| ![]() t-online Brief erhalten (hackerangriffe wurden angeblich ausgeführt) So, vor einigen Tagen erhielt ich einen Brief von T-online, dass angeblich von meinem Computer bzw. dem Familien-Netzwerk schädliche Internet-Angriffe durchgeführt wurden. Nachdem ich nun auf jedem unserer Computer 2 Virenscans (mit G-Data und Avast), sowie eine Bereinigung mit dem CCleaner durchgeführt habe kam heute der 2 Brief, in dem stand, dass sämtliche Email-Accounts vorerst gesperrt sind. Da muss doch was schlimmes im Netzwerk umhergehen. Als bitte an euch möchte ich, dass dieses Problem schnellstmöglich behandelt wird, denn ohne Email geht bei uns nichts. Angefangen mit PC #1 (da das ganze Netzwerk betroffen ist müssen auch 3 Rechner "bereinigt" werde): Als erstes die OTL.txt Code:
ATTFilter OTL logfile created on: 31.08.2013 13:59:49 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Max\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 5,81 Gb Available Physical Memory | 73,47% Memory free 15,83 Gb Paging File | 13,69 Gb Available in Paging File | 86,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 247,85 Gb Free Space | 53,23% Space Free | Partition Type: NTFS Drive D: | 445,76 Gb Total Space | 0,01 Gb Free Space | 0,00% Space Free | Partition Type: NTFS Drive E: | 19,99 Gb Total Space | 10,68 Gb Free Space | 53,40% Space Free | Partition Type: FAT32 Drive F: | 6,76 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: MAX-PC | User Name: Max | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Max\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Programme\AVAST Software\Avast\AvastUI.exe (AVAST Software) PRC - C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software) PRC - C:\Windows\SysWOW64\PnkBstrA.exe () PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) PRC - C:\Programme\Tablet\Pen\WacomHost.exe (Wacom Technology) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org) PRC - C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtWlan.exe (ASUSTeK Computer Inc.) PRC - C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtlService.exe (Realtek) PRC - C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.) PRC - C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Symantec Corporation) PRC - C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (CyberLink) ========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll () MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () MOD - C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll () MOD - c:\progra~2\safesa~1\sprote~1.dll () MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll () ========== Services (SafeList) ========== SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (avast! Antivirus) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software) SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe () SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) SRV - (WTabletServiceCon) -- C:\Programme\Tablet\Pen\WTabletServiceCon.exe (Wacom Technology, Corp.) SRV - (AsusSE) -- C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtlService.exe (Realtek) SRV - (nlsX86cc) -- C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.) SRV - (cFosSpeedS) -- C:\Programme\ASRock\XFast LAN\spd.exe (cFos Software GmbH) SRV - (NIS) -- C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Symantec Corporation) SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) SRV - (SmartViewService) -- C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe (DeviceVM, Inc.) SRV - (WCUService) -- C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe (DeviceVM, Inc.) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software) DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software) DRV:64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys () DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software) DRV:64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys () DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software) DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software) DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software) DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation) DRV:64bit: - (RTL8192Ce) -- C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation ) DRV:64bit: - (FNETURPX) -- C:\Windows\SysNative\drivers\FNETURPX.SYS (FNet Co., Ltd.) DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation) DRV:64bit: - (WacHidRouter) -- C:\Windows\SysNative\drivers\wachidrouter.sys (Wacom Technology) DRV:64bit: - (hidkmdf) -- C:\Windows\SysNative\drivers\hidkmdf.sys (Windows (R) Win 7 DDK provider) DRV:64bit: - (wacomrouterfilter) -- C:\Windows\SysNative\drivers\wacomrouterfilter.sys (Wacom Technology) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (FanatecWheelFilterUsb) -- C:\Windows\SysNative\drivers\FWFilterUsb.sys (Windows (R) Codename Longhorn DDK provider) DRV:64bit: - (cFosSpeed) -- C:\Windows\SysNative\drivers\cfosspeed6.sys (cFos Software GmbH) DRV:64bit: - (VirtuWDDM) -- C:\Windows\SysNative\drivers\VirtuWDDM.sys (Lucidlogix Inc.) DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\NISx64\1207020.003\symnets.sys (Symantec Corporation) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (mvs91xx) -- C:\Windows\SysNative\drivers\mvs91xx.sys (Marvell Semiconductor, Inc.) DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\NISx64\1207020.003\srtsp64.sys (Symantec Corporation) DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\NISx64\1207020.003\srtspx64.sys (Symantec Corporation) DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\NISx64\1207020.003\symefa64.sys (Symantec Corporation) DRV:64bit: - (k57nd60a) -- C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation) DRV:64bit: - (EtronXHCI) -- C:\Windows\SysNative\drivers\EtronXHCI.sys (Etron Technology Inc) DRV:64bit: - (EtronHub3) -- C:\Windows\SysNative\drivers\EtronHub3.sys (Etron Technology Inc) DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\NISx64\1207020.003\symds64.sys (Symantec Corporation) DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\NISx64\1207020.003\ironx64.sys (Symantec Corporation) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation) DRV:64bit: - (AsrAppCharger) -- C:\Windows\SysNative\drivers\AsrAppCharger.sys (Windows (R) Win 7 DDK provider) DRV:64bit: - (MBfilt) -- C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.) DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\EX64.SYS (Symantec Corporation) DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation) DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation) DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\ENG64.SYS (Symantec Corporation) DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx64.sys (Symantec Corporation) DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVia64.sys (Symantec Corporation) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.easylifeapp.com/?pid=512&src=ie1&r=2013/06/16&hid=1493084629&lg=EN&cc=DE IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6}: "URL" = hxxp://search.easylifeapp.com/?q={searchTerms}&pid=512&src=ie2&r=2013/06/16&hid=1493084629&lg=EN&cc=DE IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 30 98 71 9F 94 33 CE 01 [binary data] IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files (x86)\DeviceVM\SmartView\AddressBarSearch.dll (DeviceVM, Inc.) IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6}: "URL" = hxxp://search.easylifeapp.com/?q={searchTerms}&pid=512&src=ie2&r=2013/06/16&hid=1493084629&lg=EN&cc=DE IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\SearchScopes\{81E806A5-46EE-49DA-9EFC-064FEAEBE60F}: "URL" = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=FC3831F8-9CB6-49DC-94B1-C39A904BFC7E&apn_sauid=DBB3DDFE-C0EF-452E-B08D-2449E06980A7 IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\SearchScopes\{EA574F84-4C80-432c-B70D-562CED90B104}: "URL" = hxxp://www.google.com/custom?client=pub-3794288947762788&forid=1&channel=5480255188&ie=UTF-8&oe=UTF-8&safe=active&cof=GALT%3A%23008000%3BGL%3A1%3BDIV%3A%23336699%3BVLC%3A663399%3BAH%3Acenter%3BBGC%3AFFFFFF%3BLBGC%3A336699%3BALC%3A0000FF%3BLC%3A0000FF%3BT%3A000000%3BGFNT%3A0000FF%3BGIMP%3A0000FF%3BFORID%3A1&hl=de&q={searchTerms} IE - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.defaultenginename,S: S", "" FF - prefs.js..browser.search.defaultthis.engineName: "" FF - prefs.js..browser.search.defaulturl: "" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.order.1,S: S", "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.search.selectedEngine,S: S", "" FF - prefs.js..browser.startup.homepage: "hxxp://www.google.com/" FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0.1 FF - prefs.js..keyword.URL: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "" FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "" FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF:64bit: - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version= C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.4: C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.7: C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version= C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2013.04.08 17:01:07 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 [2013.08.31 13:53:42 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.08.25 19:02:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.04.08 21:43:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Max\AppData\Roaming\mozilla\Extensions [2013.08.30 17:46:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions [2013.08.30 17:46:53 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ========== Chrome ========== CHR - homepage: hxxp://www.google.de/ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbkjepneoomjodcmphebgobdinjoiad\1\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgkogmmlmfijkljjnhalncbabkljhceo\0.2_0\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\2.4.3_0\ CHR - Extension: No name found = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation) O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O2 - BHO: (SmartView VisualBookmark) - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\DeviceVM\SmartView\SmartView.dll (DeviceVM, Inc.) O2 - BHO: (Search-NeuWWTab) - {15DE79EA-B60C-674F-C111-4E827FC5C6B1} - C:\ProgramData\Search-NeuWWTab\51703b13d77f2.dll () O2 - BHO: (Search-NeuWWTab) - {1EA1558A-FD42-3B24-C760-5BAEDA12BF97} - C:\ProgramData\Search-NeuWWTab\517053bf97d72.dll () O2 - BHO: (Browwse2siAvee) - {5807C1BC-9472-A080-48F5-067D09BD0920} - C:\ProgramData\Browwse2siAvee\51703afdeb1b7.dll () O2 - BHO: (safe Saave) - {5EAA53FA-9A49-0815-D346-340A52DECABE} - C:\ProgramData\safe Saave\51bda6ebb650a.dll () O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPS\IPSBHO.DLL (Symantec Corporation) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (SearchNewTab) - {B0A3DECF-0C8D-4E9D-48D8-9607E3729075} - C:\ProgramData\SearchNewTab\51bda7063d147.dll () O2 - BHO: (Browwse2siAvee) - {CCFE5824-3446-7DD4-ED63-644CC4181B6E} - C:\ProgramData\Browwse2siAvee\517053bbddda5.dll () O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKLM\..