Plagegeister aller Art und deren Bekämpfung: TR/Dropper.gen Meldung über AviraWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | ![]() TR/Dropper.gen Meldung über Avira Hey Leute, ich hoffe ich bin in der falschen Unterkategorie gelandet. Meine Freundin hatte heute 3 Meldungen von Avira bekommen. Ich hab jetzt ein Logfile von Antivir erstellt und wollte wissen ob sie nun verseucht ist oder nicht? Wenns nach mir ginge würd ich einfach Format C: machen ![]() Hier das Logfile: Zitat:
liebe Grüße Ebo |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über Avira hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
![]() | ![]() TR/Dropper.gen Meldung über Avira FSRT:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-08-2013 Ran by ***** (administrator) on 23-08-2013 11:22:20 Running from K:\Antivirenzeugs Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe () C:\Program Files (x86)\Tor\tor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Alienware) C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe (Dropbox, Inc.) C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe (PowerISO Computing, Inc.) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe (Alienware) C:\Program Files\Alienware\Command Center\ThermalController.exe (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe () C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\avcenter.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6419560 2011-11-21] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-21] (Realtek Semiconductor) HKLM\...\Run: [Launch Keyboard CI] - C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe [3439928 2012-07-11] (Alienware) HKLM\...\Run: [] - [x] HKLM\...\Run: [Command Center Controllers] - C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-07-25] (Alienware) HKCU\...\Run: [EA Core] - "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent [x] HKCU\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2676584 2011-09-16] (Hewlett-Packard Co.) MountPoints2: J - J:\Autorun.exe MountPoints2: M - M:\Autorun.exe MountPoints2: {8844ef79-9ea4-11e2-a07c-d4bed9fd526c} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\index.html HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [RUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2009-07-27] (PowerISO Computing, Inc.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs-x32: c:\progra~3\browse~1\261519~1.190\{c16c1~1\browse~1.dll [97280 2009-07-14] () Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\*****\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "$" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "$" FF NetworkProxy: "ssl", "$" FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\icq-search.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{4EA20D6D-D7F6-4C7D-A61F-EA5ECBA9A302}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{BCAFAC8D-52F8-440B-B859-12339354365D}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{D8DE6131-5A57-473B-B1CC-3198470737B2}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{F117ECFC-ECBC-4B1D-997F-D7C69D90110F}.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF Extension: LavaFox V2-Blue - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\djziggy@gmail.com FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () R2 Windows Internet Name Service; C:\Windows\SysWow64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe [2735616 2013-08-23] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-05] (Avira Operations GmbH & Co. KG) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [26072 2012-08-08] (Intel Corporation) R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2013-02-08] (Renesas Electronics Corporation) R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation) S3 BTMCOM; System32\Drivers\btmcom.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-23 11:04 - 2013-08-23 11:05 - 00000000 ____D C:\AdwCleaner 2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun 2013-08-23 10:56 - 2013-08-23 10:55 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-23 10:56 - 2013-08-23 10:55 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 10:56 - 2013-08-23 10:55 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java 2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe 2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor 2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤™ 2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip 2013-08-21 12:46 - 2013-08-21 12:47 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart 2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft 2013-08-19 21:58 - 2013-08-19 23:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds 2013-08-19 20:08 - 2013-08-18 10:56 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack 2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds 2013-08-16 21:34 - 2013-08-17 00:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds 2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner 2013-08-15 14:00 - 2013-08-15 14:02 - 00000000 ____D C:\Program Files\s3pe 2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones 2013-08-15 13:55 - 2013-08-15 13:56 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds 2013-08-14 18:23 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 18:23 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 18:23 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 18:23 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 18:23 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 18:23 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 18:23 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 18:23 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 18:23 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 18:23 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 18:23 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 18:23 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 18:19 - 2013-08-14 18:20 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 17:56 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 17:56 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 17:55 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 17:55 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 17:55 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 17:55 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 17:55 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 17:55 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 17:55 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 17:55 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 17:55 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 17:55 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 17:55 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 17:55 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 17:55 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 17:55 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 17:55 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 17:55 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 17:55 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 17:55 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 17:55 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 12:13 - 