|
Log-Analyse und Auswertung: Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.08.2013, 10:17 | #1 |
| Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ Hallo liebes Trojaner-Board-Team, seit ein paar Tagen macht mein PC ordentlich Probleme. Ich benutze Windows Vista 32-bit und erhielt beim surfen und spielen nachdem der Ping sich stark verschlechtert hatte auch div. Standbilder. Ein Viren Scan mit Antivir ergab div. Viren ... vorallem JAVA/Dldr.Obfshlp.QQ. Diese habe ich entfernt - seitdem habe ich auch Bluescreens. Ich habe wie in eurem Forum beschrieben div. Scans laufen lassen und poste diese jetzt hier, mit der Hoffnung, dass ihr mir helfen könnt - ansonsten bin ich schon kurz davor alles zu formatieren. Zu dem Gmer-Scan muss ich sagen, dass mein PC diesen garnicht mochte ... ich konnte ihn nur im abgesicherten Modus durchführen. Ich hoffe Ihr könnt mir helfen, mit freundlichen Grüßen, digiRecon. Avira: Code:
ATTFilter Exportierte Ereignisse: 21.08.2013 12:54 [System-Scanner] Malware gefunden Die Datei 'C:\Users\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\54ef7758- 4026c00e' enthielt einen Virus oder unerwünschtes Programm 'JAVA/Dldr.Obfshlp.QQ' [virus]. Durchgeführte Aktion(en): Die Datei wurde gelöscht. 21.08.2013 12:54 [System-Scanner] Malware gefunden Die Datei 'C:\Users\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\2471480b- 38aca415' enthielt einen Virus oder unerwünschtes Programm 'JAVA/Dldr.Obfshlp.QQ' [virus]. Durchgeführte Aktion(en): Die Datei wurde gelöscht. 21.08.2013 11:47 [System-Scanner] Malware gefunden Die Datei 'C:\Users\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\54ef7758- 4026c00e' enthielt einen Virus oder unerwünschtes Programm 'JAVA/Dldr.Obfshlp.QQ' [virus]. Durchgeführte Aktion(en): Die Datei wurde gelöscht. 21.08.2013 11:47 [System-Scanner] Malware gefunden Die Datei 'C:\Users\*****\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\2471480b- 38aca415' enthielt einen Virus oder unerwünschtes Programm 'JAVA/Dldr.Obfshlp.QQ' [virus]. Durchgeführte Aktion(en): Die Datei wurde gelöscht. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-08-2013 02 Ran by ****** (administrator) on 22-08-2013 10:09:17 Running from C:\Users\*****\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hi-Rez Studios) D:\Games\HiPatchService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Dropbox, Inc.) C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2008-03-25] (Hewlett-Packard) HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [81920 2008-03-13] (Hewlett-Packard) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) MountPoints2: {48d89364-7ce5-11e2-9198-0021859e233c} - K:\launcher.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm URLSearchHook: BittorrentBar_DE Toolbar - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - C:\Program Files\BittorrentBar_DE\prxtbBitt.dll No File SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2849855 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKCU - {4B2BCF1E-9A97-429B-8C52-3C93BE43DAAB} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2849855 BHO: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO: BittorrentBar_DE Toolbar - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - C:\Program Files\BittorrentBar_DE\prxtbBitt.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - BittorrentBar_DE Toolbar - {64ead72b-ffd4-4e01-aa3a-4c71665d73e4} - C:\Program Files\BittorrentBar_DE\prxtbBitt.dll No File Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU -No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\searchplugins\MyStart Search.xml FF Extension: toolbar_AVIRA-V7 - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "urls_to_restore_on_startup": [ CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.0.0_0 CHR Extension: (Gmail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM\...\Chrome\Extension: [hempmfkijmahkaddljkmchcmjbojoedl] - C:\Users\*****\AppData\Local\Temp\crxA065.tmp ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.) R2 HiPatchService; D:\Games\HiPatchService.exe [9216 2013-08-13] (Hi-Rez Studios) ==================== Drivers (Whitelisted) ==================== S4 ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [170000 2007-12-19] (AMD Technologies Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) S4 JRAID; C:\Windows\system32\drivers\jraid.sys [65024 2007-09-29] (JMicron Technology Corp.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-02-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH) S3 ALSysIO; \??\C:\Users\*****~1\AppData\Local\Temp\ALSysIO.