w- c:\windows\SysWow64\tzres.dll 2013-08-15 17:35 . 2013-07-06 06:03 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-03 21:28 . 2013-08-03 21:29 -------- d-----w- c:\program files (x86)\SetEdit8500 2013-08-02 16:37 . 2013-08-02 16:37 -------- d-----w- c:\users\RA\AppData\Local\NikLicenseFiles 2013-08-02 16:37 . 2013-08-02 16:37 -------- d-----w- c:\users\RA\AppData\Local\Software 2013-08-02 16:26 . 2013-08-02 16:26 -------- d-----w- c:\program files\Google 2013-08-02 16:26 . 2013-08-02 16:27 -------- d-----w- c:\users\RA\AppData\Local\Google 2013-08-02 16:26 . 2013-08-02 16:26 -------- d-----w- c:\program files (x86)\Google 2013-08-02 15:18 . 2013-08-02 15:27 -------- d-----w- c:\program files\WinFellow 2013-08-02 15:13 . 2013-08-02 15:18 -------- d-----w- c:\users\RA\AppData\Roaming\WinFellow 2013-07-29 21:23 . 2013-07-29 21:23 -------- d-----w- c:\users\RA\AppData\Roaming\WTablet 2013-07-26 07:45 . 2013-07-26 07:45 62808 ----a-w- c:\windows\system32\drivers\PktIcpt.sys 2013-07-26 07:45 . 2013-07-26 07:45 64856 ----a-w- c:\windows\system32\drivers\gdwfpcd64.sys 2013-07-26 07:45 . 2013-07-26 07:45 64856 ----a-w- c:\windows\system32\drivers\HookCentre.sys 2013-07-26 07:45 . 2013-07-26 07:45 60248 ----a-w- c:\windows\system32\drivers\GDBehave.sys 2013-07-26 07:45 . 2013-07-26 07:45 133976 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys 2013-07-26 07:43 . 2013-07-26 07:43 -------- d-----w- c:\program files (x86)\Common Files\G Data 2013-07-26 07:33 . 2013-07-26 07:33 -------- d-----w- c:\windows\SysWow64\wbem\Logs 2013-07-22 07:38 . 2013-07-22 07:38 -------- d-----w- c:\programdata\RIBS . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-15 17:44 . 2012-11-09 18:20 78161360 ----a-w- c:\windows\system32\MRT.exe 2013-07-09 04:45 . 2013-08-15 17:38 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-07-03 13:34 . 2012-11-02 10:59 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-07-03 13:34 . 2012-11-02 10:59 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-27 12:05 . 2013-02-28 12:10 16944 ----a-w- c:\windows\system32\drivers\GdPhyMem.sys 2013-06-24 07:05 . 2013-06-24 07:05 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-24 07:05 . 2012-10-31 18:15 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-06-24 07:05 . 2012-10-31 18:15 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-06-05 03:34 . 2013-07-10 20:31 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 06:00 . 2013-07-10 20:31 624128 ----a-w- c:\windows\system32\qedit.dll 2013-06-04 04:53 . 2013-07-10 20:31 509440 ----a-w- c:\windows\SysWow64\qedit.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FMCore.exe"="c:\program files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe" [2011-10-27 9211392] "DisplayFusion"="c:\program files (x86)\DisplayFusion\DisplayFusion.exe" [2013-04-26 7283072] "iFunBoxConnector"="c:\program files (x86)\i-Funbox DevTeam\ifb_conn.exe" [2013-04-23 812544] "AirVideoServer"="c:\program files (x86)\AirVideoServer\AirVideoServer.exe" [2012-07-19 4935112] "Spotify Web Helper"="c:\users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2013-06-26 1104384] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-08-15 6581488] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "G Data ASM"="c:\program files (x86)\G Data\AntiVirus\DelayLoader\AutorunDelayLoader.exe" [2013-02-25 472016] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-08-08 2236816] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe" [2012-12-18 3478752] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-05-31 152392] "G Data AntiVirus Tray"="c:\program files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe" [2013-02-25 1444304] "TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2013-07-19 1655568] . c:\users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\RA\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968] EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2013-7-23 1089888] EvernoteTray.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteTray.exe [2013-7-23 395104] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ FreeStyle Auto-Assist.lnk - c:\program files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe [2012-11-16 64336] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2013-6-7 1148944] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 GDPkIcpt;GDPkIcpt;c:\windows\system32\drivers\PktIcpt.sys;c:\windows\SYSNATIVE\drivers\PktIcpt.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 GDBehave;GDBehave;c:\windows\system32\drivers\GDBehave.sys;c:\windows\SYSNATIVE\drivers\GDBehave.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S1 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys;c:\windows\SYSNATIVE\drivers\MiniIcpt.sys [x] S1 gdwfpcd;G Data WFP CD;c:\windows\system32\drivers\gdwfpcd64.sys;c:\windows\SYSNATIVE\drivers\gdwfpcd64.sys [x] S1 GRD;G Data Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys;c:\windows\SYSNATIVE\drivers\GRD.sys [x] S1 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys;c:\windows\SYSNATIVE\drivers\HookCentre.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x] S2 AVKProxy;G Data AntiVirus Proxy;c:\program files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe;c:\program files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [x] S2 AVKService;G Data Scheduler;c:\program files (x86)\G Data\AntiVirus\AVK\AVKService.exe;c:\program files (x86)\G Data\AntiVirus\AVK\AVKService.exe [x] S2 AVKWCtl;G Data Dateisystem Wächter;c:\program files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe;c:\program files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [x] S2 DisplayFusionService;DisplayFusionService;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x] S2 WTabletServicePro;Wacom Professional Service;c:\program files\Tablet\Wacom\WTabletServicePro.exe;c:\program files\Tablet\Wacom\WTabletServicePro.exe [x] S3 GDScan;G Data Scanner;c:\program files (x86)\Common Files\G Data\GDScan\GDScan.exe;c:\program files (x86)\Common Files\G Data\GDScan\GDScan.exe [x] S3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x] S3 PRISM_A00;PRISM 802.11 Driver;c:\windows\system32\DRIVERS\PRISMA00.sys;c:\windows\SYSNATIVE\DRIVERS\PRISMA00.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys;c:\windows\SYSNATIVE\DRIVERS\teamviewervpn.sys [x] S3 WacHidRouter;Wacom Hid Router;c:\windows\system32\DRIVERS\wachidrouter.sys;c:\windows\SYSNATIVE\DRIVERS\wachidrouter.sys [x] S3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02 16:26] . 2013-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02 16:26] . 2013-08-20 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-07-31 20:36 3359088 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-07-31 20:36 3359088 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-07-31 20:36 3359088 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Bluetooth Connection Assistant"="LBTWIZ.EXE -silent" [X] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 134160] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: An vorhandene PDF-Datei anfügen - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Auswahl speichern - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 IE: Bild ausschneiden - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=4 IE: Diese Seite ausschneiden - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 IE: In Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Linkziel an vorhandene PDF-Datei anhängen - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Linkziel in Adobe PDF konvertieren - c:\program files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Neue Notiz - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\NewNote.html IE: URL notieren - c:\program files (x86)\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 TCP: DhcpNameServer = FF - ProfilePath - c:\users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\ FF - prefs.js: browser.startup.homepage - www.google.de|hxxp://www.creative-nonstop.com/|hxxp://www.existenzgruender.de/selbstaendigkeit/vorbereitung/index.php|hxxp://www.s354533063.website-start.de FF - ExtSQL: 2013-07-08 11:50; amznUWL2@amazon.com; c:\users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\extensions\amznUWL2@amazon.com.xpi FF - ExtSQL: 2013-08-20 09:27; {6140bbfd-aa20-11e1-aba7-109add603214}; c:\users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\extensions\{6140bbfd-aa20-11e1-aba7-109add603214}.xpi . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-{43B74FAB-FB58-447D-8D3A-5F638AF36FD1} - c:\programdata\{87B61FE8-334F-4066-B7AA-68DC81782D4D}\Netzmanager1.071.0301_120720a.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-20 15:32:07 ComboFix-quarantined-files.txt 2013-08-20 13:32 . Vor Suchlauf: 12 Verzeichnis(se), 119.676.317.696 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 145.514.139.648 Bytes frei . - - End Of File - - 888E85D1FB790B0A22E0E5D045ED1E1D 5C616939100B85E558DA92B899A0FC36 Zitat:
![]() |
![]() | #6 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
und ein frisches FRST log bitte.
__________________ --> Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? |
![]() | #7 | |
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Hallo Schrauber, noch eine kurze Frage zu Malwarebytes Anti-Malware. Du schreibst Zitat:
Vielen Dank für deine Rückmeldung schonmal! ![]() |
![]() | #8 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Quick Scan ist mehr als ausreichend ![]()
gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM!