2013-08-23 11:07 - 00000000 ___RD C:\Users\*****\Dropbox 2013-08-14 12:13 - 2013-08-14 12:13 - 00001041 _____ C:\Users\*****\Desktop\Dropbox.lnk 2013-08-14 12:12 - 2013-08-14 12:12 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-14 12:01 - 2013-08-23 11:07 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-12 10:20 - 2013-08-21 23:36 - 00000000 ____D C:\Users\*****\Desktop\DLs 2013-08-06 18:28 - 2013-08-06 21:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions ==================== One Month Modified Files and Folders ======= 2013-08-23 11:14 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-23 11:14 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-23 11:12 - 2013-04-06 07:26 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-23 11:12 - 2013-04-06 07:26 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-23 11:12 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-23 11:07 - 2013-08-14 12:13 - 00000000 ___RD C:\Users\*****\Dropbox 2013-08-23 11:07 - 2013-08-14 12:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-23 11:06 - 2013-04-05 22:00 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-23 11:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-23 11:06 - 2009-07-14 06:51 - 00043565 _____ C:\Windows\setupact.log 2013-08-23 11:05 - 2013-08-23 11:04 - 00000000 ____D C:\AdwCleaner 2013-08-23 11:05 - 2013-04-05 21:32 - 01641107 _____ C:\Windows\WindowsUpdate.log 2013-08-23 11:01 - 2013-04-28 11:53 - 00000254 _____ C:\Windows\Tasks\HP Photo Creations Messager.job 2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun 2013-08-23 10:55 - 2013-08-23 10:56 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-23 10:55 - 2013-08-23 10:56 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 10:55 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java 2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe 2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor 2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤™ 2013-08-22 16:22 - 2013-04-06 14:00 - 00000000 ____D C:\Users\*****\AppData\Local\Paint.NET 2013-08-21 23:36 - 2013-08-12 10:20 - 00000000 ____D C:\Users\*****\Desktop\DLs 2013-08-21 19:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip 2013-08-21 12:47 - 2013-08-21 12:46 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart 2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft 2013-08-20 10:45 - 2013-05-07 18:57 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 10:45 - 2013-04-05 22:37 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-20 10:45 - 2013-04-05 22:37 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-19 23:01 - 2013-08-19 21:58 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds 2013-08-19 14:14 - 2013-04-06 14:00 - 00000000 ____D C:\Program Files\Paint.NET 2013-08-18 10:56 - 2013-08-19 20:08 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack 2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds 2013-08-17 19:56 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-17 18:24 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-17 00:01 - 2013-08-16 21:34 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds 2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner 2013-08-15 14:02 - 2013-08-15 14:00 - 00000000 ____D C:\Program Files\s3pe 2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones 2013-08-15 13:56 - 2013-08-15 13:55 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds 2013-08-14 18:20 - 2013-08-14 18:19 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 18:19 - 2013-04-05 23:56 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 12:18 - 2010-11-21 05:47 - 00020356 _____ C:\Windows\PFRO.log 2013-08-14 12:13 - 2013-08-14 12:13 - 00001041 _____ C:\Users\*****\Desktop\Dropbox.lnk 2013-08-14 12:13 - 2013-04-05 21:53 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-14 12:13 - 2013-04-05 21:52 - 00000000 ____D C:\Users\***** 2013-08-14 12:12 - 2013-08-14 12:12 - 00000000 ____D C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-13 18:24 - 2013-04-28 11:52 - 00000000 ____D C:\Users\*****\AppData\Roaming\HpUpdate 2013-08-13 12:13 - 2013-04-06 18:25 - 00000000 ___RD C:\Users\*****\Desktop\***** 2013-08-06 21:01 - 2013-08-06 18:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-04 20:39 - 2013-07-10 19:11 - 00000000 ____D C:\Users\*****\.gimp-2.8 2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-08-03 10:43 - 2010-11-21 09:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-28 16:53 - 2013-04-06 18:47 - 00000000 ____D C:\Users\*****\Documents\Electronic Arts 2013-07-28 16:52 - 2013-04-06 18:32 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-07-28 16:52 - 2013-04-05 22:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-26 07:13 - 2013-08-14 18:23 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 18:23 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 18:23 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 18:23 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 18:23 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 18:23 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 18:23 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 18:23 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 18:23 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 18:23 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 17:55 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 17:55 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-24 18:43 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-18 22:39 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-08-2013 Ran by ***** at 2013-08-23 11:22:46 Running from K:\Antivirenzeugs Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Flash Player ActiveX (x32 Version: Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Alienware Command Center (Version: Alienware Command Center (x32 Version: Alienware TactX Keyboard CI 1.10.102 (Version: 1.10.102) Avira Free Antivirus (x32 Version: Cisco EAP-FAST Module (x32 Version: 2.2.14) Cisco LEAP Module (x32 Version: 1.0.19) Cisco PEAP Module (x32 Version: 1.1.6) Die Sims™ 3 "Erstelle eine Welt"-Tool - Beta (x32 Version: 1.18.46) Die Sims™ 3 (x32 Version: 1.55.4) Die Sims™ 3 70er, 80er & 90er Accessoires (x32 Version: 17.0.77) Die Sims™ 3 Design-Garten-Accessoires (x32 Version: 7.3.2) Die Sims™ 3 Diesel Accessoires (x32 Version: 14.0.48) Die Sims™ 3 Einfach tierisch (x32 Version: 10.0.96) Die Sims™ 3 Gib Gas-Accessoires (x32 Version: 5.8.1) Die Sims™ 3 Inselparadies (x32 Version: 19.0.101) Die Sims™ 3 Jahreszeiten (x32 Version: 16.0.136) Die Sims™ 3 Katy Perry Süße Welt (x32 Version: 13.0.62) Die Sims™ 3 Late Night (x32 Version: 6.5.1) Die Sims™ 3 Lebensfreude (x32 Version: 8.0.152) Die Sims™ 3 Luxus-Accessoires (x32 Version: 3.13.1) Die Sims™ 3 Reiseabenteuer (x32 Version: 2.17.2) Die Sims™ 3 Showtime (x32 Version: 12.0.273) Die Sims™ 3 Stadt-Accessoires (x32 Version: 9.0.73) Die Sims™ 3 Supernatural (x32 Version: 15.0.135) Die Sims™ 3 Traumkarrieren (x32 Version: 4.10.1) Die Sims™ 3 Traumsuite-Accessoires (x32 Version: 11.0.84) Die Sims™ 3 Wildes Studentenleben (x32 Version: 18.0.126) Dropbox (HKCU Version: 2.0.26) General Runtime Files for Nemetschek Allplan 2008 (x32 Version: HP FWUpdateEDO2 (x32 Version: HP Photo Creations (x32 Version: HP Photosmart 5510 series - Grundlegende Software für das Gerät (Version: 25.0.621.0) HP Photosmart 5510 series Hilfe (x32 Version: HP Update (x32 Version: HPDiagnosticAlert (x32 Version: 1.00.0000) Intel(R) Management Engine Components (x32 Version: Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.5614.