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-22 10:08 - 2013-08-22 10:08 - 01070315 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe 2013-08-21 19:47 - 2013-08-21 19:47 - 00160048 _____ C:\Windows\Minidump\Mini082113-02.dmp 2013-08-21 07:14 - 2013-08-21 07:14 - 00151288 _____ C:\Windows\Minidump\Mini082113-01.dmp 2013-08-18 15:04 - 2013-08-18 15:04 - 00000000 ____D C:\Users\*****\Documents\Wizards of the Coast 2013-08-18 14:47 - 2013-08-18 14:47 - 00000208 _____ C:\Users\*****\Desktop\Magic 2014.url 2013-08-18 14:40 - 2013-08-18 14:41 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 19:58 - 2013-08-14 20:00 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 15:19 - 2013-07-30 06:30 - 01176576 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 15:19 - 2013-07-30 06:30 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 15:19 - 2013-07-30 06:30 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 06118912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 03625472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 15:19 - 2013-07-30 00:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-08-14 15:19 - 2013-07-30 00:12 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 15:19 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 15:19 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 15:19 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 15:19 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-14 15:19 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 15:19 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 15:19 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 15:19 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-08-14 15:19 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-11 15:31 - 2013-08-11 15:31 - 00000000 ____D C:\Program Files\Dungeon Defenders 2013-07-29 11:27 - 2013-07-29 11:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-07-29 11:23 - 2013-07-29 11:23 - 00000000 ____D C:\Users\*****\AppData\Local\AskPartnerNetwork 2013-07-29 11:22 - 2013-07-29 11:22 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-07-29 11:22 - 2013-07-29 11:22 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-07-29 11:21 - 2013-07-29 11:21 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-29 11:21 - 2013-07-29 11:21 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:21 - 2013-07-29 11:15 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-23 18:23 - 2013-07-23 18:23 - 00000000 ____D C:\Users\*****\AppData\Local\My Games 2013-07-23 16:39 - 2013-07-23 16:39 - 00000206 _____ C:\Users\*****\Desktop\Sid Meier's Civilization V.url ==================== One Month Modified Files and Folders ======= 2013-08-22 10:09 - 2013-08-22 10:09 - 00000000 ____D C:\FRST 2013-08-22 10:08 - 2013-08-22 10:08 - 01070315 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe 2013-08-22 10:07 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-22 10:07 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-22 10:06 - 2012-11-06 10:52 - 00000000 ___RD C:\Users\*****\Documents\Dropbox 2013-08-22 10:06 - 2012-11-06 10:50 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-22 10:05 - 2011-10-20 13:05 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-22 10:05 - 2011-10-20 13:05 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2013-08-22 10:02 - 2008-01-21 03:35 - 01121183 _____ C:\Windows\WindowsUpdate.log 2013-08-22 09:56 - 2011-09-26 15:12 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-22 09:55 - 2011-09-26 15:23 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-22 09:55 - 2006-11-02 15:01 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-22 09:55 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-21 20:55 - 2013-01-11 22:29 - 00000000 ____D C:\Users\*****\2013-01 (Jan) 2013-08-21 20:55 - 2011-09-26 14:31 - 00000000 ____D C:\Users\***** 2013-08-21 20:48 - 2012-07-23 10:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-21 20:33 - 2011-09-26 15:12 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-21 20:04 - 2006-11-02 12:33 - 01590362 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 19:47 - 2013-08-21 19:47 - 00160048 _____ C:\Windows\Minidump\Mini082113-02.dmp 2013-08-21 19:47 - 2012-05-22 12:48 - 00000000 ____D C:\Windows\Minidump 2013-08-21 19:46 - 2012-05-22 12:48 - 236842403 _____ C:\Windows\MEMORY.DMP 2013-08-21 07:48 - 2012-05-13 19:22 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-08-21 07:48 - 2011-09-26 15:11 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-08-21 07:14 - 2013-08-21 07:14 - 00151288 _____ C:\Windows\Minidump\Mini082113-01.dmp 2013-08-19 08:41 - 2012-05-04 08:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-18 