![]() | #9 | |
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? So, Malwarebytes Anti-Malware hat keine infizierten Objekte gefunden. Schonmal positiv, denke ich. Log sieht folgendermaßen aus ... Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.08.20.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 RA :: RA-PC [Administrator] 20.08.2013 16:20:24 mbam-log-2013-08-20 (16-20-24).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P Deaktivierte Suchlaufeinstellungen: Durchsuchte Objekte: 274228 Laufzeit: 6 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Zitat:
Jetzt wurde eine Datei, Registry-Einträge und was unter Firefox gefunden... Habe dann "Clean" ausgewählt, die Einträge wurden entfernt und der Rechner neu gestartet. Dann wurde der Log hier angezeigt ... Code:
ATTFilter # AdwCleaner v3.000 - Report created 20/08/2013 at 16:46:35 # Updated 20/08/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : RA - RA-PC # Running from : C:\Users\RA\Desktop\Scan\8\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Users\RA\AppData\Local\PackageAware Folder Deleted : C:\Users\RA\AppData\LocalLow\PriceGong Folder Deleted : C:\Users\RA\AppData\Roaming\DesktopIconForAmazon Folder Deleted : C:\Users\RA\AppData\Roaming\OCS Folder Deleted : C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\jetpack Folder Deleted : C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829} Folder Deleted : C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\sparpilot@sparpilot.com File Deleted : C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\user.js ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKCU\Software\OCS Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1648 octets] - [20/08/2013 16:34:49] AdwCleaner[S0].txt - [1511 octets] - [20/08/2013 16:46:35] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1571 octets] ########## FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-08-2013 03 Ran by RA (administrator) on 20-08-2013 17:00:33 Running from C:\Users\RA\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\tv_x64.exe (Logitech Inc.) C:\Program Files\Logitech\SetPoint\LBTWiz.exe (Celartem, Inc., doing business as Extensis.) C:\Program Files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe () C:\Program Files (x86)\i-Funbox DevTeam\ifb_conn.exe () C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe (Spotify Ltd) C:\Users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (Abbott Diabetes Care) C:\Program Files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe (Dropbox, Inc.) C:\Users\RA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\Evernote.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [134160 2007-09-21] (Logitech, Inc.) HKLM\...\Run: [Bluetooth Connection Assistant] - LBTWIZ.EXE -silent [x] HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKCU\...\Run: [FMCore.exe] - C:\Program Files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe [9211392 2011-10-27] (Celartem, Inc., doing business as Extensis.) HKCU\...\Run: [DisplayFusion] - C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software) HKCU\...\Run: [iFunBoxConnector] - C:\Program Files (x86)\i-Funbox DevTeam\ifb_conn.exe [812544 2013-04-23] () HKCU\...\Run: [AirVideoServer] - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe [4935112 2012-07-20] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-06-26] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6581488 2013-08-15] (SUPERAntiSpyware) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [G Data ASM] - C:\Program Files (x86)\G Data\AntiVirus\DelayLoader\AutorunDelayLoader.exe [472016 2013-02-25] (G Data Software AG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-08-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478752 2012-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [G Data AntiVirus Tray] - C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe [1444304 2013-02-25] (G Data Software AG) HKLM-x32\...\Run: [TrojanScanner] - C:\Program Files (x86)\Trojan Remover\Trjscan.exe [1655568 2013-07-19] (Simply Super Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FreeStyle Auto-Assist.lnk ShortcutTarget: FreeStyle Auto-Assist.lnk -> C:\Program Files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe (Abbott Diabetes Care) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\RA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk ShortcutTarget: EvernoteTray.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default FF Homepage: www.google.de|hxxp://www.creative-nonstop.com/|hxxp://www.existenzgruender.de/selbstaendigkeit/vorbereitung/index.php|hxxp://www.s354533063.website-start.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF SearchPlugin: C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\searchplugins\rapidshare-filefinder.xml FF Extension: Pocket - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\isreaditlater@ideashower.com FF Extension: Flash and Video Download - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} FF Extension: Bitdefender QuickScan - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} FF Extension: Evernote Web Clipper - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} FF Extension: amznUWL2 - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\amznUWL2@amazon.com.xpi FF Extension: artur.dubovoy - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\artur.dubovoy@gmail.com.xpi FF Extension: autofillForms - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\autofillForms@blueimp.net.xpi FF Extension: checkin - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\checkin@my4squarealibi.com.xpi FF Extension: duplicate-this-tab - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\duplicate-this-tab@mozilla.org.xpi FF Extension: exif_viewer - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\exif_viewer@mozilla.doslash.org.xpi FF Extension: firebug - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: fireform - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\fireform@mozilla.org.xpi FF Extension: firefox - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\firefox@red-cog.com.xpi FF Extension: HighlightedTextToFile - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\HighlightedTextToFile@bobbyrne01.org.xpi FF Extension: jid0-4deOYiOeBrYfBB9hS3xTnGoKZC4 - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\jid0-4deOYiOeBrYfBB9hS3xTnGoKZC4@jetpack.xpi FF Extension: picbrowser - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\picbrowser@iodragon.com.xpi FF Extension: readability - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\readability@readability.com.xpi FF Extension: rsDownloader - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\rsDownloader@163.com.xpi FF Extension: snaplinks - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\snaplinks@snaplinks.mozdev.org.xpi FF Extension: testpilot - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\testpilot@labs.mozilla.com.xpi FF Extension: tineye - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\tineye@ideeinc.com.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{5546F97E-11A5-46b0-9082-32AD74AAA920}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{6140bbfd-aa20-11e1-aba7-109add603214}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{62b958b4-9962-4fc2-9983-01a9a42d6f2d}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{791DB184-BFBA-11DA-9C61-0638DF403F48}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{9fb7d178-155a-4318-9173-1a8eaaea7fe4}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{a1109c2a-1187-4027-901d-13097b755625}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{B347DFB4-AC21-11DD-9016-B77D55D89593}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{cd6c4ebf-366e-45a0-98b5-b8217288eed7}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1956304 2013-03-04] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [635344 2013-02-25] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2249944 2013-02-25] (G Data Software AG) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [696808 2013-02-25] (G Data Software AG) R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [598808 2013-06-06] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-07-26] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [133976 2013-07-26] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [62808 2013-07-26] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-07-26] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-08-19] (G Data Software) R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-08-19] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [64856 2013-07-26] (G Data Software AG) R3 PRISM_A00; C:\Windows\System32\DRIVERS\PRISMA00.sys [407136 2009-10-27] (Conexant Systems, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-20 15:32 - 2013-08-20 15:32 - 00018312 _____ C:\ComboFix.txt 2013-08-20 15:09 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-20 15:09 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-20 15:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-20 15:04 - 2013-08-20 15:32 - 00000000 ____D C:\Qoobox 2013-08-20 15:03 - 2013-08-20 15:29 - 00000000 ____D C:\Windows\erdnt 2013-08-20 15:01 - 2013-08-19 20:13 - 05106564 ____R (Swearware) C:\Users\RA\Desktop\ComboFix.exe 2013-08-20 13:58 - 2013-08-20 13:58 - 00052647 _____ C:\Users\RA\Desktop\FRST-1.txt 2013-08-20 13:57 - 2013-08-20 13:58 - 00023039 _____ C:\Users\RA\Desktop\Addition-1.txt 2013-08-20 13:38 - 2013-08-20 13:38 - 00000000 ____D C:\FRST 2013-08-20 13:38 - 2013-08-20 01:45 - 01576196 _____ (Farbar) C:\Users\RA\Desktop\FRST64.exe 2013-08-20 13:37 - 2013-08-20 13:37 - 00000000 ____D C:\Users\RA\Desktop\FontDoctor-2-6-1 2013-08-20 13:36 - 2012-09-19 20:31 - 05278816 _____ C:\Users\RA\Desktop\FontDoctor-2-6-1.zip 2013-08-20 13:08 - 2013-08-20 15:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-20 12:52 - 2013-08-20 12:52 - 00000000 ____D C:\Program Files\7-Zip 2013-08-20 12:18 - 2013-08-20 12:18 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-08-20 12:18 - 2013-08-20 12:18 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-20 12:18 - 2013-08-20 12:18 - 00000000 ____D C:\Program Files\CCleaner 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\rsit 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\Program Files (x86)\trend micro 2013-08-20 12:07 - 2013-08-20 16:29 - 00000000 ____D C:\Users\RA\Desktop\Scan 2013-08-20 11:53 - 2013-08-20 11:53 - 00000217 _____ C:\Users\RA\Desktop\impressum.URL 2013-08-20 11:53 - 2013-08-20 11:53 - 00000198 _____ C:\Users\RA\Desktop\Meschert Elektro-Technik GbR » Hier entsteht die Website der Meschert Elektro-Technik GbR.URL 2013-08-20 11:51 - 2013-07-22 11:36 - 00000761 _____ C:\Windows\system32\Drivers\etc\hosts.trb 2013-08-20 11:49 - 2013-08-20 11:49 - 00001139 _____ C:\Users\Public\Desktop\Trojan Remover.lnk 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\Documents\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\AppData\Roaming\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\ProgramData\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2013-08-20 09:48 - 2013-08-20 09:48 - 00000242 _____ C:\Users\RA\Desktop\Formular-Management-System der Bundesfinanzverwaltung (Fragebogen zur steuerlichen Erfassung Aufnahme einer gewerblichen, se.URL 2013-08-20 09:22 - 2013-07-25 15:45 - 23334896 _____ (Simply Super Software ) C:\Users\RA\Desktop\trjsetup_688.exe 2013-08-20 01:08 - 2013-08-20 02:00 - 00000504 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job 2013-08-20 01:08 - 2013-08-20 01:08 - 00003570 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb 2013-08-20 01:07 - 2013-08-20 01:07 - 00001808 _____ C:\Users\RA\Desktop\SUPERAntiSpyware Professional.lnk 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-08-19 16:44 - 2013-08-19 16:44 - 00000000 ____D C:\Users\RA\AppData\Roaming\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-19 16:43 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-19 16:36 - 2013-08-19 13:54 - 27088288 _____ (SUPERAntiSpyware) C:\Users\RA\Desktop\SUPERAntiSpywarePro.exe 2013-08-19 15:48 - 2013-08-19 15:48 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2013-08-15 19:54 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 19:54 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 19:54 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 19:54 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 19:54 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 19:54 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 19:54 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 19:54 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 19:54 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 19:54 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 19:54 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 19:54 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 19:39 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 19:39 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-15 19:39 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 19:39 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 19:39 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-15 19:39 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-15 19:38 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-15 19:38 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-15 19:38 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 19:38 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 19:38 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-15 19:38 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-15 19:38 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-15 19:38 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-15 19:38 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-15 19:38 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-15 19:38 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-15 19:38 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-15 19:38 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-15 19:38 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-15 19:35 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-11 12:04 - 2013-08-11 12:04 - 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-08-11 09:34 - 2013-08-11 09:34 - 37722096 _____ C:\Users\RA\Desktop\Unbenannt_HDR2.psd 2013-08-11 09:33 - 2013-08-11 09:33 - 120030172 _____ C:\Users\RA\Desktop\Unbenannt_HDR3.psd 2013-08-07 21:40 - 2013-08-07 21:40 - 00000000 ____D C:\Users\RA\Desktop\Flyer 2013-08-03 23:28 - 2013-08-03 23:29 - 00000000 ____D C:\Program Files (x86)\SetEdit8500 2013-08-02 18:51 - 2013-08-02 18:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Google 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\Software 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\NikLicenseFiles 2013-08-02 18:26 - 2013-08-20 16:51 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-02 18:26 - 2013-08-20 16:36 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-02 18:26 - 2013-08-02 18:31 - 00004098 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-02 18:26 - 2013-08-02 18:31 - 00003846 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-02 18:26 - 2013-08-02 18:27 - 00000000 ____D C:\Users\RA\AppData\Local\Google 2013-08-02 18:26 - 2013-08-02 18:27 - 00000000 ____D C:\ProgramData\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-02 00:26 - 2013-08-02 00:26 - 00000000 ____D C:\Users\RA\Desktop\HAUS 2013-07-29 23:23 - 2013-07-29 23:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\WTablet 2013-07-26 09:45 - 2013-07-26 09:45 - 00133976 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00062808 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\TabletPlugins 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\Tablet 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files (x86)\TabletPlugins 2013-07-26 09:36 - 2013-06-06 19:31 - 01959192 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01952536 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01820952 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01817880 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01614104 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01606936 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01493272 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01489176 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll 2013-07-26 09:36 - 2013-04-30 19:18 - 00085304 _____ (Wacom Technology) C:\Windows\system32\Drivers\wachidrouter.sys 2013-07-26 09:36 - 2013-04-30 19:18 - 00014136 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys 2013-07-26 09:36 - 2012-12-21 00:20 - 00015344 _____ (Wacom Technology) C:\Windows\system32\Drivers\wacomrouterfilter.sys 2013-07-25 21:29 - 2013-07-25 21:29 - 00000000 ____D C:\Users\RA\Desktop\ProcessExplorer 2013-07-25 21:09 - 2013-07-25 21:38 - 00000000 ____D C:\Windows\pss 2013-07-25 20:55 - 2013-07-25 20:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf 2013-07-25 12:03 - 2013-08-01 11:12 - 00000000 ____D C:\Users\RA\Desktop\Weierhof 2013-07-22 09:38 - 2013-07-22 09:38 - 00000000 ____D C:\ProgramData\RIBS ==================== One Month Modified Files and Folders ======= 2013-08-20 16:59 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-20 16:59 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-20 16:56 - 2012-10-27 08:18 - 00000010 _____ C:\Users\RA\AppData\Local\.56C369H5-8CEH-20F1-75G2-452FC2FCCD50 2013-08-20 16:56 - 2012-10-27 08:18 - 00000010 _____ C:\ProgramData\.93067BD7-6BGG-312E-86F3-566EB31BBC4E 2013-08-20 16:54 - 2012-10-26 21:53 - 00000000 ____D C:\Users\RA\AppData\Local\Adobe 2013-08-20 16:53 - 2012-10-30 14:50 - 00000000 ____D C:\Users\RA\AppData\Roaming\Dropbox 2013-08-20 16:51 - 2013-08-02 18:26 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-20 16:51 - 2012-10-31 20:12 - 00000000 ____D C:\jexepackres 2013-08-20 16:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-20 16:48 - 2013-05-17 17:44 - 00016941 _____ C:\Windows\setupact.log 2013-08-20 16:48 - 2012-11-15 19:07 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-20 16:47 - 2012-10-26 20:20 - 01653866 _____ C:\Windows\WindowsUpdate.log 2013-08-20 16:46 - 2013-08-20 16:33 - 00000000 ____D C:\AdwCleaner 2013-08-20 16:36 - 2013-08-02 18:26 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-20 16:29 - 2013-08-20 12:07 - 00000000 ____D C:\Users\RA\Desktop\Scan 2013-08-20 15:37 - 2013-05-17 17:43 - 00196498 _____ C:\Windows\PFRO.log 2013-08-20 15:37 - 2012-10-26 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-20 15:34 - 2013-08-20 13:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-20 15:32 - 2013-08-20 15:32 - 00018312 _____ C:\ComboFix.txt 2013-08-20 15:32 - 2013-08-20 15:04 - 00000000 ____D C:\Qoobox 2013-08-20 15:32 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-20 15:29 - 2013-08-20 15:03 - 00000000 ____D C:\Windows\erdnt 2013-08-20 15:28 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-20 13:58 - 2013-08-20 13:58 - 00052647 _____ C:\Users\RA\Desktop\FRST-1.txt 2013-08-20 13:58 - 2013-08-20 13:57 - 00023039 _____ C:\Users\RA\Desktop\Addition-1.txt 2013-08-20 13:38 - 2013-08-20 13:38 - 00000000 ____D C:\FRST 2013-08-20 13:37 - 2013-08-20 13:37 - 00000000 ____D C:\Users\RA\Desktop\FontDoctor-2-6-1 2013-08-20 13:09 - 2012-10-26 23:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-20 12:52 - 2013-08-20 12:52 - 00000000 ____D C:\Program Files\7-Zip 2013-08-20 12:18 - 2013-08-20 12:18 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-08-20 12:18 - 2013-08-20 12:18 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-20 12:18 - 2013-08-20 12:18 - 00000000 ____D C:\Program Files\CCleaner 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\rsit 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\Program Files (x86)\trend micro 2013-08-20 11:53 - 2013-08-20 11:53 - 00000217 _____ C:\Users\RA\Desktop\impressum.URL 2013-08-20 11:53 - 2013-08-20 11:53 - 00000198 _____ C:\Users\RA\Desktop\Meschert Elektro-Technik GbR » Hier entsteht die Website der Meschert Elektro-Technik GbR.URL 2013-08-20 11:53 - 2012-11-08 15:31 - 00000000 ____D C:\Users\RA\AppData\Local\CrashDumps 2013-08-20 11:49 - 2013-08-20 11:49 - 00001139 _____ C:\Users\Public\Desktop\Trojan Remover.lnk 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\Documents\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\AppData\Roaming\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\ProgramData\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2013-08-20 09:48 - 2013-08-20 09:48 - 00000242 _____ C:\Users\RA\Desktop\Formular-Management-System der Bundesfinanzverwaltung (Fragebogen zur steuerlichen Erfassung Aufnahme einer gewerblichen, se.URL 2013-08-20 02:00 - 2013-08-20 01:08 - 00000504 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job 2013-08-20 01:45 - 2013-08-20 13:38 - 01576196 _____ (Farbar) C:\Users\RA\Desktop\FRST64.exe 2013-08-20 01:08 - 2013-08-20 01:08 - 00003570 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb 2013-08-20 01:07 - 2013-08-20 01:07 - 00001808 _____ C:\Users\RA\Desktop\SUPERAntiSpyware Professional.lnk 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-08-19 20:13 - 2013-08-20 15:01 - 05106564 ____R (Swearware) C:\Users\RA\Desktop\ComboFix.exe 2013-08-19 16:44 - 2013-08-19 16:44 - 00000000 ____D C:\Users\RA\AppData\Roaming\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-19 15:48 - 2013-08-19 15:48 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2013-08-19 13:54 - 2013-08-19 16:36 - 27088288 _____ (SUPERAntiSpyware) C:\Users\RA\Desktop\SUPERAntiSpywarePro.exe 2013-08-15 22:29 - 2013-06-18 00:41 - 00128440 _____ C:\Users\RA\Documents\500pxPublisher.log 2013-08-15 19:51 - 2012-10-31 12:43 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-15 19:48 - 2013-07-11 14:14 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 19:44 - 2012-11-09 20:20 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-13 01:13 - 2013-04-19 21:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\vlc 2013-08-13 00:19 - 2013-05-04 01:06 - 00000000 ____D C:\Users\RA\Desktop\[[ SORT ]] 2013-08-13 00:18 - 1970-02-28 23:31 - 00000000 ____D C:\Users\RA\Desktop\CASTLE ___ 2013-07- 2013-08-11 12:04 - 2013-08-11 12:04 - 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-08-11 09:34 - 2013-08-11 09:34 - 37722096 _____ C:\Users\RA\Desktop\Unbenannt_HDR2.psd 2013-08-11 09:33 - 2013-08-11 09:33 - 120030172 _____ C:\Users\RA\Desktop\Unbenannt_HDR3.psd 2013-08-11 09:02 - 2012-10-26 23:09 - 00000000 ____D C:\Users\RA\AppData\Local\Thunderbird 2013-08-07 21:40 - 2013-08-07 21:40 - 00000000 ____D C:\Users\RA\Desktop\Flyer 2013-08-07 20:24 - 2013-06-27 14:04 - 00000000 ____D C:\Users\RA\Desktop\WordPress- 2013-08-07 17:03 - 2012-11-01 02:33 - 00000000 ____D C:\Users\RA\AppData\Roaming\FileZilla 2013-08-03 23:29 - 2013-08-03 23:28 - 00000000 ____D C:\Program Files (x86)\SetEdit8500 2013-08-03 21:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-02 20:13 - 2013-02-07 10:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Mp3tag 2013-08-02 18:51 - 2013-08-02 18:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Google 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\Software 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\NikLicenseFiles 2013-08-02 18:31 - 2013-08-02 18:26 - 00004098 