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) MozBackup 1.5.1 (x32) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8) Nemetschek Allplan 2008 (x32 Version: 2008.0) Nemetschek SoftLock 2006 (x32 Version: 1.00.0000) NVIDIA 3D Vision Controller-Treiber 301.42 (Version: 301.42) NVIDIA 3D Vision Treiber 301.42 (Version: 301.42) NVIDIA Grafiktreiber 301.42 (Version: 301.42) NVIDIA HD-Audiotreiber (Version: NVIDIA Install Application (Version: 2.1002.109.718) NVIDIA Optimus 1.8.15 (Version: 1.8.15) NVIDIA PhysX (x32 Version: 9.12.0213) NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 301.42 (Version: 301.42) NVIDIA Update Components (Version: 1.8.15) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593) Origin (x32 Version: Paint.NET v3.5.11 (Version: 3.61.0) PDF Architect (x32 Version: PDFCreator (x32 Version: 1.6.2) PowerISO (x32) Ralink RT2870 Wireless LAN Card (x32 Version: Realtek Ethernet Controller Driver (x32 Version: 7.46.610.2011) Realtek High Definition Audio Driver (x32 Version: Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: rosoft .NET Framework 4 Client Profile (Version: 4.0.30319) s3pe - Sims3 Package Editor (x32 Version: 13-0316-1933) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) ==================== Restore Points ========================= 19-08-2013 12:13:52 Paint.NET v3.5.11 22-08-2013 11:33:18 Windows Update 23-08-2013 08:55:40 Installed Java 7 Update 25 ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {090DBEF1-32E4-4834-8A4C-7EF1AC381BFF} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {496DD7E7-7A6E-4C34-BECB-1488E4CE30EC} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation) Task: {4BDB74F3-10EF-439A-BAA8-6760DD4F8A40} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {719B49BD-96EC-4C8B-9950-3A5196316DBB} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {8C2D951C-763C-48F9-9C4A-5CD4325896BD} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe [2013-05-28] (Adobe Systems Incorporated) Task: {C3DA8E0C-07A3-4AE3-A655-29FF4A093B3D} - \BrowserProtect No Task File Task: {DED33DCB-3F08-4B6D-806A-6D87935A8255} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {FE5B4966-6B30-4C9E-87DC-BDD7AAA034E7} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/23/2013 11:07:30 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/23/2013 11:00:44 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (08/23/2013 10:17:57 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/23/2013 10:17:51 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version:, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version:, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00011380 ID des fehlerhaften Prozesses: 0x1010 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (08/22/2013 11:23:03 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/22/2013 09:58:56 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version:, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version:, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00011380 ID des fehlerhaften Prozesses: 0x2868 Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (08/22/2013 03:59:00 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: avnotify.exe, Version:, Zeitstempel: 0x51e6b921 Name des fehlerhaften Moduls: avnotify.exe, Version:, Zeitstempel: 0x51e6b921 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00011380 ID des fehlerhaften Prozesses: 0xcbc Startzeit der fehlerhaften Anwendung: 0xavnotify.exe0 Pfad der fehlerhaften Anwendung: avnotify.exe1 Pfad des fehlerhaften Moduls: avnotify.exe2 Berichtskennung: avnotify.exe3 Error: (08/22/2013 03:23:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/22/2013 02:14:14 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (08/22/2013 01:23:13 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 System errors: ============= Error: (08/22/2013 11:21:23 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 22.08.2013 um 23:19:46 unerwartet heruntergefahren. Error: (08/18/2013 01:53:09 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (08/15/2013 06:51:48 PM) (Source: NetBT) (User: ) Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (08/15/2013 06:42:55 PM) (Source: NetBT) (User: ) Description: Der Name "*****-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (08/15/2013 06:42:55 PM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{B9E9EE2E-3D49-446A-8418-C4C764F71209} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (08/15/2013 06:42:48 PM) (Source: NetBT) (User: ) Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (08/14/2013 04:32:55 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (08/14/2013 01:55:48 PM) (Source: NetBT) (User: ) Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (08/14/2013 01:55:47 PM) (Source: NetBT) (User: ) Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (08/14/2013 01:53:04 PM) (Source: NetBT) (User: ) Description: Der Name "*****-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Microsoft Office Sessions: ========================= Error: (08/23/2013 11:07:30 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/23/2013 11:00:44 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (08/23/2013 10:17:57 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/23/2013 10:17:51 AM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500011380101001ce9fd92c653530C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe807176ec-0bcc-11e3-ae9a-d4bed9fd526c Error: (08/22/2013 11:23:03 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/22/2013 09:58:56 PM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500011380286801ce9f720696f6aeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe46ae0a95-0b65-11e3-9626-d4bed9fd526c Error: (08/22/2013 03:59:00 PM) (Source: Application Error)(User: ) Description: avnotify.exe13.6.20.210051e6b921avnotify.exe13.6.20.210051e6b921c000000500011380cbc01ce9f3fbbf018e2C:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exeC:\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exefe68f377-0b32-11e3-9626-d4bed9fd526c Error: (08/22/2013 03:23:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/22/2013 02:14:14 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (08/22/2013 01:23:13 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 16300.23 MB Available physical RAM: 13472.86 MB Total Pagefile: 32598.64 MB Available Pagefile: 29447.59 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:921.13 GB) (Free:501.62 GB) NTFS Drive d: (RECOVERY) (Fixed) (Total:9.73 GB) (Free:2.76 GB) NTFS Drive k: (TRANSCEND) (Removable) (Total:3.73 GB) (Free:3.06 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 9CEB53D4) Partition: GPT Partition Type ======================================================== Disk: 1 (Size: 4 GB) (Disk ID: 0FF16EAD) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über AviraCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
gruß, schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!