15:04 - 2013-08-18 15:04 - 00000000 ____D C:\Users\*****\Documents\Wizards of the Coast 2013-08-18 14:47 - 2013-08-18 14:47 - 00000208 _____ C:\Users\*****\Desktop\Magic 2014.url 2013-08-18 14:41 - 2013-08-18 14:40 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-15 20:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 10:54 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-08-15 10:35 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-14 20:00 - 2013-08-14 19:58 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 19:58 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-08-14 19:56 - 2011-09-29 14:10 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-11 15:31 - 2013-08-11 15:31 - 00000000 ____D C:\Program Files\Dungeon Defenders 2013-08-05 22:29 - 2013-04-30 13:34 - 00000000 ____D C:\Users\*****\Desktop\ÖKo 2013-08-01 14:03 - 2011-09-29 14:15 - 00002631 _____ C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk 2013-07-31 08:07 - 2013-03-05 10:45 - 00000000 ____D C:\Program Files\Common Files\Steam 2013-07-30 09:37 - 2011-09-29 14:10 - 00000000 ____D C:\Users\*****\AppData\Local\Microsoft Help 2013-07-30 09:32 - 2008-01-21 04:47 - 00282738 _____ C:\Windows\PFRO.log 2013-07-30 06:30 - 2013-08-14 15:19 - 01176576 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 06:30 - 2013-08-14 15:19 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 06:30 - 2013-08-14 15:19 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 06118912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 03625472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 00:27 - 2013-08-14 15:19 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 00:12 - 2013-08-14 15:19 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-29 11:27 - 2013-07-29 11:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-07-29 11:23 - 2013-07-29 11:23 - 00000000 ____D C:\Users\*****\AppData\Local\AskPartnerNetwork 2013-07-29 11:22 - 2013-07-29 11:22 - 00000000 ____D C:\ProgramData\AskPartnerNetwork 2013-07-29 11:22 - 2013-07-29 11:22 - 00000000 ____D C:\Program Files\AskPartnerNetwork 2013-07-29 11:21 - 2013-07-29 11:21 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-29 11:21 - 2013-07-29 11:21 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:21 - 2011-09-26 16:23 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:15 - 2013-07-29 11:21 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-25 19:48 - 2013-07-19 20:54 - 00000000 ____D C:\Users\*****\AppData\Local\dxhr 2013-07-23 18:23 - 2013-07-23 18:23 - 00000000 ____D C:\Users\*****\AppData\Local\My Games 2013-07-23 18:23 - 2012-01-07 21:22 - 00000000 ____D C:\Users\*****\Documents\My Games 2013-07-23 16:39 - 2013-07-23 16:39 - 00000206 _____ C:\Users\*****\Desktop\Sid Meier's Civilization V.url 2013-07-23 08:18 - 2013-05-02 11:50 - 00000000 ____D C:\Users\*****\Desktop\Humanbiologie ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 10:05 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-08-2013 02 Ran by ****** at 2013-08-22 10:10:17 Running from C:\Users\******\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) 32 Bit HP CIO Components Installer (Version: 2.1.4) Adobe AIR (Version: 1.5.2.8900) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Alan Wake Alan Wake's American Nightmare Apple Application Support (Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (Version: 2.1.3.127) Arma 2 Army of The Czech Republic (LITE) Uninstall ARMA 2 Operation Arrowhead Uninstall ArmA 2 Uninstall Avira Free Antivirus (Version: 13.0.0.3885) Avira SearchFree Toolbar plus Web Protection (Version: 12.2.2.663) Batman: Arkham Asylum GOTY Edition BattlEye for OA Uninstall BattlEye Uninstall Bonjour (Version: 3.0.0.10) BufferChm (Version: 110.0.180.000) Cards_Calendar_OrderGift_DoMorePlugout (Version: 2.03.0000) Chivalry: Medieval Warfare CustomerResearchQFolder (Version: 1.00.0000) Destination Component (Version: 110.0.0.0) Deus Ex: Human Revolution - The Missing Link DeviceDiscovery (Version: 110.0.180.000) DeviceManagementQFolder (Version: 1.00.0000) DJ_AIO_03_F4200_Software (Version: 110.0.238.000) DJ_AIO_03_F4200_Software_Min (Version: 110.0.238.000) DJ_AIO_03_F4220_ProductContext (Version: 110.0.238.000) Don't Starve Dropbox (HKCU Version: 2.0.22) Dungeon Defenders EA Installer (Version: 2.2.0.62) EA Shared Game Component: Activation (Version: 2.2.0) EA Shared Game Component: Activation (Version: 2.2.0.62) eSupportQFolder (Version: 1.00.0000) F4200 (Version: 110.0.238.000) F4210_Help (Version: 110.0.238.000) Fallen Enchantress: Legendary Heroes Fallout: New Vegas Game Dev Tycoon DEMO Version 1.0.1 (Version: 1.0.1) Game