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-02 18:31 - 2013-08-02 18:26 - 00003846 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-02 18:27 - 2013-08-02 18:26 - 00000000 ____D C:\Users\RA\AppData\Local\Google 2013-08-02 18:27 - 2013-08-02 18:26 - 00000000 ____D C:\ProgramData\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-02 17:25 - 2012-10-26 20:22 - 00000000 ____D C:\Users\RA\AppData\Local\VirtualStore 2013-08-02 11:27 - 2012-11-15 21:55 - 00000000 ____D C:\Users\RA\Documents\theRenamer 2013-08-02 00:26 - 2013-08-02 00:26 - 00000000 ____D C:\Users\RA\Desktop\HAUS 2013-08-01 11:12 - 2013-07-25 12:03 - 00000000 ____D C:\Users\RA\Desktop\Weierhof 2013-07-31 10:58 - 2012-11-09 09:50 - 00000000 ____D C:\Users\RA\AppData\Roaming\iFunbox_UserCache 2013-07-30 14:55 - 2012-10-29 11:03 - 00001456 _____ C:\Users\RA\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2013-07-30 11:31 - 2013-01-23 11:10 - 00000000 ____D C:\Users\RA\AppData\Roaming\Skype 2013-07-29 23:23 - 2013-07-29 23:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\WTablet 2013-07-29 11:20 - 2013-07-15 14:05 - 00000000 ____D C:\Users\RA\Desktop\[GRÜNDUNG] 2013-07-26 09:45 - 2013-07-26 09:45 - 00133976 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00062808 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2013-07-26 09:45 - 2012-10-26 22:52 - 00000000 ____D C:\ProgramData\G DATA 2013-07-26 09:43 - 2012-10-26 22:52 - 00000000 ____D C:\Program Files (x86)\G Data 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\TabletPlugins 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\Tablet 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files (x86)\TabletPlugins 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com 2013-07-26 09:30 - 2012-10-26 20:22 - 00000000 ___RD C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-26 07:13 - 2013-08-15 19:54 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-15 19:54 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-15 19:54 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-15 19:54 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-15 19:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-15 19:54 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-15 19:54 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-15 19:54 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-15 19:54 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-15 19:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-15 19:54 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-15 19:54 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 21:38 - 2013-07-25 21:09 - 00000000 ____D C:\Windows\pss 2013-07-25 21:29 - 2013-07-25 21:29 - 00000000 ____D C:\Users\RA\Desktop\ProcessExplorer 2013-07-25 20:55 - 2013-07-25 20:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf 2013-07-25 15:45 - 2013-08-20 09:22 - 23334896 _____ (Simply Super Software ) C:\Users\RA\Desktop\trjsetup_688.exe 2013-07-25 11:58 - 2013-03-27 11:12 - 00000000 ___RD C:\Users\RA\Desktop\facebook 2013-07-25 11:25 - 2013-08-15 19:38 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-15 19:38 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 22:27 - 2012-10-26 22:21 - 00187400 _____ C:\Users\RA\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-24 22:25 - 2009-07-14 06:45 - 06132088 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-23 16:17 - 2012-10-26 21:57 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-23 16:02 - 2012-10-26 21:58 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-23 16:00 - 2012-10-26 21:58 - 00000000 ____D C:\Program Files\Adobe 2013-07-23 14:55 - 2012-10-26 21:53 - 00000000 ____D C:\Users\RA\AppData\Roaming\Adobe 2013-07-23 12:57 - 2012-10-26 21:54 - 00000000 ____D C:\ProgramData\Adobe 2013-07-23 12:31 - 2012-10-26 20:21 - 00000000 ____D C:\Users\RA 2013-07-22 11:45 - 2012-10-26 23:29 - 00000000 ____D C:\Users\RA\AppData\Roaming\Apple Computer 2013-07-22 11:41 - 2012-10-26 23:21 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-22 11:36 - 2013-08-20 11:51 - 00000761 _____ C:\Windows\system32\Drivers\etc\hosts.trb 2013-07-22 09:38 - 2013-07-22 09:38 - 00000000 ____D C:\ProgramData\RIBS ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-05 12:47 ==================== End Of Log ============================ --- --- --- und Addition.txt (war dieses Mal nicht aktiv, habe ich dann aktiviert, oder war das unnötig? Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-08-2013 03 Ran by RA at 2013-08-20 17:01:25 Running from C:\Users\RA\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 64 Bit HP CIO Components Installer (Version: 13.2.1) 7-Zip 9.30 (x64 edition) (Version: Adobe Acrobat XI Pro (x32 Version: 11.0) Adobe Acrobat XI Pro (x32 Version: 11.0.02) Adobe After Effects CC (x32 Version: 12) Adobe AIR (x32 Version: Adobe Bridge CC (64 Bit) (x32 Version: 6.0) Adobe Connect 9 Add-in (HKCU Version: 11,2,381,0) Adobe Creative Cloud (x32 Version: Adobe Download Assistant (x32 Version: 1.2.3) Adobe Dreamweaver CC (x32 Version: 13) Adobe Edge Animate (x32 Version: 1.5) Adobe Edge Animate CC (x32 Version: 2.0) Adobe Edge Code CC (x32 Version: 0.94) Adobe Edge Inspect CC (x32 Version: 1.0.408) Adobe Edge Reflow CC Preview (x32 Version: 0.23.10993) Adobe Exchange Panel (x32 Version: 1) Adobe ExtendScript Toolkit CC (x32 Version: Adobe Extension Manager CC (x32 Version: 7.1) Adobe Flash Builder 4.7 (64 Bit) (x32 Version: 4.7) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Flash Professional CC (x32 Version: 13.0) Adobe Help Manager (x32 Version: 4.0.244) Adobe Illustrator CC (x32 Version: 17.0) Adobe InCopy CC (x32 Version: 9.0) Adobe InDesign CC (x32 Version: 9.0) Adobe Media Player (x32 Version: 1.8) Adobe Muse (x32 Version: 4.1) Adobe Muse (x32 Version: 4.1.8) Adobe Photoshop CC (x32 Version: 14.0) Adobe Photoshop Lightroom 4.2 64-bit (Version: 4.2.1) Adobe Photoshop Lightroom 5 64-bit (Version: 5.0.1) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Adobe Touch App Plugins (x32 Version: 1.0) Adobe Widget Browser (x32 Version: 2.0 Build 348) Adobe Widget Browser (x32 Version: 2.0.348) Adobe® Content Viewer (x32 Version: 3.2.0) Air Video Server 2.4.6-beta3 (x32 Version: 2.4.6-beta3) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: Apple Software Update (x32 Version: Attribute Changer 7.10c (x32 Version: 7.10c) Axialis IconWorkshop 6.33 (x32 Version: 6.33) Biet-O-Matic v2.14.12 (x32 Version: 2.14.12) bl (x32 Version: 1.0.0) BMWi-Businessplaner Gründung (x32 Version: 1.0.2) Bonjour (Version: Bonjour-Druckdienste (Version: Bonjour-Druckdienste (Version: Camtasia Studio 8 (x32 Version: Canon Auto Update Service (x32 Version: CANON iMAGE GATEWAY MyCamera Download Plugin (x32 Version: CANON iMAGE GATEWAY Task for ZoomBrowser EX (x32 Version: Canon MOV Decoder (x32 Version: Canon MOV Encoder (x32 Version: Canon MovieEdit Task for ZoomBrowser EX (x32 Version: Canon MP Navigator EX 1.0 (x32) Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX (x32 Version: Canon Utilities ZoomBrowser EX (x32 Version: Canon ZoomBrowser EX Memory Card Utility (x32 Version: CCleaner (Version: 4.04) CDDRV_Installer (Version: 4.24.15) Directory Lister Pro v1.49 (x32 Version: 1.49) DisplayFusion 5.0.1 (x32 Version: Dropbox (HKCU Version: 1.4.20) Evernote v. 4.6.7 (x32 Version: ExposurePlot 1.1.5a (x32) Extensis Suitcase Fusion 3 (x32 Version: 14.2.0) FileZilla Client (x32 Version: FreeStyle Auto-Assist (x32) G Data AntiVirus 2014 (x32 Version: GeoSetter 3.4.16 (x32) Google Update Helper (x32 Version: HandBrake 0.9.8 (x32 Version: 0.9.8) iFunbox (v2.0.2150.728), iFunbox DevTeam (x32 Version: v2.0.2150.728) ipswDownloader 1.6 (x32 Version: 1.6) iTunes (Version: Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: KhalInstallWrapper (Version: 4.24.99) K-Lite Codec Pack 5.2.0 (Full) (x32 Version: 5.2.0) Lightroom 5.0 (x32 Version: 5.0) Logitech SetPoint (x32 Version: 4.24) Malwarebytes Anti-Malware Version (x32 Version: MetroTwit (HKCU Version: Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) MozBackup 1.5.1 (x32) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7) Mp3tag v2.54 (x32 Version: v2.54) Nik Collection (x32 Version: Notepad++ (x32 Version: 6.2) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) or Autopano Giga 2.6 (Version: V2.6.4) PDF Settings CC (x32 Version: 12.0) ph (x32 Version: 1.0.0) PxMergeModule (x32 Version: 1.00.0000) QuickTime (x32 Version: Recuva (Version: 1.47) Safari (x32 Version: SilverFast CanonSDK 6.6.2r5 (x32) Skype™ 6.1 (x32 Version: 6.1.129) Spotify (HKCU Version: StreamTransport version: (x32) SUPERAntiSpyware (Version: 5.6.1032) TeamViewer 7 (x32 Version: 7.0.17271) theRenamer 7.58 (x32) Trojan Remover 6.8.8 (x32 Version: 6.8.8) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2768023) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817642) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (Version: 6.3.6w3) Webocton - Scriptly (x32 Version: WebTablet FB Plugin 32 bit (x32 Version: WebTablet FB Plugin 64 bit (Version: Yahoo! Detect (x32) ==================== Restore Points ========================= 07-08-2013 08:03:17 Windows Update 11-08-2013 06:54:33 Windows Update 15-08-2013 17:40:04 Windows Update 20-08-2013 08:48:31 Windows Update 20-08-2013 10:49:50 Installed 7-Zip 9.30 (x64 edition) ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-08-20 15:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05038D52-B7F7-447D-BB6D-BE3C3EE86462} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02] (Google Inc.) Task: {140FE688-9A46-4AC0-B53E-A7E8A374E5BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {16FD5339-9FD9-4F09-8B0D-C6676AE4E3EF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {23F1AC01-3095-418F-9C02-582777D023B9} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {69F0E039-1FAE-424B-989B-E3188B31AAD9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) Task: {6FBA5E25-A5ED-4CCA-8E58-975D0D3B67FB} - System32\Tasks\AdobeAAMUpdater-1.0-RA-PC-RA => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {7B1CA893-A231-4797-8D15-CF4F79DD3B59} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02] (Google Inc.) Task: {97C170EF-50DF-487B-9CF2-642BD30531A0} - System32\Tasks\AdobeAAMUpdater-1.0-RA-PC-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {D512B88E-1481-4F38-B816-DC8334646AD7} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {D600E553-C31B-44A2-9D11-FC5232A38A45} - System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/20/2013 11:53:05 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Rmvtrjan.exe, Version:, Zeitstempel: 0x51e96b81 Name des fehlerhaften Moduls: USER32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba59 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001872e ID des fehlerhaften Prozesses: 0x68c Startzeit der fehlerhaften Anwendung: 0xRmvtrjan.exe0 Pfad der fehlerhaften Anwendung: Rmvtrjan.exe1 Pfad des fehlerhaften Moduls: Rmvtrjan.exe2 Berichtskennung: Rmvtrjan.exe3 Error: (08/19/2013 04:02:34 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: mmc.