![]() | ![]() TR/Dropper.gen Meldung über AviraCode:
ATTFilter ComboFix 13-08-22.01 - Dani 23.08.2013 12:04:25.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.16300.14000 [GMT 2:00] ausgeführt von:: c:\users\Dani\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . D:\Autorun.inf . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_Windows Internet Name Service . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-23 bis 2013-08-23 )))))))))))))))))))))))))))))) . . 2013-08-23 10:08 . 2013-08-23 10:08 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-08-23 10:08 . 2013-08-23 10:08 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-23 09:22 . 2013-08-23 09:22 -------- d-----w- C:\FRST 2013-08-23 09:04 . 2013-08-23 09:05 -------- d-----w- C:\AdwCleaner 2013-08-23 08:56 . 2013-08-23 08:56 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-08-23 08:56 . 2013-08-23 08:55 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-08-23 08:56 . 2013-08-23 08:55 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-08-23 08:56 . 2013-08-23 08:56 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-08-23 08:55 . 2013-08-23 08:55 -------- d-----w- c:\program files (x86)\Java 2013-08-23 08:21 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7FFE3232-940D-464C-8098-D04B9B8496CF}\mpengine.dll 2013-08-23 08:17 . 2013-08-23 08:17 -------- d-----w- c:\program files (x86)\Tor 2013-08-15 12:00 . 2013-08-15 12:00 -------- d-----w- c:\users\Dani\AppData\Roaming\Peter L Jones 2013-08-15 12:00 . 2013-08-15 12:02 -------- d-----w- c:\program files\s3pe 2013-08-14 16:19 . 2013-08-14 16:20 -------- d-----w- c:\windows\system32\MRT 2013-08-14 15:56 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll 2013-08-14 15:56 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-14 15:56 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll 2013-08-14 15:56 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-14 15:56 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-08-14 15:56 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-08-14 15:56 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-08-14 15:56 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-08-14 10:13 . 2013-08-23 09:07 -------- d-----r- c:\users\Dani\Dropbox 2013-08-14 10:01 . 2013-08-23 09:29 -------- d-----w- c:\users\Dani\AppData\Roaming\Dropbox 2013-08-06 16:28 . 2013-08-06 19:01 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2013-07-24 19:24 . 2013-07-24 19:24 -------- d-----w- c:\windows\SysWow64\Extensions 2013-07-24 19:24 . 2013-07-24 19:24 -------- d-----w- c:\windows\SysWow64\searchplugins . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-20 08:45 . 2013-05-07 16:57 81112 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-08-20 08:45 . 2013-04-05 20:37 132088 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-08-20 08:45 . 2013-04-05 20:37 105344 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-08-14 16:19 . 2013-04-05 21:56 78161360 ----a-w- c:\windows\system32\MRT.exe 2013-07-15 16:37 . 2013-04-06 11:36 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-07-15 16:37 . 2013-04-06 11:36 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-07-09 04:45 . 2013-08-14 15:55 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-06-05 03:34 . 2013-07-10 16:35 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 06:00 . 2013-07-10 16:35 624128 ----a-w- c:\windows\system32\qedit.dll 2013-06-04 04:53 . 2013-07-10 16:35 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2013-05-28 13:05 . 2013-06-19 17:50 163328 ----a-w- c:\windows\SysWow64\FlashPlayerUpdateService.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-09-16 2676584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-08-20 347192] "RUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2009-07-27 180224] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . c:\users\Dani\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe;c:\program files\Alienware\Command Center\AlienFusionService.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys;c:\windows\SYSNATIVE\Drivers\btmcom.sys [x] R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x] R3 LVUVC64;Logitech Webcam 250(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] S0 iaStorA;iaStorA;c:\windows\system32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\drivers\iaStorF.sys;c:\windows\SYSNATIVE\drivers\iaStorF.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files (x86)\PDF Architect\HelperService.exe;c:\program files (x86)\PDF Architect\HelperService.exe [x] S2 PDF Architect Service;PDF Architect Service;c:\program files (x86)\PDF Architect\ConversionService.exe;c:\program files (x86)\PDF Architect\ConversionService.exe [x] S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\Ralink\Common\RaRegistry64.exe;c:\program files (x86)\Ralink\Common\RaRegistry64.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 tor;Tor Win32 Service;c:\program files (x86)\Tor\tor.exe;c:\program files (x86)\Tor\tor.exe [x] S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3hub.sys [x] S3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\DRIVERS\rusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\rusb3xhc.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-08-23 c:\windows\Tasks\HP Photo Creations Messager.job - c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-11-21 6419560] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-11-21 1156712] "Launch Keyboard CI"="c:\program files\Alienware\Alienware TactX Keyboard CI\txkbci.exe" [2012-07-11 3439928] "Command Center Controllers"="c:\program files\Alienware\Command Center\AWCCStartupOrchestrator.exe" [2012-07-25 12656] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.dell.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = FF - ProfilePath - c:\users\Dani\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe Wow6432Node-HKLM-Run-<NO NAME> - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Dani\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Dani\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Dani\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - c:\users\Dani\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.9" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}] @Denied: (A 2) (Everyone) @="IFlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Ralink\Common\RaRegistry.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-08-23 12:14:40 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-08-23 10:14 . Vor Suchlauf: 16 Verzeichnis(se), 564.693.987.328 Bytes frei Nach Suchlauf: 21 Verzeichnis(se), 564.656.799.744 Bytes frei . - - End Of File - - 9FB3C9F3EE04E9222DDE47664F302813 Was kann man bisher sagen? :] |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über Avira Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
und ein frisches FRST log bitte. Noch Probleme?
![]() | ![]() TR/Dropper.gen Meldung über AviraFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-08-2013 Ran by ***** (administrator) on 23-08-2013 15:14:59 Running from C:\Users\*****\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe () C:\Program Files (x86)\Tor\tor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6419560 2011-11-21] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-21] (Realtek Semiconductor) HKLM\...\Run: [Launch Keyboard CI] - C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe [3439928 2012-07-11] (Alienware) HKLM\...\Run: [Command Center Controllers] - C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-07-25] (Alienware) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKCU\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2676584 2011-09-16] (Hewlett-Packard Co.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [RUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2009-07-27] (PowerISO Computing, Inc.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "$" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "$" FF NetworkProxy: "ssl", "$" FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\icq-search.