Dev Tycoon Version 1.3.9 (Version: 1.3.9) Google Chrome (Version: 28.0.1500.95) Google Update Helper (Version: 1.3.21.153) GPBaseService (Version: 110.0.180.000) Heroes of Might & Magic V: Hammers of Fate Heroes of Might and Magic V Heroes of Might and Magic V - Tribes of the East Hi-Rez Studios Authenticate and Update Service (Version: 3.0.0.0) HP Customer Participation Program 11.0 (Version: 11.0) HP Deskjet F4200 All-In-One Driver Software 11.0 Rel .3 (Version: 11.0) HP Imaging Device Functions 11.0 (Version: 11.0) HP Photosmart Essential 2.5 (Version: 1.03.0000) HP Photosmart Essential 3.0 (Version: 3.0) HP Smart Web Printing (Version: 4.0) HP Solution Center 11.0 (Version: 11.0) HP Update (Version: 4.000.009.002) HPProductAssistant (Version: 110.0.180.000) Lager (Version: 1.0.0.0) Left 4 Dead 2 Mafia II Magic 2014 Magicka MarketResearch (Version: 110.0.180.000) Mass Effect 2 (Version: 1.2.1604.0) Mass Effect™ 3 (Version: 1.05.0.0) Master of Orion II Medieval II Total War (Version: 1.03.000) Medieval II Total War : Kingdoms : Americas (Version: 1.05.000) Medieval II Total War : Kingdoms : Britannia (Version: 1.05.000) Medieval II Total War : Kingdoms : Crusades (Version: 1.05.000) Medieval II Total War : Kingdoms : Teutonic (Version: 1.05.000) Microsoft .NET Framework 1.1 (Version: 1.1.4322) Microsoft .NET Framework 1.1 Security Update (KB2698023) Microsoft .NET Framework 1.1 Security Update (KB2833941) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Games for Windows - LIVE (Version: 3.0.86.0) Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.92.0) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft XNA Framework Redistributable 3.1 (Version: 3.1.10527.0) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) NVIDIA 3D Vision Controller Driver (Version: 280.19) NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Drivers NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA PhysX (Version: 9.12.0613) NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) Origin (Version: 9.1.10.2728) Pando Media Booster (Version: 2.6.0.2) PAYDAY: The Heist PDF-XChange Viewer (Version: 2.5.198.0) Play withSIX (Version: 1.20.0344) PSSWCORE (Version: 2.03.0000) Scan (Version: 11.0.0.0) Sid Meier's Civilization V SimCity™ (Version: 1.0.0.0) Skype™ 6.3 (Version: 6.3.107) SmartWebPrinting (Version: 110.0.182.000) Smite (Version: 0.1.1682.0) SolutionCenter (Version: 110.0.180.000) StarCraft II (Version: 2.0.4.24944) Status (Version: 110.0.180.000) Steam (Version: 1.0.0.0) TeamSpeak 3 Client Toolbox (Version: 110.0.180.000) TrayApp (Version: 110.0.180.000) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) VideoToolkit01 (Version: 110.0.171.000) VLC media player 1.1.11 (Version: 1.1.11) War of the Roses Balance Beta War of the Roses: Kingmaker Warlock - Master of the Arcane WebReg (Version: 110.0.180.000) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) WinRAR 4.11 (32-Bit) (Version: 4.11.0) ==================== Restore Points ========================= 11-08-2013 13:30:39 DirectX wurde installiert 12-08-2013 11:36:22 Geplanter Prüfpunkt 14-08-2013 17:52:18 Windows Update 20-08-2013 11:47:47 Geplanter Prüfpunkt 21-08-2013 16:42:23 Geplanter Prüfpunkt 22-08-2013 08:03:35 Removed Java 7 Update 25 ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {20BFEC11-9053-40BC-820A-569A824241BF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {3180A5FD-A277-4993-93B1-FE7B35A33996} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-21] (Adobe Systems Incorporated) Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {618C60E5-84D0-49CF-8C87-957B9A7CD6AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-26] (Google Inc.) Task: {9314FFE3-ADD1-4CD4-AC17-4AC85E565F29} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-21] (Microsoft Corporation) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-21] (Microsoft Corporation) Task: {C385DE33-5C49-4714-B2D3-C37DEC024034} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-26] (Google Inc.) Task: {D24DF210-AB42-4642-9CF7-3A27A2012B5B} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: SM-Bus-Controller Description: SM-Bus-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Coprozessor Description: Coprozessor Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/22/2013 09:55:54 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/21/2013 07:54:19 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: -1216 Error: (08/21/2013 07:54:19 PM) (Source: ESENT) (User: ) Description: Catalog Database (1560) Catalog Database: Bei Datenbankwiederherstellung trat ein unerwarteter Fehler -1216 auf. Error: (08/21/2013 07:54:19 PM) (Source: ESENT) (User: ) Description: Catalog Database (1560) Catalog Database: Bei der Datenbankwiederherstellung ist ein Fehler aufgetreten (Fehler -1216), da Verweise auf Datenbank "C:\Windows\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb" festgestellt wurden, die nicht mehr vorhanden ist. Die Datenbank wurde nicht sauber heruntergefahren, bevor sie entfernt (oder möglicherweise verschoben oder umbenannt) wurde. Das Datenbankmodul lässt den Abschluss der Wiederherstellung für diese Instanz erst dann zu, wenn die fehlende Datenbank wieder verfügbar gemacht wird. Wenn die Datenbank tatsächlich nicht mehr verfügbar oder nicht mehr erforderlich ist, finden Sie Informationen zum Beheben dieses Fehlers in der Microsoft Knowledge Base oder unter dem Link "Weitere Informationen" am Ende dieser Meldung. Error: (08/21/2013 07:53:58 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\8OAIAZTK.DEFAULT\CACHE\9\35> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/21/2013 07:53:58 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\8OAIAZTK.DEFAULT\CACHE\9\35> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/21/2013 07:53:58 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\8OAIAZTK.DEFAULT\CACHE\9\33> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/21/2013 07:53:58 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\8OAIAZTK.DEFAULT\CACHE\9\33> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/21/2013 07:53:58 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\8OAIAZTK.DEFAULT\CACHE\9\30> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/21/2013 07:53:58 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\*****\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\8OAIAZTK.DEFAULT\CACHE\9\30> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (08/22/2013 10:01:57 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (08/22/2013 10:00:25 AM) (Source: Service Control Manager) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (08/22/2013 10:00:25 AM) (Source: Service Control Manager) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (08/22/2013 09:58:06 AM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (08/21/2013 07:58:55 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (08/21/2013 07:57:30 PM) (Source: Service Control Manager) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (08/21/2013 07:57:30 PM) (Source: Service Control Manager) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (08/21/2013 07:54:20 PM) (Source: Service Control Manager) (User: ) Description: HP CUE DeviceDiscovery Service Error: (08/21/2013 07:52:38 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 21.08.2013 um 19:49:32 unerwartet heruntergefahren. Error: (08/21/2013 07:49:32 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 21.08.2013 um 19:47:53 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= Error: (12/11/2012 02:46:17 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 2961 seconds with 1740 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2011-10-28 13:17:54.133 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-10-28 13:17:54.071 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-10-28 13:17:53.993 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-10-28 13:17:53.915 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2011-10-28 13:17:53.837 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 3070.51 MB Available physical RAM: 1391.72 MB Total Pagefile: 6369.42 MB Available Pagefile: 4614.38 MB Total Virtual: 2047.88 MB Available Virtual: 1901.36 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:153.63 GB) (Free:80.7 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:303.34 GB) (Free:119.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: E7FE8170) Partition 1: (Not Active) - (Size=9 GB) - (Type=27) Partition 2: (Active) - (Size=154 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=303 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-08-22 10:46:17 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000AAKS-07A7B0 rev.01.03B01 465,76GB Running: gmer_2.1.19163.exe; Driver: C:\Users\*****\AppData\Local\Temp\kxldakoc.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD8 0x66 0x57 0x41 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD8 0x66 0x57 0x41 ... ---- EOF - GMER 2.1 ---- |
22.08.2013, 10:37 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ Hallo und
__________________Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
22.08.2013, 11:06 | #3 |
| Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ Erstmal vielen Dank für die überaus schnelle Hilfe ... hier die 2.Runde an logfiles!