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc808 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b8479b Ausnahmecode: 0x00000000 Fehleroffset: 0x0000000000009e5d ID des fehlerhaften Prozesses: 0x91c Startzeit der fehlerhaften Anwendung: 0xmmc.exe0 Pfad der fehlerhaften Anwendung: mmc.exe1 Pfad des fehlerhaften Moduls: mmc.exe2 Berichtskennung: mmc.exe3 Error: (08/15/2013 09:41:09 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2bcac Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000003c010 ID des fehlerhaften Prozesses: 0xf68 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/13/2013 00:47:56 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: StreamTransport.exe, Version:, Zeitstempel: 0x2a425e19 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0x0eedfade Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x1c80 Startzeit der fehlerhaften Anwendung: 0xStreamTransport.exe0 Pfad der fehlerhaften Anwendung: StreamTransport.exe1 Pfad des fehlerhaften Moduls: StreamTransport.exe2 Berichtskennung: StreamTransport.exe3 Error: (08/11/2013 04:59:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MediaCoreIF.DLL, Version:, Zeitstempel: 0x51a64846 Ausnahmecode: 0xc000041d Fehleroffset: 0x0000000000201ac8 ID des fehlerhaften Prozesses: 0x1ab4 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/11/2013 04:51:15 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MediaCoreIF.DLL, Version:, Zeitstempel: 0x51a64846 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000201ac8 ID des fehlerhaften Prozesses: 0x1ab4 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/11/2013 04:01:23 PM) (Source: Application Hang) (User: ) Description: Programm lightroom.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 14d0 Startzeit: 01ce969a7edab799 Endzeit: 79 Anwendungspfad: C:\Program Files\Adobe\Adobe Photoshop Lightroom 5\lightroom.exe Berichts-ID: 7dbd60e1-028e-11e3-8bf0-0007ca045fc4 Error: (08/11/2013 03:53:37 PM) (Source: Application Hang) (User: ) Description: Programm lightroom.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 17cc Startzeit: 01ce96791c0d6338 Endzeit: 4120 Anwendungspfad: C:\Program Files\Adobe\Adobe Photoshop Lightroom 5\lightroom.exe Berichts-ID: 556d243a-028d-11e3-8bf0-0007ca045fc4 Error: (08/07/2013 10:02:07 AM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (08/07/2013 10:02:07 AM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=3800} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (08/20/2013 04:51:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 04:51:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/20/2013 03:40:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 03:40:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/20/2013 03:28:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/20/2013 03:27:28 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (08/20/2013 03:23:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/20/2013 01:04:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 01:04:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/19/2013 03:53:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-08-20 15:27:28.559 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-08-20 15:27:28.434 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 4094.49 MB Available physical RAM: 1813.04 MB Total Pagefile: 8187.17 MB Available Pagefile: 5253.28 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:298.09 GB) (Free:136.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (MUSIK) (Fixed) (Total:200.2 GB) (Free:95.84 GB) NTFS Drive e: (ARBEIT) (Fixed) (Total:74.53 GB) (Free:43.7 GB) NTFS Drive f: (PRIVAT) (Fixed) (Total:100.59 GB) (Free:71.3 GB) NTFS Drive g: (RAM) (Fixed) (Total:50.29 GB) (Free:50.16 GB) NTFS Drive h: (FONTS) (Fixed) (Total:114.68 GB) (Free:105.77 GB) NTFS Drive o: (My Book) (Fixed) (Total:931.28 GB) (Free:349.63 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 8D33E5C1) Partition 1: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=101 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=115 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D578C98E) Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 75 GB) (Disk ID: B5495A2E) Partition 1: (Not Active) - (Size=75 GB) - (Type=07 NTFS) ======================================================== Disk: 7 (Size: 932 GB) (Disk ID: E8900690) Partition 1: (Not Active) - (Size=932 GB) - (Type=0C) ==================== End Of Log ============================ Sooo, hoffe der Schritt hat uns weiter gen Ziel geführt... ![]() Geändert von asparagus (20.08.2013 um 16:05 Uhr) |
![]() | #10 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner?ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #11 |
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Hallo Schrauber, so, hier wieder meine nächsten Logs... Der ESET-Log Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=77c3eb16880d6446a561a7b0870eef69 # engine=14842 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-20 09:36:49 # local_time=2013-08-20 11:36:49 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 46053 128664459 0 0 # scanned=1010927 # found=0 # cleaned=0 # scan_time=21251 Der Security Check Log: Code:
ATTFilter Results of screen317's Security Check version 0.99.72 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` G Data AntiVirus 2014 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Trojan Remover 6.8.8 Malwarebytes Anti-Malware Version Java 7 Update 25 Adobe Flash Player 11.7.700.224 Adobe Reader XI Mozilla Firefox (23.0.1) Mozilla Thunderbird (17.0.7) ````````Process Check: objlist.exe by Laurent```````` G Data AntiVirus AVK AVKWCtlx64.exe G Data AntiVirus AVK AVKService.exe G Data AntiVirus AVKTray AVKTray.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-08-2013 05 Ran by RA (administrator) on 20-08-2013 23:54:51 Running from C:\Users\RA\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe (Logitech Inc.) C:\Program Files\Logitech\SetPoint\LBTWiz.exe (Celartem, Inc., doing business as Extensis.) C:\Program Files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe () C:\Program Files (x86)\i-Funbox DevTeam\ifb_conn.exe (Spotify Ltd) C:\Users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Abbott Diabetes Care) C:\Program Files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Windows\splwow64.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe () C:\Users\RA\Desktop\SecurityCheck.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Kernel and Hardware Abstraction Layer] - C:\Windows\KHALMNPR.EXE [134160 2007-09-21] (Logitech, Inc.) HKLM\...\Run: [Bluetooth Connection Assistant] - LBTWIZ.EXE -silent [x] HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKCU\...\Run: [FMCore.exe] - C:\Program Files (x86)\Extensis\Suitcase Fusion 3\FMCore.exe [9211392 2011-10-27] (Celartem, Inc., doing business as Extensis.) HKCU\...\Run: [DisplayFusion] - C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [7283072 2013-04-26] (Binary Fortress Software) HKCU\...\Run: [iFunBoxConnector] - C:\Program Files (x86)\i-Funbox DevTeam\ifb_conn.exe [812544 2013-04-23] () HKCU\...\Run: [AirVideoServer] - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe [4935112 2012-07-20] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\RA\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-06-26] (Spotify Ltd) HKCU\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6581488 2013-08-15] (SUPERAntiSpyware) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [G Data ASM] - C:\Program Files (x86)\G Data\AntiVirus\DelayLoader\AutorunDelayLoader.exe [472016 2013-02-25] (G Data Software AG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-08-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478752 2012-12-18] (Adobe Systems Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.) HKLM-x32\...\Run: [G Data AntiVirus Tray] - C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe [1444304 2013-02-25] (G Data Software AG) HKLM-x32\...\Run: [TrojanScanner] - C:\Program Files (x86)\Trojan Remover\Trjscan.exe [1655568 2013-07-19] (Simply Super Software) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FreeStyle Auto-Assist.lnk ShortcutTarget: FreeStyle Auto-Assist.lnk -> C:\Program Files (x86)\Abbott Diabetes Care\FreeStyle Auto-Assist\BGTrayApp.exe (Abbott Diabetes Care) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\RA\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) Startup: C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk ShortcutTarget: EvernoteTray.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) BHO-x32: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default FF Homepage: www.google.de|hxxp://www.creative-nonstop.com/|hxxp://www.existenzgruender.de/selbstaendigkeit/vorbereitung/index.php|hxxp://www.s354533063.website-start.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF SearchPlugin: C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\searchplugins\rapidshare-filefinder.xml FF Extension: Pocket - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\isreaditlater@ideashower.com FF Extension: Flash and Video Download - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} FF Extension: Bitdefender QuickScan - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} FF Extension: Evernote Web Clipper - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} FF Extension: amznUWL2 - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\amznUWL2@amazon.com.xpi FF Extension: artur.dubovoy - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\artur.dubovoy@gmail.com.xpi FF Extension: autofillForms - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\autofillForms@blueimp.net.xpi FF Extension: checkin - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\checkin@my4squarealibi.com.xpi FF Extension: duplicate-this-tab - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\duplicate-this-tab@mozilla.org.xpi FF Extension: exif_viewer - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\exif_viewer@mozilla.doslash.org.xpi FF Extension: firebug - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: fireform - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\fireform@mozilla.org.xpi FF Extension: firefox - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\firefox@red-cog.com.xpi FF Extension: HighlightedTextToFile - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\HighlightedTextToFile@bobbyrne01.org.xpi FF Extension: jid0-4deOYiOeBrYfBB9hS3xTnGoKZC4 - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\jid0-4deOYiOeBrYfBB9hS3xTnGoKZC4@jetpack.xpi FF Extension: picbrowser - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\picbrowser@iodragon.com.xpi FF Extension: readability - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\readability@readability.com.xpi FF Extension: rsDownloader - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\rsDownloader@163.com.xpi FF Extension: snaplinks - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\snaplinks@snaplinks.mozdev.org.xpi FF Extension: testpilot - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\testpilot@labs.mozilla.com.xpi FF Extension: tineye - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\tineye@ideeinc.com.