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{4EA20D6D-D7F6-4C7D-A61F-EA5ECBA9A302}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{BCAFAC8D-52F8-440B-B859-12339354365D}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{D8DE6131-5A57-473B-B1CC-3198470737B2}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{F117ECFC-ECBC-4B1D-997F-D7C69D90110F}.xml FF Extension: LavaFox V2-Blue - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\djziggy@gmail.com FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-05] (Avira Operations GmbH & Co. KG) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [26072 2012-08-08] (Intel Corporation) R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2013-02-08] (Renesas Electronics Corporation) R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation) S3 BTMCOM; System32\Drivers\btmcom.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-23 15:14 - 2013-08-23 11:19 - 01576474 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe 2013-08-23 15:05 - 2013-08-23 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-08-23 15:05 - 2013-08-23 14:55 - 01021434 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-23 15:04 - 2013-08-23 11:03 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-23 15:00 - 2013-08-23 15:00 - 00001111 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-23 15:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-23 12:14 - 2013-08-23 12:14 - 00015735 _____ C:\ComboFix.txt 2013-08-23 12:02 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-23 12:02 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-23 12:02 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-23 11:54 - 2013-08-23 12:14 - 00000000 ____D C:\Qoobox 2013-08-23 11:54 - 2013-08-23 12:13 - 00000000 ____D C:\Windows\erdnt 2013-08-23 11:54 - 2013-08-23 11:53 - 05111180 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe 2013-08-23 11:22 - 2013-08-23 11:22 - 00000000 ____D C:\FRST 2013-08-23 11:04 - 2013-08-23 15:04 - 00000000 ____D C:\AdwCleaner 2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun 2013-08-23 10:56 - 2013-08-23 10:55 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-23 10:56 - 2013-08-23 10:55 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 10:56 - 2013-08-23 10:55 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java 2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe 2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor 2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤 2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip 2013-08-21 12:46 - 2013-08-21 12:47 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart 2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft 2013-08-19 21:58 - 2013-08-19 23:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds 2013-08-19 20:08 - 2013-08-18 10:56 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack 2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds 2013-08-16 21:34 - 2013-08-17 00:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds 2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner 2013-08-15 14:00 - 2013-08-15 14:02 - 00000000 ____D C:\Program Files\s3pe 2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones 2013-08-15 13:55 - 2013-08-15 13:56 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds 2013-08-14 18:23 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 18:23 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 18:23 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 18:23 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 18:23 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 18:23 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 18:23 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 18:23 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 18:23 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 18:23 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 18:23 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 18:23 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 18:19 - 2013-08-14 18:20 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 17:56 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 17:56 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 17:55 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 17:55 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 17:55 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 17:55 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 17:55 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 17:55 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 17:55 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 17:55 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 17:55 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 17:55 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 17:55 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 17:55 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 17:55 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 17:55 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 17:55 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 17:55 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 17:55 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 17:55 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 17:55 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 12:13 - 2013-08-23 11:07 - 00000000 ___RD C:\Users\*****\Dropbox 2013-08-14 12:01 - 2013-08-23 11:29 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-12 10:20 - 2013-08-21 23:36 - 00000000 ____D C:\Users\*****\Desktop\DLs 2013-08-06 18:28 - 2013-08-06 21:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions ==================== One Month Modified Files and Folders ======= 2013-08-23 15:14 - 2013-08-23 15:14 - 00001277 _____ C:\Users\*****\Desktop\JRT.txt 2013-08-23 15:05 - 2013-08-23 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-08-23 15:04 - 2013-08-23 11:04 - 00000000 ____D C:\AdwCleaner 2013-08-23 15:01 - 2013-04-28 11:53 - 00000254 _____ C:\Windows\Tasks\HP Photo Creations Messager.job 2013-08-23 15:00 - 2013-08-23 15:00 - 00001111 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-23 14:59 - 2013-04-05 21:32 - 01655973 _____ C:\Windows\WindowsUpdate.log 2013-08-23 14:55 - 2013-08-23 15:05 - 01021434 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-23 12:18 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-23 12:18 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-23 12:14 - 2013-08-23 12:14 - 00015735 _____ C:\ComboFix.txt 2013-08-23 12:14 - 2013-08-23 11:54 - 00000000 ____D C:\Qoobox 2013-08-23 12:14 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-23 12:13 - 2013-08-23 11:54 - 00000000 ____D C:\Windows\erdnt 2013-08-23 12:11 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-23 12:10 - 2013-04-05 22:00 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-23 12:10 - 2010-11-21 05:47 - 00021504 _____ C:\Windows\PFRO.log 2013-08-23 12:10 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-23 12:10 - 2009-07-14 06:51 - 00043733 _____ C:\Windows\setupact.log 2013-08-23 12:10 - 2009-07-14 04:34 - 55574528 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 19136512 _____ C:\Windows\system32\config\SYSTEM.