__________________Adw-Cleaner AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.000 - Report created 22/08/2013 at 11:50:44 # Updated 20/08/2013 by Xplode # Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Username : ***** - *****-PC # Running from : C:\Users\*****\Desktop\adwcleaner.exe # Option : Clean ***** [ Services ] ***** Service Deleted : APNMCP ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\APN Folder Deleted : C:\ProgramData\AskPartnerNetwork Folder Deleted : C:\Program Files\AskPartnerNetwork Folder Deleted : C:\Program Files\Conduit Folder Deleted : C:\Users\*****\AppData\Local\AskPartnerNetwork Folder Deleted : C:\Users\*****\AppData\Local\Conduit Folder Deleted : C:\Users\*****~1\AppData\Local\Temp\APN Folder Deleted : C:\Users\*****~1\AppData\Local\Temp\AskSearch Folder Deleted : C:\Users\*****\AppData\LocalLow\Conduit Folder Deleted : C:\Users\*****\AppData\LocalLow\BittorrentBar_DE Folder Deleted : C:\Users\*****\AppData\Roaming\software4u File Deleted : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\searchplugins\MyStart Search.xml ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DC59CB47-3949-4A1D-9CE6-4C1B08BFA158} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BCE90EC8-E22B-4937-BC8A-DABBB43D963E} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BCE90EC8-E22B-4937-BC8A-DABBB43D963E} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75286E2E-2323-470D-BE89-98243F5F1E62} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C4F0F66-E5A9-4C38-A8C4-9E18FC0FBAAE} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{64EAD72B-FFD4-4E01-AA3A-4C71665D73E4}] Key Deleted : HKCU\Software\AskPartnerNetwork Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\AppDataLow\Toolbar Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\BittorrentBar_DE Key Deleted : HKLM\Software\AskPartnerNetwork Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\Software\InstallIQ Key Deleted : HKLM\Software\BittorrentBar_DE Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [ Browsers ] ***** -\\ Internet Explorer v7.0.6002.18005 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\prefs.js ] Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"smartwebprinting@hp.com\":{\"descriptor\":\"C:\\\\Program Files\\\\HP\\\\Digital Imaging\\\\Smart Web Printing\\\\M[...] -\\ Google Chrome v28.0.1500.95 [ File : C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [4790 octets] - [22/08/2013 11:50:10] AdwCleaner[S0].txt - [4473 octets] - [22/08/2013 11:50:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4533 octets] ########## JRT JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.3 (08.21.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by ***** on 22.08.2013 at 11:56:08,28 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\dt soft\daemon tools toolbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2849855 ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [File] C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8oaiaztk.default\extensions\toolbar_avira-v7@apn.ask.com.xpi Emptied folder: C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8oaiaztk.default\minidumps [15 files] ~~~ Chrome Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 22.08.2013 at 11:58:14,48 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST (nummer 2) FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-08-2013 02 Ran by ***** (administrator) on 22-08-2013 11:59:53 Running from C:\Users\*****\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 7 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hi-Rez Studios) D:\Games\HiPatchService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Dropbox, Inc.) C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2008-03-25] (Hewlett-Packard) HKLM\...\Run: [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [81920 2008-03-13] (Hewlett-Packard) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) MountPoints2: {48d89364-7ce5-11e2-9198-0021859e233c} - K:\launcher.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {4B2BCF1E-9A97-429B-8C52-3C93BE43DAAB} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms} BHO: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" No File Toolbar: HKCU -Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - "C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8oaiaztk.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG) R2 HiPatchService; D:\Games\HiPatchService.exe [9216 2013-08-13] (Hi-Rez Studios) ==================== Drivers (Whitelisted) ==================== S4 ahcix86s; C:\Windows\system32\drivers\ahcix86s.sys [170000 2007-12-19] (AMD Technologies Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) S4 JRAID; C:\Windows\system32\drivers\jraid.sys [65024 2007-09-29] (JMicron Technology Corp.) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2013-02-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH) S3 ALSysIO; \??\C:\Users\*****~1\AppData\Local\Temp\ALSysIO.