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{5546F97E-11A5-46b0-9082-32AD74AAA920}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{6140bbfd-aa20-11e1-aba7-109add603214}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{62b958b4-9962-4fc2-9983-01a9a42d6f2d}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{791DB184-BFBA-11DA-9C61-0638DF403F48}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{9fb7d178-155a-4318-9173-1a8eaaea7fe4}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{a1109c2a-1187-4027-901d-13097b755625}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{B347DFB4-AC21-11DD-9016-B77D55D89593}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{cd6c4ebf-366e-45a0-98b5-b8217288eed7}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{ce7e73df-6a44-4028-8079-5927a588c948}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi FF Extension: No Name - C:\Users\RA\AppData\Roaming\Mozilla\Firefox\Profiles\yqgjc3vf.default\Extensions\{FCAB6FDD-5585-425b-95C1-5ED856F3FD08}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn ==================== Services (Whitelisted) ================= R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143120 2013-05-23] (SUPERAntiSpyware.com) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1956304 2013-03-04] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [635344 2013-02-25] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe [2249944 2013-02-25] (G Data Software AG) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [1498000 2013-04-26] (Binary Fortress Software) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [696808 2013-02-25] (G Data Software AG) R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [598808 2013-06-06] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-07-26] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [133976 2013-07-26] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [62808 2013-07-26] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-07-26] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-08-19] (G Data Software) R1 GRD; C:\Windows\system32\drivers\GRD.sys [107128 2013-08-19] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [64856 2013-07-26] (G Data Software AG) R3 PRISM_A00; C:\Windows\System32\DRIVERS\PRISMA00.sys [407136 2009-10-27] (Conexant Systems, Inc.) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-20 23:49 - 2013-08-20 23:49 - 00000903 _____ C:\Users\RA\Desktop\checkup.txt 2013-08-20 23:40 - 2013-08-20 23:40 - 00891115 _____ C:\Users\RA\Desktop\SecurityCheck.exe 2013-08-20 18:14 - 2013-08-20 18:14 - 00000000 ____D C:\Users\RA\Desktop\LRTimelapse3.1_win 2013-08-20 17:41 - 2013-04-04 14:07 - 02347384 _____ (ESET) C:\Users\RA\Desktop\esetsmartinstaller_enu.exe 2013-08-20 17:01 - 2013-08-20 17:01 - 00054290 _____ C:\Users\RA\Desktop\FRST-2.txt 2013-08-20 17:01 - 2013-08-20 17:01 - 00024236 _____ C:\Users\RA\Desktop\Addition-2.txt 2013-08-20 16:33 - 2013-08-20 16:46 - 00000000 ____D C:\AdwCleaner 2013-08-20 15:32 - 2013-08-20 15:32 - 00018312 _____ C:\ComboFix.txt 2013-08-20 15:09 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-20 15:09 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-20 15:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-20 15:09 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-20 15:04 - 2013-08-20 15:32 - 00000000 ____D C:\Qoobox 2013-08-20 15:03 - 2013-08-20 15:29 - 00000000 ____D C:\Windows\erdnt 2013-08-20 15:01 - 2013-08-19 20:13 - 05106564 ____R (Swearware) C:\Users\RA\Desktop\ComboFix.exe 2013-08-20 13:58 - 2013-08-20 13:58 - 00052647 _____ C:\Users\RA\Desktop\FRST-1.txt 2013-08-20 13:57 - 2013-08-20 13:58 - 00023039 _____ C:\Users\RA\Desktop\Addition-1.txt 2013-08-20 13:38 - 2013-08-20 13:38 - 00000000 ____D C:\FRST 2013-08-20 13:37 - 2013-08-20 13:37 - 00000000 ____D C:\Users\RA\Desktop\FontDoctor-2-6-1 2013-08-20 13:08 - 2013-08-20 15:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-20 12:52 - 2013-08-20 12:52 - 00000000 ____D C:\Program Files\7-Zip 2013-08-20 12:18 - 2013-08-20 12:18 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-08-20 12:18 - 2013-08-20 12:18 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-20 12:18 - 2013-08-20 12:18 - 00000000 ____D C:\Program Files\CCleaner 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\rsit 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\Program Files (x86)\trend micro 2013-08-20 12:07 - 2013-08-20 16:29 - 00000000 ____D C:\Users\RA\Desktop\Scan 2013-08-20 11:53 - 2013-08-20 11:53 - 00000217 _____ C:\Users\RA\Desktop\impressum.URL 2013-08-20 11:53 - 2013-08-20 11:53 - 00000198 _____ C:\Users\RA\Desktop\Meschert Elektro-Technik GbR » Hier entsteht die Website der Meschert Elektro-Technik GbR.URL 2013-08-20 11:51 - 2013-07-22 11:36 - 00000761 _____ C:\Windows\system32\Drivers\etc\hosts.trb 2013-08-20 11:49 - 2013-08-20 11:49 - 00001139 _____ C:\Users\Public\Desktop\Trojan Remover.lnk 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\Documents\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\AppData\Roaming\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\ProgramData\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2013-08-20 09:22 - 2013-07-25 15:45 - 23334896 _____ (Simply Super Software ) C:\Users\RA\Desktop\trjsetup_688.exe 2013-08-20 01:08 - 2013-08-20 02:00 - 00000504 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job 2013-08-20 01:08 - 2013-08-20 01:08 - 00003570 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb 2013-08-20 01:07 - 2013-08-20 01:07 - 00001808 _____ C:\Users\RA\Desktop\SUPERAntiSpyware Professional.lnk 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-08-19 16:44 - 2013-08-19 16:44 - 00000000 ____D C:\Users\RA\AppData\Roaming\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-19 16:43 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-19 16:36 - 2013-08-19 13:54 - 27088288 _____ (SUPERAntiSpyware) C:\Users\RA\Desktop\SUPERAntiSpywarePro.exe 2013-08-19 15:48 - 2013-08-19 15:48 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2013-08-15 19:54 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 19:54 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 19:54 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 19:54 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 19:54 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 19:54 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 19:54 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 19:54 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 19:54 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 19:54 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 19:54 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 19:54 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 19:54 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 19:54 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-15 19:39 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-15 19:39 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-15 19:39 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-15 19:39 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-15 19:39 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-15 19:39 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-15 19:39 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-15 19:39 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-15 19:38 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-15 19:38 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-15 19:38 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-15 19:38 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-15 19:38 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-15 19:38 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-15 19:38 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-15 19:38 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-15 19:38 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-15 19:38 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-15 19:38 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-15 19:38 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-15 19:38 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-15 19:38 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-15 19:35 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-11 12:04 - 2013-08-11 12:04 - 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-08-11 09:34 - 2013-08-11 09:34 - 37722096 _____ C:\Users\RA\Desktop\Unbenannt_HDR2.psd 2013-08-11 09:33 - 2013-08-11 09:33 - 120030172 _____ C:\Users\RA\Desktop\Unbenannt_HDR3.psd 2013-08-07 21:40 - 2013-08-07 21:40 - 00000000 ____D C:\Users\RA\Desktop\Flyer 2013-08-03 23:28 - 2013-08-03 23:29 - 00000000 ____D C:\Program Files (x86)\SetEdit8500 2013-08-02 18:51 - 2013-08-02 18:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Google 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\Software 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\NikLicenseFiles 2013-08-02 18:26 - 2013-08-20 23:36 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-02 18:26 - 2013-08-20 18:36 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-02 18:26 - 2013-08-02 18:31 - 00004098 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-02 18:26 - 2013-08-02 18:31 - 00003846 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-02 18:26 - 2013-08-02 18:27 - 00000000 ____D C:\Users\RA\AppData\Local\Google 2013-08-02 18:26 - 2013-08-02 18:27 - 00000000 ____D C:\ProgramData\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-02 00:26 - 2013-08-02 00:26 - 00000000 ____D C:\Users\RA\Desktop\HAUS 2013-07-29 23:23 - 2013-07-29 23:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\WTablet 2013-07-26 09:45 - 2013-07-26 09:45 - 00133976 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00062808 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\TabletPlugins 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\Tablet 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files (x86)\TabletPlugins 2013-07-26 09:36 - 2013-06-06 19:31 - 01959192 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01952536 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01820952 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01817880 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01614104 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01606936 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01493272 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll 2013-07-26 09:36 - 2013-06-06 19:31 - 01489176 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll 2013-07-26 09:36 - 2013-04-30 19:18 - 00085304 _____ (Wacom Technology) C:\Windows\system32\Drivers\wachidrouter.sys 2013-07-26 09:36 - 2013-04-30 19:18 - 00014136 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys 2013-07-26 09:36 - 2012-12-21 00:20 - 00015344 _____ (Wacom Technology) C:\Windows\system32\Drivers\wacomrouterfilter.sys 2013-07-25 21:29 - 2013-07-25 21:29 - 00000000 ____D C:\Users\RA\Desktop\ProcessExplorer 2013-07-25 21:09 - 2013-07-25 21:38 - 00000000 ____D C:\Windows\pss 2013-07-25 20:55 - 2013-07-25 20:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf 2013-07-25 12:03 - 2013-08-01 11:12 - 00000000 ____D C:\Users\RA\Desktop\Weierhof 2013-07-22 09:38 - 2013-07-22 09:38 - 00000000 ____D C:\ProgramData\RIBS ==================== One Month Modified Files and Folders ======= 2013-08-20 23:49 - 2013-08-20 23:49 - 00000903 _____ C:\Users\RA\Desktop\checkup.txt 2013-08-20 23:40 - 2013-08-20 23:40 - 00891115 _____ C:\Users\RA\Desktop\SecurityCheck.exe 2013-08-20 23:36 - 2013-08-02 18:26 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-20 23:01 - 2013-08-20 23:52 - 01576210 _____ (Farbar) C:\Users\RA\Desktop\FRST64.exe 2013-08-20 18:36 - 2013-08-02 18:26 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-20 18:14 - 2013-08-20 18:14 - 00000000 ____D C:\Users\RA\Desktop\LRTimelapse3.1_win 2013-08-20 17:39 - 2012-10-31 20:12 - 00000000 ____D C:\jexepackres 2013-08-20 17:01 - 2013-08-20 17:01 - 00054290 _____ C:\Users\RA\Desktop\FRST-2.txt 2013-08-20 17:01 - 2013-08-20 17:01 - 00024236 _____ C:\Users\RA\Desktop\Addition-2.txt 2013-08-20 16:59 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-20 16:59 - 2009-07-14 06:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-20 16:56 - 2012-10-27 08:18 - 00000010 _____ C:\Users\RA\AppData\Local\.56C369H5-8CEH-20F1-75G2-452FC2FCCD50 2013-08-20 16:56 - 2012-10-27 08:18 - 00000010 _____ C:\ProgramData\.93067BD7-6BGG-312E-86F3-566EB31BBC4E 2013-08-20 16:55 - 2012-10-26 20:20 - 01653866 _____ C:\Windows\WindowsUpdate.log 2013-08-20 16:54 - 2012-10-26 21:53 - 00000000 ____D C:\Users\RA\AppData\Local\Adobe 2013-08-20 16:53 - 2012-10-30 14:50 - 00000000 ____D C:\Users\RA\AppData\Roaming\Dropbox 2013-08-20 16:49 