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\DEFAULT.bak 2013-08-23 12:09 - 2009-07-14 04:34 - 44302336 _____ C:\Windows\system32\config\COMPONENTS.bak 2013-08-23 11:53 - 2013-08-23 11:54 - 05111180 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe 2013-08-23 11:29 - 2013-08-14 12:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-23 11:29 - 2013-04-05 21:53 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-23 11:22 - 2013-08-23 11:22 - 00000000 ____D C:\FRST 2013-08-23 11:19 - 2013-08-23 15:14 - 01576474 _____ (Farbar) C:\Users\*****\Desktop\FRST64.exe 2013-08-23 11:12 - 2013-04-06 07:26 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-23 11:12 - 2013-04-06 07:26 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-23 11:12 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-23 11:07 - 2013-08-14 12:13 - 00000000 ___RD C:\Users\*****\Dropbox 2013-08-23 11:03 - 2013-08-23 15:04 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun 2013-08-23 10:55 - 2013-08-23 10:56 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-23 10:55 - 2013-08-23 10:56 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 10:55 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java 2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe 2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor 2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤 2013-08-22 16:22 - 2013-04-06 14:00 - 00000000 ____D C:\Users\*****\AppData\Local\Paint.NET 2013-08-21 23:36 - 2013-08-12 10:20 - 00000000 ____D C:\Users\*****\Desktop\DLs 2013-08-21 19:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip 2013-08-21 12:47 - 2013-08-21 12:46 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart 2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft 2013-08-20 10:45 - 2013-05-07 18:57 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 10:45 - 2013-04-05 22:37 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-20 10:45 - 2013-04-05 22:37 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-19 23:01 - 2013-08-19 21:58 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds 2013-08-19 14:14 - 2013-04-06 14:00 - 00000000 ____D C:\Program Files\Paint.NET 2013-08-18 10:56 - 2013-08-19 20:08 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack 2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds 2013-08-17 19:56 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-17 18:24 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-17 00:01 - 2013-08-16 21:34 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds 2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner 2013-08-15 14:02 - 2013-08-15 14:00 - 00000000 ____D C:\Program Files\s3pe 2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones 2013-08-15 13:56 - 2013-08-15 13:55 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds 2013-08-14 18:20 - 2013-08-14 18:19 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 18:19 - 2013-04-05 23:56 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 12:13 - 2013-04-05 21:52 - 00000000 ____D C:\Users\***** 2013-08-13 18:24 - 2013-04-28 11:52 - 00000000 ____D C:\Users\*****\AppData\Roaming\HpUpdate 2013-08-13 12:13 - 2013-04-06 18:25 - 00000000 ___RD C:\Users\*****\Desktop\***** 2013-08-06 21:01 - 2013-08-06 18:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-04 20:39 - 2013-07-10 19:11 - 00000000 ____D C:\Users\*****\.gimp-2.8 2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-08-03 10:43 - 2010-11-21 09:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-28 16:53 - 2013-04-06 18:47 - 00000000 ____D C:\Users\*****\Documents\Electronic Arts 2013-07-28 16:52 - 2013-04-06 18:32 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-07-28 16:52 - 2013-04-05 22:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-26 07:13 - 2013-08-14 18:23 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 18:23 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 18:23 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 18:23 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 18:23 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 18:23 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 18:23 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 18:23 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 18:23 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 18:23 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 17:55 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 17:55 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-24 18:43 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-23 12:46 ==================== End Of Log ============================ |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über Avira die anderen Logs? Und FRST muss nach all diesen Tools laufen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | ![]() TR/Dropper.gen Meldung über Avira Ahso schuldigung, ja hab es so gemacht wie du geschrieben hast. Hier die anderen Logs: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.08.23.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 ***** :: *****-PC [Administrator] 23.08.2013 15:01:27 mbam-log-2013-08-23 (15-01-27).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 242578 Laufzeit: 1 Minute(n), 28 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.000 - Report created 23/08/2013 at 15:04:10 # Updated 20/08/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : ***** - *****-PC # Running from : C:\Users\*****\Desktop\adwcleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Babylon.xml File Found : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\Babylon.xml ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\prefs.js ] ************************* AdwCleaner[R0].txt - [10921 octets] - [23/08/2013 11:04:42] AdwCleaner[R1].txt - [992 octets] - [23/08/2013 15:04:10] AdwCleaner[S0].txt - [10863 octets] - [23/08/2013 11:05:14] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1112 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.4 (08.22.2013:1) OS: Windows 7 Home Premium x64 Ran by ***** on 23.08.2013 at 15:05:11,75 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs ~~~ Files ~~~ Folders ~~~ FireFox Failed to delete: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" Successfully deleted: [File] "C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml" Successfully deleted: [File] C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\yxsx9q0c.default\searchplugins\babylon.xml Emptied folder: C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\yxsx9q0c.default\minidumps [15 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 23.08.2013 at 15:14:14,59 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Das FRST Log hast du ja schon Geändert von Ebo (23.08.2013 um 14:54 Uhr) Grund: Logs vergessen |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über AviraESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
gruß, schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!
![]() | ![]() TR/Dropper.gen Meldung über AviraCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=8e4bc6392f435b45bffdc48ea65f957f # engine=14881 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-23 07:26:11 # local_time=2013-08-23 09:26:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 96 40137 12092294 32923 0 # compatibility_mode=5893 16776573 100 94 11863 128915821 0 0 # scanned=307087 # found=2 # cleaned=0 # scan_time=5422 sh=2378F5B19F07882A594876E755399F0434A6F3A9 ft=1 fh=c71c001134773971 vn="a variant of Win32/Kryptik.BIPP trojan" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe" sh=2378F5B19F07882A594876E755399F0434A6F3A9 ft=1 fh=c71c001134773971 vn="a variant of Win32/Kryptik.BIPP trojan" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-08-2013 01 Ran by ***** (administrator) on 23-08-2013 21:31:48 Running from C:\Users\*****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VI1AYTE6 Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe () C:\Program Files (x86)\Tor\tor.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alienware) C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe (PowerISO Computing, Inc.) C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe (Alienware) C:\Program Files\Alienware\Command Center\ThermalController.exe (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6419560 2011-11-21] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-21] (Realtek Semiconductor) HKLM\...\Run: [Launch Keyboard CI] - C:\Program Files\Alienware\Alienware TactX Keyboard CI\txkbci.exe [3439928 2012-07-11] (Alienware) HKLM\...\Run: [Command Center Controllers] - C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [12656 2012-07-25] (Alienware) HKCU\...\Run: [HP Photosmart 5510 series (NET)] - C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2676584 2011-09-16] (Hewlett-Packard Co.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [RUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [180224 2009-07-27] (PowerISO Computing, Inc.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "$" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "$" FF NetworkProxy: "ssl", "$" FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\icq-search.