![]() |
|
Log-Analyse und Auswertung: Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #3 |
| ![]() Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ Erstmal vielen Dank für die überaus schnelle Hilfe ... hier die 2.Runde an logfiles!
__________________Adw-Cleaner AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.000 - Report created 22/08/2013 at 11:50:44 # Updated 20/08/2013 by Xplode # Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Username : ***** - *****-PC # Running from : C:\Users\*****\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** Service Deleted : APNMCP ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\APN Folder Deleted : C:\ProgramData\AskPartnerNetwork Folder Deleted : C:\Program Files\AskPartnerNetwork Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Users\*****\AppData\Local\AskPartnerNetwork Folder Deleted : C:\Users\*****\AppData\Local\Conduit Folder Deleted : C:\Users\*****~1\AppData\Local\Temp\APN Folder Deleted : C:\Users\*****~1\AppData\Local\Temp\AskSearch Folder Deleted : C:\Users\*****\AppData\LocalLow\Conduit Folder Deleted : C:\Users\*****\AppData\LocalLow\BittorrentBar_DE Folder Deleted : C:\Users\*****\AppData\Roaming\software4u File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\searchplugins\MyStart Search.xml ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DC59CB47-3949-4A1D-9CE6-4C1B08BFA158} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BCE90EC8-E22B-4937-BC8A-DABBB43D963E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE90EC8-E22B-4937-BC8A-DABBB43D963E} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75286E2E-2323-470D-BE89-98243F5F1E62} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C4F0F66-E5A9-4C38-A8C4-9E18FC0FBAAE} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}] Key Deleted : HKCU\Software\AskPartnerNetwork Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\BittorrentBar_DE Key Deleted : HKLM\Software\AskPartnerNetwork Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\InstallIQ Key Deleted : HKLM\Software\BittorrentBar_DE Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [ Browsers ] ***** -\\ Internet Explorer v7.0.6002.18005 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\prefs.js ] Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\M[...] -\\ Google Chrome v28.0.1500.95 [ File : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [4790 octets] - [22/08/2013 11:50:10] AdwCleaner[S0].txt - [4473 octets] - [22/08/2013 11:50:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4533 octets] ########## JRT JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.3 (08.21.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by ***** on 22.08.2013 at 11:56:08,28 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2849855 ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [File] C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8oaiaztk.default\extensions\toolbar_avira-v7@apn.ask.com.xpi Emptied folder: C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8oaiaztk.default\minidumps [15 files] ~~~ Chrome Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 22.08.2013 at 11:58:14,48 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST (nummer 2) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-08-2013 02 Ran by ***** (administrator) on 22-08-2013 11:59:53 Running from C:\Users\*****\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hi-Rez Studios) D:\Games\HiPatchService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Dropbox, Inc.) C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2008-03-25] (Hewlett-Packard) HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [81920 2008-03-13] (Hewlett-Packard) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) MountPoints2: {48d89364-7ce5-11e2-9198-0021859e233c} - K:\launcher.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {4B2BCF1E-9A97-429B-8C52-3C93BE43DAAB} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" No File Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG) R2 HiPatchService; D:\Games\HiPatchService.exe [9216 2013-08-13] (Hi-Rez Studios) ==================== Drivers (Whitelisted) ==================== S4 ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [170000 2007-12-19] (AMD Technologies Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) S4 JRAID; C:\Windows\system32\drivers\jraid.sys [65024 2007-09-29] (JMicron Technology Corp.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-02-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH) S3 ALSysIO; \??\C:\Users\*****~1\AppData\Local\Temp\ALSysIO.