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-20 16:48 - 2013-05-17 17:44 - 00016941 _____ C:\Windows\setupact.log 2013-08-20 16:48 - 2012-11-15 19:07 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-20 16:46 - 2013-08-20 16:33 - 00000000 ____D C:\AdwCleaner 2013-08-20 16:29 - 2013-08-20 12:07 - 00000000 ____D C:\Users\RA\Desktop\Scan 2013-08-20 15:37 - 2013-05-17 17:43 - 00196498 _____ C:\Windows\PFRO.log 2013-08-20 15:37 - 2012-10-26 20:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-20 15:34 - 2013-08-20 13:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-20 15:32 - 2013-08-20 15:32 - 00018312 _____ C:\ComboFix.txt 2013-08-20 15:32 - 2013-08-20 15:04 - 00000000 ____D C:\Qoobox 2013-08-20 15:32 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-20 15:29 - 2013-08-20 15:03 - 00000000 ____D C:\Windows\erdnt 2013-08-20 15:28 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-20 13:58 - 2013-08-20 13:58 - 00052647 _____ C:\Users\RA\Desktop\FRST-1.txt 2013-08-20 13:58 - 2013-08-20 13:57 - 00023039 _____ C:\Users\RA\Desktop\Addition-1.txt 2013-08-20 13:38 - 2013-08-20 13:38 - 00000000 ____D C:\FRST 2013-08-20 13:37 - 2013-08-20 13:37 - 00000000 ____D C:\Users\RA\Desktop\FontDoctor-2-6-1 2013-08-20 13:09 - 2012-10-26 23:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-20 12:52 - 2013-08-20 12:52 - 00000000 ____D C:\Program Files\7-Zip 2013-08-20 12:18 - 2013-08-20 12:18 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-08-20 12:18 - 2013-08-20 12:18 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-08-20 12:18 - 2013-08-20 12:18 - 00000000 ____D C:\Program Files\CCleaner 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\rsit 2013-08-20 12:09 - 2013-08-20 12:09 - 00000000 ____D C:\Program Files (x86)\trend micro 2013-08-20 11:53 - 2013-08-20 11:53 - 00000217 _____ C:\Users\RA\Desktop\impressum.URL 2013-08-20 11:53 - 2013-08-20 11:53 - 00000198 _____ C:\Users\RA\Desktop\Meschert Elektro-Technik GbR » Hier entsteht die Website der Meschert Elektro-Technik GbR.URL 2013-08-20 11:53 - 2012-11-08 15:31 - 00000000 ____D C:\Users\RA\AppData\Local\CrashDumps 2013-08-20 11:49 - 2013-08-20 11:49 - 00001139 _____ C:\Users\Public\Desktop\Trojan Remover.lnk 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\Documents\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Users\RA\AppData\Roaming\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\ProgramData\Simply Super Software 2013-08-20 11:49 - 2013-08-20 11:49 - 00000000 ____D C:\Program Files (x86)\Trojan Remover 2013-08-20 02:00 - 2013-08-20 01:08 - 00000504 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job 2013-08-20 01:08 - 2013-08-20 01:08 - 00003570 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb 2013-08-20 01:07 - 2013-08-20 01:07 - 00001808 _____ C:\Users\RA\Desktop\SUPERAntiSpyware Professional.lnk 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com 2013-08-20 01:07 - 2013-08-20 01:07 - 00000000 ____D C:\Program Files\SUPERAntiSpyware 2013-08-19 20:13 - 2013-08-20 15:01 - 05106564 ____R (Swearware) C:\Users\RA\Desktop\ComboFix.exe 2013-08-19 16:44 - 2013-08-19 16:44 - 00000000 ____D C:\Users\RA\AppData\Roaming\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-19 16:43 - 2013-08-19 16:43 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-19 15:48 - 2013-08-19 15:48 - 00107128 _____ (G Data Software) C:\Windows\system32\Drivers\GRD.sys 2013-08-19 13:54 - 2013-08-19 16:36 - 27088288 _____ (SUPERAntiSpyware) C:\Users\RA\Desktop\SUPERAntiSpywarePro.exe 2013-08-15 22:29 - 2013-06-18 00:41 - 00128440 _____ C:\Users\RA\Documents\500pxPublisher.log 2013-08-15 19:51 - 2012-10-31 12:43 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-15 19:48 - 2013-07-11 14:14 - 00000000 ____D C:\Windows\system32\MRT 2013-08-15 19:44 - 2012-11-09 20:20 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-13 01:13 - 2013-04-19 21:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\vlc 2013-08-13 00:19 - 2013-05-04 01:06 - 00000000 ____D C:\Users\RA\Desktop\[[ SORT ]] 2013-08-13 00:18 - 1970-02-28 23:31 - 00000000 ____D C:\Users\RA\Desktop\CASTLE ___ 2013-07- 2013-08-11 12:04 - 2013-08-11 12:04 - 00001297 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2013-08-11 09:34 - 2013-08-11 09:34 - 37722096 _____ C:\Users\RA\Desktop\Unbenannt_HDR2.psd 2013-08-11 09:33 - 2013-08-11 09:33 - 120030172 _____ C:\Users\RA\Desktop\Unbenannt_HDR3.psd 2013-08-11 09:02 - 2012-10-26 23:09 - 00000000 ____D C:\Users\RA\AppData\Local\Thunderbird 2013-08-07 21:40 - 2013-08-07 21:40 - 00000000 ____D C:\Users\RA\Desktop\Flyer 2013-08-07 20:24 - 2013-06-27 14:04 - 00000000 ____D C:\Users\RA\Desktop\WordPress- 2013-08-07 17:03 - 2012-11-01 02:33 - 00000000 ____D C:\Users\RA\AppData\Roaming\FileZilla 2013-08-03 23:29 - 2013-08-03 23:28 - 00000000 ____D C:\Program Files (x86)\SetEdit8500 2013-08-03 21:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-02 20:13 - 2013-02-07 10:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Mp3tag 2013-08-02 18:51 - 2013-08-02 18:51 - 00000000 ____D C:\Users\RA\AppData\Roaming\Google 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\Software 2013-08-02 18:37 - 2013-08-02 18:37 - 00000000 ____D C:\Users\RA\AppData\Local\NikLicenseFiles 2013-08-02 18:31 - 2013-08-02 18:26 - 00004098 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-02 18:31 - 2013-08-02 18:26 - 00003846 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-02 18:27 - 2013-08-02 18:26 - 00000000 ____D C:\Users\RA\AppData\Local\Google 2013-08-02 18:27 - 2013-08-02 18:26 - 00000000 ____D C:\ProgramData\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files\Google 2013-08-02 18:26 - 2013-08-02 18:26 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-02 17:25 - 2012-10-26 20:22 - 00000000 ____D C:\Users\RA\AppData\Local\VirtualStore 2013-08-02 11:27 - 2012-11-15 21:55 - 00000000 ____D C:\Users\RA\Documents\theRenamer 2013-08-02 00:26 - 2013-08-02 00:26 - 00000000 ____D C:\Users\RA\Desktop\HAUS 2013-08-01 11:12 - 2013-07-25 12:03 - 00000000 ____D C:\Users\RA\Desktop\Weierhof 2013-07-31 10:58 - 2012-11-09 09:50 - 00000000 ____D C:\Users\RA\AppData\Roaming\iFunbox_UserCache 2013-07-30 14:55 - 2012-10-29 11:03 - 00001456 _____ C:\Users\RA\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2013-07-30 11:31 - 2013-01-23 11:10 - 00000000 ____D C:\Users\RA\AppData\Roaming\Skype 2013-07-29 23:23 - 2013-07-29 23:23 - 00000000 ____D C:\Users\RA\AppData\Roaming\WTablet 2013-07-29 11:20 - 2013-07-15 14:05 - 00000000 ____D C:\Users\RA\Desktop\[GRÜNDUNG] 2013-07-26 09:45 - 2013-07-26 09:45 - 00133976 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00064856 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00062808 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2013-07-26 09:45 - 2013-07-26 09:45 - 00060248 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2013-07-26 09:45 - 2012-10-26 22:52 - 00000000 ____D C:\ProgramData\G DATA 2013-07-26 09:43 - 2012-10-26 22:52 - 00000000 ____D C:\Program Files (x86)\G Data 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\TabletPlugins 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files\Tablet 2013-07-26 09:36 - 2013-07-26 09:36 - 00000000 ____D C:\Program Files (x86)\TabletPlugins 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\Setup 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\oobe 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\MUI 2013-07-26 09:31 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\com 2013-07-26 09:30 - 2012-10-26 20:22 - 00000000 ___RD C:\Users\RA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-07-26 07:13 - 2013-08-15 19:54 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-15 19:54 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-15 19:54 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-15 19:54 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-15 19:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-15 19:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-15 19:54 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-15 19:54 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-15 19:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-15 19:54 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-15 19:54 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-15 19:54 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-15 19:54 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-15 19:54 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 21:38 - 2013-07-25 21:09 - 00000000 ____D C:\Windows\pss 2013-07-25 21:29 - 2013-07-25 21:29 - 00000000 ____D C:\Users\RA\Desktop\ProcessExplorer 2013-07-25 20:55 - 2013-07-25 20:55 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf 2013-07-25 15:45 - 2013-08-20 09:22 - 23334896 _____ (Simply Super Software ) C:\Users\RA\Desktop\trjsetup_688.exe 2013-07-25 11:58 - 2013-03-27 11:12 - 00000000 ___RD C:\Users\RA\Desktop\facebook 2013-07-25 11:25 - 2013-08-15 19:38 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-15 19:38 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 22:27 - 2012-10-26 22:21 - 00187400 _____ C:\Users\RA\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-24 22:25 - 2009-07-14 06:45 - 06132088 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-23 16:17 - 2012-10-26 21:57 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-23 16:02 - 2012-10-26 21:58 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-07-23 16:00 - 2012-10-26 21:58 - 00000000 ____D C:\Program Files\Adobe 2013-07-23 14:55 - 2012-10-26 21:53 - 00000000 ____D C:\Users\RA\AppData\Roaming\Adobe 2013-07-23 12:57 - 2012-10-26 21:54 - 00000000 ____D C:\ProgramData\Adobe 2013-07-23 12:31 - 2012-10-26 20:21 - 00000000 ____D C:\Users\RA 2013-07-22 11:45 - 2012-10-26 23:29 - 00000000 ____D C:\Users\RA\AppData\Roaming\Apple Computer 2013-07-22 11:41 - 2012-10-26 23:21 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2013-07-22 11:36 - 2013-08-20 11:51 - 00000761 _____ C:\Windows\system32\Drivers\etc\hosts.trb 2013-07-22 09:38 - 2013-07-22 09:38 - 00000000 ____D C:\ProgramData\RIBS ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-05 12:47 ==================== End Of Log ============================ und der Log Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-08-2013 05 Ran by RA at 2013-08-20 23:55:45 Running from C:\Users\RA\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 64 Bit HP CIO Components Installer (Version: 13.2.1) 7-Zip 9.30 (x64 edition) (Version: Adobe Acrobat XI Pro (x32 Version: 11.0) Adobe Acrobat XI Pro (x32 Version: 11.0.02) Adobe After Effects CC (x32 Version: 12) Adobe AIR (x32 Version: Adobe Bridge CC (64 Bit) (x32 Version: 6.0) Adobe Connect 9 Add-in (HKCU Version: 11,2,381,0) Adobe Creative Cloud (x32 Version: Adobe Download Assistant (x32 Version: 1.2.3) Adobe Dreamweaver CC (x32 Version: 13) Adobe Edge Animate (x32 Version: 1.5) Adobe Edge Animate CC (x32 Version: 2.0) Adobe Edge Code CC (x32 Version: 0.94) Adobe Edge Inspect CC (x32 Version: 1.0.408) Adobe Edge Reflow CC Preview (x32 Version: 0.23.10993) Adobe Exchange Panel (x32 Version: 1) Adobe ExtendScript Toolkit CC (x32 Version: Adobe Extension Manager CC (x32 Version: 7.1) Adobe Flash Builder 4.7 (64 Bit) (x32 Version: 4.7) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Flash Professional CC (x32 Version: 13.0) Adobe Help Manager (x32 Version: 4.0.244) Adobe Illustrator CC (x32 Version: 17.0) Adobe InCopy CC (x32 Version: 9.0) Adobe InDesign CC (x32 Version: 9.0) Adobe Media Player (x32 Version: 1.8) Adobe Muse (x32 Version: 4.1) Adobe Muse (x32 Version: 4.1.8) Adobe Photoshop CC (x32 Version: 14.0) Adobe Photoshop Lightroom 4.2 64-bit (Version: 4.2.1) Adobe Photoshop Lightroom 5 64-bit (Version: 5.0.1) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Adobe Touch App Plugins (x32 Version: 1.0) Adobe Widget Browser (x32 Version: 2.0 Build 348) Adobe Widget Browser (x32 Version: 2.0.348) Adobe® Content Viewer (x32 Version: 3.2.0) Air Video Server 2.4.6-beta3 (x32 Version: 2.4.6-beta3) Apple Application Support (x32 Version: 2.3.4) Apple Mobile Device Support (Version: Apple Software Update (x32 Version: Attribute Changer 7.10c (x32 Version: 7.10c) Axialis IconWorkshop 6.33 (x32 Version: 6.33) Biet-O-Matic v2.14.12 (x32 Version: 2.14.12) bl (x32 Version: 1.0.0) BMWi-Businessplaner Gründung (x32 Version: 1.0.2) Bonjour (Version: Bonjour-Druckdienste (Version: Bonjour-Druckdienste (Version: Camtasia Studio 8 (x32 Version: Canon Auto Update Service (x32 Version: CANON iMAGE GATEWAY MyCamera Download Plugin (x32 Version: CANON iMAGE GATEWAY Task for ZoomBrowser EX (x32 Version: Canon MOV Decoder (x32 Version: Canon MOV Encoder (x32 Version: Canon MovieEdit Task for ZoomBrowser EX (x32 Version: Canon MP Navigator EX 1.0 (x32) Canon Utilities EOS Video Snapshot Task for ZoomBrowser EX (x32 Version: Canon Utilities ZoomBrowser EX (x32 Version: Canon ZoomBrowser EX Memory Card Utility (x32 Version: CCleaner (Version: 4.04) CDDRV_Installer (Version: 4.24.15) Directory Lister Pro v1.49 (x32 Version: 1.49) DisplayFusion 5.0.1 (x32 Version: Dropbox (HKCU Version: 1.4.20) Evernote v. 4.6.7 (x32 Version: ExposurePlot 1.1.5a (x32) Extensis Suitcase Fusion 3 (x32 Version: 14.2.0) FileZilla Client (x32 Version: FreeStyle Auto-Assist (x32) G Data AntiVirus 2014 (x32 Version: GeoSetter 3.4.16 (x32) Google Update Helper (x32 Version: HandBrake 0.9.8 (x32 Version: 0.9.8) iFunbox (v2.0.2150.728), iFunbox DevTeam (x32 Version: v2.0.2150.728) ipswDownloader 1.6 (x32 Version: 1.6) iTunes (Version: Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: KhalInstallWrapper (Version: 4.24.99) K-Lite Codec Pack 5.2.0 (Full) (x32 Version: 5.2.0) Lightroom 5.0 (x32 Version: 5.0) Logitech SetPoint (x32 Version: 4.24) Malwarebytes Anti-Malware Version (x32 Version: MetroTwit (HKCU Version: Microsoft .NET Framework 4.5 (Version: 4.5.50709) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000) MozBackup 1.5.1 (x32) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7) Mp3tag v2.54 (x32 Version: v2.54) Nik Collection (x32 Version: Notepad++ (x32 Version: 6.2) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) or Autopano Giga 2.6 (Version: V2.6.4) PDF Settings CC (x32 Version: 12.0) ph (x32 Version: 1.0.0) PxMergeModule (x32 Version: 1.00.0000) QuickTime (x32 Version: Recuva (Version: 1.47) Safari (x32 Version: SilverFast CanonSDK 6.6.2r5 (x32) Skype™ 6.1 (x32 Version: 6.1.129) Spotify (HKCU Version: StreamTransport version: (x32) SUPERAntiSpyware (Version: 5.6.1032) TeamViewer 7 (x32 Version: 7.0.17271) theRenamer 7.58 (x32) Trojan Remover 6.8.8 (x32 Version: 6.8.8) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1) Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2768023) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817642) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (Version: 6.3.6w3) Webocton - Scriptly (x32 Version: WebTablet FB Plugin 32 bit (x32 Version: WebTablet FB Plugin 64 bit (Version: Yahoo! Detect (x32) ==================== Restore Points ========================= 07-08-2013 08:03:17 Windows Update 11-08-2013 06:54:33 Windows Update 15-08-2013 17:40:04 Windows Update 20-08-2013 08:48:31 Windows Update 20-08-2013 10:49:50 Installed 7-Zip 9.30 (x64 edition) ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-08-20 15:28 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05038D52-B7F7-447D-BB6D-BE3C3EE86462} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02] (Google Inc.) Task: {140FE688-9A46-4AC0-B53E-A7E8A374E5BD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {16FD5339-9FD9-4F09-8B0D-C6676AE4E3EF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-07-22] (Piriform Ltd) Task: {23F1AC01-3095-418F-9C02-582777D023B9} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {69F0E039-1FAE-424B-989B-E3188B31AAD9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) Task: {6FBA5E25-A5ED-4CCA-8E58-975D0D3B67FB} - System32\Tasks\AdobeAAMUpdater-1.0-RA-PC-RA => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {7B1CA893-A231-4797-8D15-CF4F79DD3B59} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-02] (Google Inc.) Task: {97C170EF-50DF-487B-9CF2-642BD30531A0} - System32\Tasks\AdobeAAMUpdater-1.0-RA-PC-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-13] (Adobe Systems Incorporated) Task: {D512B88E-1481-4F38-B816-DC8334646AD7} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: {D600E553-C31B-44A2-9D11-FC5232A38A45} - System32\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-05-23] (SUPERAdBlocker.com) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task ad271f93-4c21-4f84-9b12-b59263a2a0bb.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/20/2013 05:42:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/20/2013 05:41:10 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/20/2013 05:41:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/20/2013 05:41:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/20/2013 11:53:05 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Rmvtrjan.exe, Version:, Zeitstempel: 0x51e96b81 Name des fehlerhaften Moduls: USER32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba59 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001872e ID des fehlerhaften Prozesses: 0x68c Startzeit der fehlerhaften Anwendung: 0xRmvtrjan.exe0 Pfad der fehlerhaften Anwendung: Rmvtrjan.exe1 Pfad des fehlerhaften Moduls: Rmvtrjan.exe2 Berichtskennung: Rmvtrjan.exe3 Error: (08/19/2013 04:02:34 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: mmc.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc808 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b8479b Ausnahmecode: 0x00000000 Fehleroffset: 0x0000000000009e5d ID des fehlerhaften Prozesses: 0x91c Startzeit der fehlerhaften Anwendung: 0xmmc.exe0 Pfad der fehlerhaften Anwendung: mmc.exe1 Pfad des fehlerhaften Moduls: mmc.exe2 Berichtskennung: mmc.exe3 Error: (08/15/2013 09:41:09 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MSVCR100.dll, Version: 10.0.40219.325, Zeitstempel: 0x4df2bcac Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000003c010 ID des fehlerhaften Prozesses: 0xf68 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/13/2013 00:47:56 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: StreamTransport.exe, Version:, Zeitstempel: 0x2a425e19 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18015, Zeitstempel: 0x50b83c8a Ausnahmecode: 0x0eedfade Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x1c80 Startzeit der fehlerhaften Anwendung: 0xStreamTransport.exe0 Pfad der fehlerhaften Anwendung: StreamTransport.exe1 Pfad des fehlerhaften Moduls: StreamTransport.exe2 Berichtskennung: StreamTransport.exe3 Error: (08/11/2013 04:59:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MediaCoreIF.DLL, Version:, Zeitstempel: 0x51a64846 Ausnahmecode: 0xc000041d Fehleroffset: 0x0000000000201ac8 ID des fehlerhaften Prozesses: 0x1ab4 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 Error: (08/11/2013 04:51:15 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lightroom.exe, Version:, Zeitstempel: 0x51a64dae Name des fehlerhaften Moduls: MediaCoreIF.DLL, Version:, Zeitstempel: 0x51a64846 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000201ac8 ID des fehlerhaften Prozesses: 0x1ab4 Startzeit der fehlerhaften Anwendung: 0xlightroom.exe0 Pfad der fehlerhaften Anwendung: lightroom.exe1 Pfad des fehlerhaften Moduls: lightroom.exe2 Berichtskennung: lightroom.exe3 System errors: ============= Error: (08/20/2013 04:51:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 04:51:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/20/2013 03:40:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 03:40:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/20/2013 03:28:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/20/2013 03:27:28 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (08/20/2013 03:23:04 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/20/2013 01:04:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (08/20/2013 01:04:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (08/19/2013 03:53:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-08-20 15:27:28.559 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-08-20 15:27:28.434 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume1\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 62% Total physical RAM: 4094.49 MB Available physical RAM: 1528.46 MB Total Pagefile: 8187.17 MB Available Pagefile: 5610.45 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:298.09 GB) (Free:134.38 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (MUSIK) (Fixed) (Total:200.2 GB) (Free:95.84 GB) NTFS Drive e: (ARBEIT) (Fixed) (Total:74.53 GB) (Free:43.7 GB) NTFS Drive f: (PRIVAT) (Fixed) (Total:100.59 GB) (Free:71.3 GB) NTFS Drive g: (RAM) (Fixed) (Total:50.29 GB) (Free:50.16 GB) NTFS Drive h: (FONTS) (Fixed) (Total:114.68 GB) (Free:105.77 GB) NTFS Drive o: (My Book) (Fixed) (Total:931.28 GB) (Free:349.63 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 8D33E5C1) Partition 1: (Not Active) - (Size=200 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=101 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=115 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D578C98E) Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or Vista) (Size: 75 GB) (Disk ID: B5495A2E) Partition 1: (Not Active) - (Size=75 GB) - (Type=07 NTFS) ======================================================== Disk: 7 (Size: 932 GB) (Disk ID: E8900690) Partition 1: (Not Active) - (Size=932 GB) - (Type=0C) ==================== End Of Log ============================ Probleme? Keine mehr, hoffe das bleibt auch so! ![]() Bedanke mich erst mal ganz herzlich, sofern das Ganze damit abgeschlossen ist und wünsche viel Erfolg beim Studium! ![]() ![]() |
![]() | #12 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Fertig ![]() Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #13 |
| ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Hallo Schrauber! Hat leider ein wenig mit meiner Antwort gedauert... Habe deine restlichen Hinweise in der oben genannten Reihenfolge durchgeführt und mir auch die anderen Tipps und Hinweise zu Herzen genommen, bzw. die Programme installiert. Ich hoffe das hilft in Zukunft ![]() Möchte dir nochmal ganz, ganz herzlich für deine Hilfe und deine Mühe danken! Somit dürfte ja jetzt alles gesäubert sein. Also wieder ran ans "Schaffen" und den Zeitverlust aufholen. Hatte befürchtet, dass Vieles jetzt verloren sei. Werde mich nun mal um eine vernünftige Backup-Lösung bemühen... Nochmals vielen Dank und viel Erfolg beim Studium! Kannst dann, wenn von deiner Seite alles durch ist, den Thread schliessen... ![]() Ach so, habe ich eben ein wenig verwechselt, dein Abo beenden, Thread wird ja vermutlich nicht geschlossen, bzw. vom Admin, oder? ![]() |
![]() | #14 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? Thread bleibt offen, Abos behalt ich auch ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
Themen zu Massenemails über meinen Account, Trojaner oder Virus auf dem Rechner? |
acrobat update, bho, bonjour, browser, desktop, diagnostics, firefox, flash player, google, hijack, hijackthis, home, hängen, install.exe, installation, mozilla, msiexec.exe, plug-in, pup.pdfpasswordremover, realtek, registry, rootkit, senden, software, spotify web helper, svchost.exe, trojaner, virus, ändern |