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-22 11:56 - 2013-08-22 11:56 - 00000000 ____D C:\Windows\ERUNT 2013-08-22 11:53 - 2013-08-22 11:53 - 00004556 _____ C:\Users\*****\Desktop\AdwCleaner.txt 2013-08-22 11:49 - 2013-08-22 11:50 - 00000000 ____D C:\AdwCleaner 2013-08-22 11:49 - 2013-08-22 11:49 - 01021455 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-22 11:48 - 2013-08-22 11:48 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-22 10:55 - 2013-08-22 10:55 - 00002664 _____ C:\Users\*****\Desktop\Avira.txt 2013-08-22 10:46 - 2013-08-22 10:49 - 00001320 _____ C:\Users\*****\Desktop\Gmer.log 2013-08-22 10:32 - 2013-08-22 10:32 - 00153680 _____ C:\Windows\Minidump\Mini082213-01.dmp 2013-08-22 10:20 - 2013-08-22 10:20 - 00377856 _____ C:\Users\*****\Desktop\gmer_2.1.19163.exe 2013-08-22 10:10 - 2013-08-22 10:19 - 00019695 _____ C:\Users\*****\Desktop\Addition.txt 2013-08-22 10:09 - 2013-08-22 10:09 - 00000000 ____D C:\FRST 2013-08-22 10:08 - 2013-08-22 10:08 - 01070315 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe 2013-08-21 19:47 - 2013-08-21 19:47 - 00160048 _____ C:\Windows\Minidump\Mini082113-02.dmp 2013-08-21 07:14 - 2013-08-21 07:14 - 00151288 _____ C:\Windows\Minidump\Mini082113-01.dmp 2013-08-18 15:04 - 2013-08-18 15:04 - 00000000 ____D C:\Users\*****\Documents\Wizards of the Coast 2013-08-18 14:47 - 2013-08-18 14:47 - 00000208 _____ C:\Users\*****\Desktop\Magic 2014.url 2013-08-18 14:40 - 2013-08-18 14:41 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-14 19:58 - 2013-08-14 20:00 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 15:19 - 2013-07-30 06:30 - 01176576 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 15:19 - 2013-07-30 06:30 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 15:19 - 2013-07-30 06:30 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 06118912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 03625472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 15:19 - 2013-07-30 06:29 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 15:19 - 2013-07-30 00:27 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-08-14 15:19 - 2013-07-30 00:12 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 15:19 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 15:19 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 15:19 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 15:19 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-08-14 15:19 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 15:19 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 15:19 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 15:19 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 15:19 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-08-14 15:19 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-11 15:31 - 2013-08-11 15:31 - 00000000 ____D C:\Program Files\Dungeon Defenders 2013-07-29 11:27 - 2013-07-29 11:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-07-29 11:21 - 2013-07-29 11:21 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-29 11:21 - 2013-07-29 11:21 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:21 - 2013-07-29 11:15 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:21 - 2013-07-29 11:15 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-23 18:23 - 2013-07-23 18:23 - 00000000 ____D C:\Users\*****~1\AppData\Local\My Games 2013-07-23 16:39 - 2013-07-23 16:39 - 00000206 _____ C:\Users\*****\Desktop\Sid Meier's Civilization V.url ==================== One Month Modified Files and Folders ======= 2013-08-22 11:59 - 2013-08-22 11:58 - 00001878 _____ C:\Users\*****\Desktop\JRT.txt 2013-08-22 11:56 - 2013-08-22 11:56 - 00000000 ____D C:\Windows\ERUNT 2013-08-22 11:53 - 2013-08-22 11:53 - 00004556 _____ C:\Users\*****\Desktop\AdwCleaner.txt 2013-08-22 11:53 - 2012-11-06 10:50 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-22 11:52 - 2011-09-26 15:23 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-22 11:52 - 2011-09-26 15:12 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-22 11:52 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-22 11:52 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-22 11:52 - 2006-11-02 14:47 - 00003712 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-22 11:51 - 2008-01-21 03:35 - 01134437 _____ C:\Windows\WindowsUpdate.log 2013-08-22 11:51 - 2006-11-02 15:01 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-22 11:50 - 2013-08-22 11:49 - 00000000 ____D C:\AdwCleaner 2013-08-22 11:49 - 2013-08-22 11:49 - 01021455 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-22 11:48 - 2013-08-22 11:48 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-22 11:48 - 2012-07-23 10:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-22 11:45 - 2012-11-06 10:52 - 00000000 ___RD C:\Users\*****\Documents\Dropbox 2013-08-22 10:55 - 2013-08-22 10:55 - 00002664 _____ C:\Users\*****\Desktop\Avira.txt 2013-08-22 10:49 - 2013-08-22 10:46 - 00001320 _____ C:\Users\*****\Desktop\Gmer.log 2013-08-22 10:32 - 2013-08-22 10:32 - 00153680 _____ C:\Windows\Minidump\Mini082213-01.dmp 2013-08-22 10:32 - 2012-05-22 12:48 - 00000000 ____D C:\Windows\Minidump 2013-08-22 10:31 - 2012-05-22 12:48 - 274763123 _____ C:\Windows\MEMORY.DMP 2013-08-22 10:31 - 2011-10-20 13:05 