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-22 11:56 - 2013-08-22 11:56 - 00000000 ____D C:\Windows\ERUNT 2013-08-22 11:53 - 2013-08-22 11:53 - 00004556 _____ C:\Users\*****\Desktop\AdwCleaner.txt 2013-08-22 11:49 - 2013-08-22 11:50 - 00000000 ____D C:\AdwCleaner 2013-08-22 11:49 - 2013-08-22 11:49 - 01021455 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-22 11:48 - 2013-08-22 11:48 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-22 10:55 - 2013-08-22 10:55 - 00002664 _____ C:\Users\*****\Desktop\Avira.txt 2013-08-22 10:46 - 2013-08-22 10:49 - 00001320 _____ C:\Users\*****\Desktop\Gmer.log 2013-08-22 10:32 - 2013-08-22 10:32 - 00153680 _____ C:\Windows\Minidump\Mini082213-01.dmp 2013-08-22 10:20 - 2013-08-22 10:20 - 00377856 _____ C:\Users\*****\Desktop\gmer_2.1.19163.exe 2013-08-22 10:10 - 2013-08-22 10:19 - 00019695 _____ C:\Users\*****\Desktop\Addition.txt 2013-08-22 10:09 - 2013-08-22 10:09 - 00000000 ____D C:\FRST 2013-08-22 10:08 - 2013-08-22 10:08 - 01070315 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe 2013-08-21 19:47 - 2013-08-21 19:47 - 00160048 _____ C:\Windows\Minidump\Mini082113-02.dmp 2013-08-21 07:14 - 2013-08-21 07:14 - 00151288 _____ C:\Windows\Minidump\Mini082113-01.dmp 2013-08-18 15:04 - 2013-08-18 15:04 - 00000000 ____D C:\Users\*****\Documents\Wizards of the Coast 2013-08-18 14:47 - 2013-08-18 14:47 - 00000208 _____ C:\Users\*****\Desktop\Magic 2014.url 2013-08-18 14:40 - 2013-08-18 14:41 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 19:58 - 2013-08-14 20:00 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 15:19 - 2013-07-30 06:30 - 01176576 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 15:19 - 2013-07-30 06:30 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 15:19 - 2013-07-30 06:30 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 06118912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 03625472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 15:19 - 2013-07-30 00:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-08-14 15:19 - 2013-07-30 00:12 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 15:19 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 15:19 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 15:19 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 15:19 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-14 15:19 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 15:19 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 15:19 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 15:19 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-08-14 15:19 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-11 15:31 - 2013-08-11 15:31 - 00000000 ____D C:\Program Files\Dungeon Defenders 2013-07-29 11:27 - 2013-07-29 11:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-07-29 11:21 - 2013-07-29 11:21 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-29 11:21 - 2013-07-29 11:21 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:21 - 2013-07-29 11:15 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-23 18:23 - 2013-07-23 18:23 - 00000000 ____D C:\Users\*****~1\AppData\Local\My Games 2013-07-23 16:39 - 2013-07-23 16:39 - 00000206 _____ C:\Users\*****\Desktop\Sid Meier's Civilization V.url ==================== One Month Modified Files and Folders ======= 2013-08-22 11:59 - 2013-08-22 11:58 - 00001878 _____ C:\Users\*****\Desktop\JRT.txt 2013-08-22 11:56 - 2013-08-22 11:56 - 00000000 ____D C:\Windows\ERUNT 2013-08-22 11:53 - 2013-08-22 11:53 - 00004556 _____ C:\Users\*****\Desktop\AdwCleaner.txt 2013-08-22 11:53 - 2012-11-06 10:50 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-22 11:52 - 2011-09-26 15:23 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-22 11:52 - 2011-09-26 15:12 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-22 11:52 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-22 11:52 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-22 11:52 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-22 11:51 - 2008-01-21 03:35 - 01134437 _____ C:\Windows\WindowsUpdate.log 2013-08-22 11:51 - 2006-11-02 15:01 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-22 11:50 - 2013-08-22 11:49 - 00000000 ____D C:\AdwCleaner 2013-08-22 11:49 - 2013-08-22 11:49 - 01021455 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-22 11:48 - 2013-08-22 11:48 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-22 11:48 - 2012-07-23 10:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-22 11:45 - 2012-11-06 10:52 - 00000000 ___RD C:\Users\*****\Documents\Dropbox 2013-08-22 10:55 - 2013-08-22 10:55 - 00002664 _____ C:\Users\*****\Desktop\Avira.txt 2013-08-22 10:49 - 2013-08-22 10:46 - 00001320 _____ C:\Users\*****\Desktop\Gmer.log 2013-08-22 10:32 - 