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{4EA20D6D-D7F6-4C7D-A61F-EA5ECBA9A302}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{BCAFAC8D-52F8-440B-B859-12339354365D}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{D8DE6131-5A57-473B-B1CC-3198470737B2}.xml FF SearchPlugin: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\searchplugins\{F117ECFC-ECBC-4B1D-997F-D7C69D90110F}.xml FF Extension: LavaFox V2-Blue - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\djziggy@gmail.com FF Extension: No Name - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\yxsx9q0c.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-08-23] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-05] (Avira Operations GmbH & Co. KG) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [26072 2012-08-08] (Intel Corporation) R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2013-02-08] (Renesas Electronics Corporation) R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [216064 2011-09-15] (Renesas Electronics Corporation) S3 BTMCOM; System32\Drivers\btmcom.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-23 19:54 - 2013-08-23 19:54 - 00000000 ____D C:\Program Files (x86)\ESET 2013-08-23 15:15 - 2013-08-23 15:15 - 00032854 _____ C:\Users\*****\Desktop\FRST.txt 2013-08-23 15:14 - 2013-08-23 15:14 - 00001277 _____ C:\Users\*****\Desktop\JRT.txt 2013-08-23 15:05 - 2013-08-23 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-08-23 15:05 - 2013-08-23 14:55 - 01021434 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-23 15:04 - 2013-08-23 11:03 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-23 15:00 - 2013-08-23 15:00 - 00001111 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-23 15:00 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-23 12:14 - 2013-08-23 12:14 - 00015735 _____ C:\ComboFix.txt 2013-08-23 12:02 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-23 12:02 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-23 12:02 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-23 12:02 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-23 11:54 - 2013-08-23 12:14 - 00000000 ____D C:\Qoobox 2013-08-23 11:54 - 2013-08-23 12:13 - 00000000 ____D C:\Windows\erdnt 2013-08-23 11:54 - 2013-08-23 11:53 - 05111180 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe 2013-08-23 11:22 - 2013-08-23 11:22 - 00000000 ____D C:\FRST 2013-08-23 11:04 - 2013-08-23 15:50 - 00000000 ____D C:\AdwCleaner 2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun 2013-08-23 10:56 - 2013-08-23 10:55 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-23 10:56 - 2013-08-23 10:55 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 10:56 - 2013-08-23 10:55 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java 2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe 2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor 2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤™ 2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip 2013-08-21 12:46 - 2013-08-21 12:47 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart 2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft 2013-08-19 21:58 - 2013-08-19 23:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds 2013-08-19 20:08 - 2013-08-18 10:56 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack 2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds 2013-08-16 21:34 - 2013-08-17 00:01 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds 2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner 2013-08-15 14:00 - 2013-08-15 14:02 - 00000000 ____D C:\Program Files\s3pe 2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones 2013-08-15 13:55 - 2013-08-15 13:56 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds 2013-08-14 18:23 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 18:23 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 18:23 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 18:23 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 18:23 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 18:23 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 18:23 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 18:23 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 18:23 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 18:23 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 18:23 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 18:23 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 18:23 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 18:23 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 18:19 - 2013-08-14 18:20 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 17:56 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 17:56 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 17:56 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 17:56 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 17:55 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 17:55 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 17:55 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 17:55 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 17:55 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 17:55 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 17:55 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 17:55 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 17:55 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 17:55 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 17:55 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 17:55 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 17:55 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 17:55 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 17:55 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 17:55 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 17:55 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 17:55 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 17:55 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 12:13 - 2013-08-23 11:07 - 00000000 ___RD C:\Users\*****\Dropbox 2013-08-14 12:01 - 2013-08-23 11:29 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-12 10:20 - 2013-08-21 23:36 - 00000000 ____D C:\Users\*****\Desktop\DLs 2013-08-06 18:28 - 2013-08-06 21:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions ==================== One Month Modified Files and Folders ======= 2013-08-23 21:01 - 2013-04-28 11:53 - 00000254 _____ C:\Windows\Tasks\HP Photo Creations Messager.job 2013-08-23 19:54 - 2013-08-23 19:54 - 00000000 ____D C:\Program Files (x86)\ESET 2013-08-23 19:54 - 2013-04-06 07:26 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-23 19:54 - 2013-04-06 07:26 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-23 19:54 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-23 19:50 - 2013-08-23 21:28 - 00891115 _____ C:\Users\*****\Desktop\SecurityCheck.exe 2013-08-23 19:17 - 2013-04-05 21:32 - 01660242 _____ C:\Windows\WindowsUpdate.log 2013-08-23 18:06 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-23 18:06 - 2009-07-14 06:45 - 00025648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-23 17:58 - 2013-04-05 22:00 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-23 17:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-23 17:58 - 2009-07-14 06:51 - 00043789 _____ C:\Windows\setupact.log 2013-08-23 15:50 - 2013-08-23 11:04 - 00000000 ____D C:\AdwCleaner 2013-08-23 15:15 - 2013-08-23 15:15 - 00032854 _____ C:\Users\*****\Desktop\FRST.txt 2013-08-23 15:14 - 2013-08-23 15:14 - 00001277 _____ C:\Users\*****\Desktop\JRT.txt 2013-08-23 15:05 - 2013-08-23 15:05 - 00000000 ____D C:\Windows\ERUNT 2013-08-23 15:00 - 2013-08-23 15:00 - 00001111 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-23 15:00 - 2013-08-23 15:00 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-23 14:55 - 2013-08-23 15:05 - 01021434 _____ (Thisisu) C:\Users\*****\Desktop\JRT.exe 2013-08-23 12:14 - 2013-08-23 12:14 - 00015735 _____ C:\ComboFix.txt 2013-08-23 12:14 - 2013-08-23 11:54 - 00000000 ____D C:\Qoobox 2013-08-23 12:14 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-08-23 12:13 - 2013-08-23 11:54 - 00000000 ____D C:\Windows\erdnt 2013-08-23 12:11 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-23 12:10 - 2010-11-21 05:47 - 00021504 _____ C:\Windows\PFRO.log 2013-08-23 12:10 - 2009-07-14 04:34 - 55574528 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 19136512 _____ C:\Windows\system32\config\SYSTEM.