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2013-08-22 10:31 - 2008-01-21 04:47 - 00283070 _____ C:\Windows\PFRO.log 2013-08-22 10:22 - 2011-10-20 13:05 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-08-22 10:20 - 2013-08-22 10:20 - 00377856 _____ C:\Users\*****\Desktop\gmer_2.1.19163.exe 2013-08-22 10:19 - 2013-08-22 10:10 - 00019695 _____ C:\Users\*****\Desktop\Addition.txt 2013-08-22 10:09 - 2013-08-22 10:09 - 00000000 ____D C:\FRST 2013-08-22 10:08 - 2013-08-22 10:08 - 01070315 _____ (Farbar) C:\Users\*****\Desktop\FRST.exe 2013-08-21 20:55 - 2013-01-11 22:29 - 00000000 ____D C:\Users\*****\2013-01 (Jan) 2013-08-21 20:55 - 2011-09-26 14:31 - 00000000 ____D C:\Users\***** 2013-08-21 20:33 - 2011-09-26 15:12 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-21 20:04 - 2006-11-02 12:33 - 01590362 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-21 19:47 - 2013-08-21 19:47 - 00160048 _____ C:\Windows\Minidump\Mini082113-02.dmp 2013-08-21 07:48 - 2012-05-13 19:22 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-08-21 07:48 - 2011-09-26 15:11 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-08-21 07:14 - 2013-08-21 07:14 - 00151288 _____ C:\Windows\Minidump\Mini082113-01.dmp 2013-08-19 08:41 - 2012-05-04 08:14 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-08-18 15:04 - 2013-08-18 15:04 - 00000000 ____D C:\Users\*****\Documents\Wizards of the Coast 2013-08-18 14:47 - 2013-08-18 14:47 - 00000208 _____ C:\Users\*****\Desktop\Magic 2014.url 2013-08-18 14:41 - 2013-08-18 14:40 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-15 20:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-08-15 10:54 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-08-15 10:35 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-08-14 20:00 - 2013-08-14 19:58 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 19:58 - 2006-11-02 12:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-08-14 19:56 - 2011-09-29 14:10 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-11 15:31 - 2013-08-11 15:31 - 00000000 ____D C:\Program Files\Dungeon Defenders 2013-08-05 22:29 - 2013-04-30 13:34 - 00000000 ____D C:\Users\*****\Desktop\ÖKo 2013-08-01 14:03 - 2011-09-29 14:15 - 00002631 _____ C:\Users\*****\Desktop\Microsoft Office Word 2007.lnk 2013-07-31 08:07 - 2013-03-05 10:45 - 00000000 ____D C:\Program Files\Common Files\Steam 2013-07-30 09:37 - 2011-09-29 14:10 - 00000000 ____D C:\Users\*****~1\AppData\Local\Microsoft Help 2013-07-30 06:30 - 2013-08-14 15:19 - 01176576 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 06:30 - 2013-08-14 15:19 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 06:30 - 2013-08-14 15:19 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 06118912 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 03625472 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00671232 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00479744 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00180736 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 06:29 - 2013-08-14 15:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 00:27 - 2013-08-14 15:19 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 00:12 - 2013-08-14 15:19 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-29 11:27 - 2013-07-29 11:27 - 00000000 ____D C:\Users\*****\AppData\Roaming\Avira 2013-07-29 11:21 - 2013-07-29 11:21 - 00001847 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-29 11:21 - 2013-07-29 11:21 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:21 - 2011-09-26 16:23 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:15 - 2013-07-29 11:21 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:15 - 2013-07-29 11:21 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-25 19:48 - 2013-07-19 20:54 - 00000000 ____D C:\Users\*****~1\AppData\Local\dxhr 2013-07-23 18:23 - 2013-07-23 18:23 - 00000000 ____D C:\Users\*****~1\AppData\Local\My Games 2013-07-23 18:23 - 2012-01-07 21:22 - 00000000 ____D C:\Users\*****\Documents\My Games 2013-07-23 16:39 - 2013-07-23 16:39 - 00000206 _____ C:\Users\*****\Desktop\Sid Meier's Civilization V.url 2013-07-23 08:18 - 2013-05-02 11:50 - 00000000 ____D C:\Users\*****\Desktop\Humanbiologie ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 11:59 ==================== End Of Log ============================ Danke Cosinus ! |
22.08.2013, 11:11 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
22.08.2013, 11:28 | #5 |
| Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ Hi Cosinus ... während des Malewarebytes-Suchlauf wieder Bluescreen. Daraufhin lies sich Windows nicht normal starten. Bin jetzt im abgesicherten Modus und probiere erneut den Suchlauf. |
Themen zu Windows Vista 32-bit, Standbild, Bluescreen ... JAVA/Dldr.Obfshlp.QQ |
absturz, antivir, antivirus, avira searchfree toolbar, bluescreen, bonjour, browser, excel, farbar, farbar recovery scan tool, fehler, firefox, firefox 23.0.1, flash player, helper, home, homepage, java/dldr.obfshlp.qq, malware, minidump, mozilla, programm, registry, scan, security, software, spielen, svchost.exe, tracker, unerwarteter fehler, viren, virus, vista, windows |