2013-08-22 10:32 - 00153680 _____ C:\Windows\Minidump\Mini082213-01.dmp 2013-08-22 10:32 - 2012-05-22 12:48 - 00000000 ____D C:\Windows\Minidump 2013-08-22 10:31 - 2012-05-22 12:48 - 274763123 _____ C:\Windows\MEMORY.DMP 2013-08-22 10:31 - 2011-10-20 13:05 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2013-08-22 10:31 - 2008-01-21 04:47 - 00283070 _____ C:\Windows\PFRO.log 2013-08-22 10:22 - 2011-10-20 13:05 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-22 10:20 - 2013-08-22 10:20 - 00377856 _____ C:\Users\*****\Desktop\gmer_2.1.19163.exe 2013-08-22 10:19 - 2013-08-22 10:10 - 00019695 _____ C:\Users\*****\Desktop\Addition.txt 2013-08-22 10:09 - 2013-08-22 10:09 - 00000000 ____D C:\FRST 2013-08-22 10:08 - 2013-08-22 10:08 - 01070315 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe 2013-08-21 20:55 - 2013-01-11 22:29 - 00000000 ____D C:\Users\*****\2013-01 (Jan) 2013-08-21 20:55 - 2011-09-26 14:31 - 00000000 ____D C:\Users\***** 2013-08-21 20:33 - 2011-09-26 15:12 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-21 20:04 - 2006-11-02 12:33 - 01590362 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 19:47 - 2013-08-21 19:47 - 00160048 _____ C:\Windows\Minidump\Mini082113-02.dmp 2013-08-21 07:48 - 2012-05-13 19:22 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-08-21 07:48 - 2011-09-26 15:11 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-08-21 07:14 - 2013-08-21 07:14 - 00151288 _____ C:\Windows\Minidump\Mini082113-01.dmp 2013-08-19 08:41 - 2012-05-04 08:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-18 15:04 - 2013-08-18 15:04 - 00000000 ____D C:\Users\*****\Documents\Wizards of the Coast 2013-08-18 14:47 - 2013-08-18 14:47 - 00000208 _____ C:\Users\*****\Desktop\Magic 2014.url 2013-08-18 14:41 - 2013-08-18 14:40 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-15 20:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 10:54 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-08-15 10:35 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-14 20:00 - 2013-08-14 19:58 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 19:58 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-08-14 19:56 - 2011-09-29 14:10 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-11 15:31 - 2013-08-11 15:31 - 00000000 ____D C:\Program Files\Dungeon Defenders 2013-08-05 22:29 - 2013-04-30 13:34 - 00000000 ____D C:\Users\*****\Desktop\ÖKo 2013-08-01 14:03 - 2011-09-29 14:15 - 00002631 _____ C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk 2013-07-31 08:07 - 2013-03-05 10:45 - 00000000 ____D C:\Program Files\Common Files\Steam 2013-07-30 09:37 - 2011-09-29 14:10 - 00000000 ____D C:\Users\*****~1\AppData\Local\Microsoft Help 2013-07-30 06:30 - 2013-08-14 15:19 - 01176576 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 06:30 - 2013-08-14 15:19 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 06:30 - 2013-08-14 15:19 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 06118912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 03625472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 00:27 - 2013-08-14 15:19 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 00:12 - 2013-08-14 15:19 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-29 11:27 - 2013-07-29 11:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-07-29 11:21 - 2013-07-29 11:21 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-29 11:21 - 2013-07-29 11:21 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:21 - 2011-09-26 16:23 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:15 - 2013-07-29 11:21 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-25 19:48 - 2013-07-19 20:54 - 00000000 ____D C:\Users\*****~1\AppData\Local\dxhr 2013-07-23 18:23 - 2013-07-23 18:23 - 00000000 ____D C:\Users\*****~1\AppData\Local\My Games 2013-07-23 18:23 - 2012-01-07 21:22 - 00000000 ____D C:\Users\*****\Documents\My Games 2013-07-23 16:39 - 2013-07-23 16:39 - 00000206 _____ C:\Users\*****\Desktop\Sid Meier's Civilization V.url 2013-07-23 08:18 - 2013-05-02 11:50 - 00000000 ____D C:\Users\*****\Desktop\Humanbiologie ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 11:59 ==================== End Of Log ============================ Danke Cosinus ! |
Themen zu Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ |
absturz, antivir, antivirus, avira searchfree toolbar, bluescreen, bonjour, browser, excel, farbar, farbar recovery scan tool, fehler, firefox, firefox 23.0.1, flash player, helper, home, homepage, java/dldr.obfshlp.qq, malware, minidump, mozilla, programm, registry, scan, security, software, spielen, svchost.exe, tracker, unerwarteter fehler, viren, virus, vista, windows |