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-08-23 12:10 - 2009-07-14 04:34 - 00262144 _____ C:\Windows\system32\config\DEFAULT.bak 2013-08-23 12:09 - 2009-07-14 04:34 - 44302336 _____ C:\Windows\system32\config\COMPONENTS.bak 2013-08-23 11:53 - 2013-08-23 11:54 - 05111180 ____R (Swearware) C:\Users\*****\Desktop\ComboFix.exe 2013-08-23 11:29 - 2013-08-14 12:01 - 00000000 ____D C:\Users\*****\AppData\Roaming\Dropbox 2013-08-23 11:29 - 2013-04-05 21:53 - 00000000 ___RD C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-23 11:22 - 2013-08-23 11:22 - 00000000 ____D C:\FRST 2013-08-23 11:07 - 2013-08-14 12:13 - 00000000 ___RD C:\Users\*****\Dropbox 2013-08-23 11:03 - 2013-08-23 15:04 - 00975858 _____ C:\Users\*****\Desktop\adwcleaner.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-08-23 10:56 - 2013-08-23 10:56 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-08-23 10:56 - 2013-08-23 10:56 - 00000000 ____D C:\ProgramData\Sun 2013-08-23 10:55 - 2013-08-23 10:56 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-08-23 10:55 - 2013-08-23 10:56 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-08-23 10:55 - 2013-08-23 10:56 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-08-23 10:55 - 2013-08-23 10:55 - 00000000 ____D C:\Program Files (x86)\Java 2013-08-23 10:54 - 2013-08-23 10:54 - 00903080 _____ (Oracle Corporation) C:\Users\*****\Downloads\JavaSetup7u25.exe 2013-08-23 10:17 - 2013-08-23 10:17 - 00000000 ____D C:\Program Files (x86)\Tor 2013-08-22 21:59 - 2013-08-22 21:59 - 99814594 _____ C:\Windows\SysWOW64\থऽ赤™ 2013-08-22 16:22 - 2013-04-06 14:00 - 00000000 ____D C:\Users\*****\AppData\Local\Paint.NET 2013-08-21 23:36 - 2013-08-12 10:20 - 00000000 ____D C:\Users\*****\Desktop\DLs 2013-08-21 19:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-21 17:52 - 2013-08-21 17:52 - 15899557 _____ C:\Users\*****\Desktop\bauantragsformulare.zip 2013-08-21 12:47 - 2013-08-21 12:46 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Grundstücksart 2013-08-21 11:03 - 2013-08-21 11:03 - 00000000 ____D C:\Users\*****\Desktop\Gemeinschaftsgrundstücke - nach Nachbarschaft 2013-08-20 10:45 - 2013-05-07 18:57 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 10:45 - 2013-04-05 22:37 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-20 10:45 - 2013-04-05 22:37 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-19 23:01 - 2013-08-19 21:58 - 00000000 ____D C:\Users\*****\Desktop\2013-08-19 Worlds 2013-08-19 14:14 - 2013-04-06 14:00 - 00000000 ____D C:\Program Files\Paint.NET 2013-08-18 10:56 - 2013-08-19 20:08 - 77797091 _____ C:\Users\*****\Desktop\2013-08-18_Objekte.Sims3Pack 2013-08-17 23:45 - 2013-08-17 23:45 - 00000000 ____D C:\Users\*****\Desktop\2013-08-17 Worlds 2013-08-17 19:56 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-17 18:24 - 2013-04-06 12:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-17 00:01 - 2013-08-16 21:34 - 00000000 ____D C:\Users\*****\Desktop\2013-08-16 Worlds 2013-08-15 14:03 - 2013-08-15 14:03 - 00000000 ____D C:\Users\*****\Desktop\Neuer Ordner 2013-08-15 14:02 - 2013-08-15 14:00 - 00000000 ____D C:\Program Files\s3pe 2013-08-15 14:00 - 2013-08-15 14:00 - 00000000 ____D C:\Users\*****\AppData\Roaming\Peter L Jones 2013-08-15 13:56 - 2013-08-15 13:55 - 00000000 ____D C:\Users\*****\Desktop\2013-08-15 Worlds 2013-08-14 18:20 - 2013-08-14 18:19 - 00000000 ____D C:\Windows\system32\MRT 2013-08-14 18:19 - 2013-04-05 23:56 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-14 12:13 - 2013-04-05 21:52 - 00000000 ____D C:\Users\***** 2013-08-13 18:24 - 2013-04-28 11:52 - 00000000 ____D C:\Users\*****\AppData\Roaming\HpUpdate 2013-08-13 12:13 - 2013-04-06 18:25 - 00000000 ___RD C:\Users\*****\Desktop\***** 2013-08-06 21:01 - 2013-08-06 18:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-08-04 20:39 - 2013-07-10 19:11 - 00000000 ____D C:\Users\*****\.gimp-2.8 2013-08-04 20:38 - 2013-08-04 20:38 - 00001458 _____ C:\Users\*****\AppData\Local\recently-used.xbel 2013-08-03 10:43 - 2010-11-21 09:16 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-07-28 16:53 - 2013-04-06 18:47 - 00000000 ____D C:\Users\*****\Documents\Electronic Arts 2013-07-28 16:52 - 2013-04-06 18:32 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2013-07-28 16:52 - 2013-04-05 22:17 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-26 07:13 - 2013-08-14 18:23 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-26 07:13 - 2013-08-14 18:23 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-26 07:13 - 2013-08-14 18:23 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-26 07:12 - 2013-08-14 18:23 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-26 07:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-26 05:35 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-26 05:13 - 2013-08-14 18:23 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-26 05:13 - 2013-08-14 18:23 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-26 05:12 - 2013-08-14 18:23 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-26 05:11 - 2013-08-14 18:23 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-26 05:11 - 2013-08-14 18:23 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-26 04:49 - 2013-08-14 18:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-26 04:39 - 2013-08-14 18:23 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-26 03:59 - 2013-08-14 18:23 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-25 11:25 - 2013-08-14 17:55 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-25 10:57 - 2013-08-14 17:55 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-24 21:24 - 2013-07-24 21:24 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-24 18:43 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-23 12:46 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Das einzige Problem wäre: Was sind das für zwei Dateien die Eset jetzt noch gefunden hat? Und noch viel wichtiger: Wo kam die ganze Sache überhaupt her? Meine Freundin meidet eigentlich so gut wie alle Seiten, die sie nicht kennt. Und die auf denen sie sich regelmäßig bewegt hatten bisher noch nie was. Ansonsten gab es ja keine großen Probleme, außer, dass Avira dauernt gemeckert hat :]. Die Kiste lief trotzdem reibungslos. Zumindest gefühlt, aber offenbar scheint ja doch was dagewesen zu sein oder da zu sein. Grüßle Geändert von Ebo (23.08.2013 um 20:40 Uhr) Grund: Änderung im Post |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über Avira Woher sowas kommt ist nicht nachzuvollziehen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Windows\System32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "$" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "$" FF NetworkProxy: "ssl", "$" Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
![]() | ![]() TR/Dropper.gen Meldung über AviraCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-08-2013 Ran by Dani at 2013-08-24 12:11:40 Run:1 Running from C:\Users\*****\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Windows\System32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe FF NetworkProxy: "backup.ftp", "" FF NetworkProxy: "backup.ftp_port", 0 FF NetworkProxy: "backup.socks", "" FF NetworkProxy: "backup.socks_port", 0 FF NetworkProxy: "backup.ssl", "" FF NetworkProxy: "backup.ssl_port", 0 FF NetworkProxy: "ftp", "$" FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "socks", "$" FF NetworkProxy: "ssl", "$" ***************** "C:\Windows\System32\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe" => File/Directory not found. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Windows Internet Name Service\wins.exe => Moved successfully. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. ==== End of Fixlog ==== |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() TR/Dropper.gen Meldung über Avira Fertig ![]() Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | ![]() TR/Dropper.gen Meldung über Avira Danke für die Hilfe ![]() |