\Toolbar: (no name) - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No CLSID value found. O3 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [EPSON Stylus DX4200 Series] C:\Windows\SysNative\spool\DRIVERS\x64\3\E_FATIAEE.EXE (SEIKO EPSON CORPORATION) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [WinUpdate] C:\Windows\SysNative\WinUpdate.exe () O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.) O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000..\Run: [AdobeBridge] File not found O4 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000..\Run: [ASRockXTU] File not found O4 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000..\Run: [EADM] C:\Program Files\Origin\Origin.exe (Electronic Arts) O4 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000..\Run: [zASRockInstantBoot] File not found O4 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1EEBF17B-9A87-41BB-BF30-7F350F16E819}: DhcpNameServer = O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51605ADB-249B-4E99-8EE1-CC91CCCB16F7}: DhcpNameServer = O20:64bit: - AppInit_DLLs: (C:\PROGRA~1\LUCIDL~1\VIRTU\APPINI~1.DLL) - C:\Programme\Lucidlogix Technologies\VIRTU\appinit_dll.dll (Lucidlogix Inc.) O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation) O20 - AppInit_DLLs: (c:\progra~1\lucidl~1\virtu\x86\appini~1.dll) - c:\Programme\Lucidlogix Technologies\VIRTU\x86\appinit_dll.dll (Lucidlogix Inc.) O20 - AppInit_DLLs: (c:\windows\syswow64\nvinit.dll c:\progra~2\safesa~1\sprote~1.dll) - c:\windows\syswow64\nvinit.dll (NVIDIA Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2013.07.07 00:14:40 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2011.01.27 20:06:10 | 000,464,144 | R--- | M] (Electronic Arts) - F:\AutoRun.exe -- [ CDFS ] O32 - AutoRun File - [2011.05.11 11:35:42 | 000,000,000 | ---D | M] - F:\Autorun -- [ CDFS ] O32 - AutoRun File - [2011.03.08 14:33:03 | 034,599,936 | R--- | M] () - F:\autorun.dat -- [ CDFS ] O32 - AutoRun File - [2011.03.08 18:33:54 | 000,000,147 | R--- | M] () - F:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{e2962c8c-9f84-11e2-bfa9-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{e2962c8c-9f84-11e2-bfa9-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2011.01.27 20:06:10 | 000,464,144 | R--- | M] (Electronic Arts) O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013.08.31 13:57:49 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe [2013.08.30 17:46:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox [2013.08.27 17:43:36 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2013.08.27 17:30:08 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\backup handy 27.08.13 [2013.08.25 19:03:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus [2013.08.25 19:03:07 | 000,033,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys [2013.08.25 19:03:06 | 000,378,944 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2013.08.25 19:03:03 | 000,072,016 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys [2013.08.25 19:03:02 | 001,030,952 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2013.08.25 19:03:02 | 000,064,288 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys [2013.08.25 19:02:50 | 000,287,840 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe [2013.08.25 19:02:50 | 000,080,816 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys [2013.08.25 19:02:34 | 000,041,664 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr [2013.08.25 19:02:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2013.08.25 19:02:02 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software [2013.08.23 15:35:20 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\download-downloadfile-26830 [2013.08.22 17:23:59 | 000,312,232 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe [2013.08.22 17:23:55 | 000,189,352 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe [2013.08.22 17:23:55 | 000,188,840 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe [2013.08.22 17:23:55 | 000,108,968 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll [2013.08.22 17:23:52 | 000,000,000 | ---D | C] -- C:\Program Files\Java [2013.08.22 17:21:20 | 001,093,032 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll [2013.08.22 17:21:20 | 000,972,712 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll [2013.08.22 16:07:22 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1 [2013.08.22 15:59:23 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\.minecraft [2013.08.22 15:58:55 | 000,000,000 | ---D | C] -- C:\Users\Max\Desktop\Minecraft1.6.1-Wazez [2013.08.22 15:49:50 | 000,000,000 | ---D | C] -- C:\Users\Max\AppData\Roaming\.minecraft - Kopie (2) [2013.08.14 15:32:31 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013.08.14 15:32:31 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013.08.14 15:32:30 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll [2013.08.14 15:32:30 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll [2013.08.14 15:32:30 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe [2013.08.14 15:32:30 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe [2013.08.14 15:32:30 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2013.08.14 15:32:30 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2013.08.14 15:32:30 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2013.08.14 15:32:30 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2013.08.14 15:32:30 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2013.08.14 15:32:29 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013.08.14 15:32:29 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013.08.14 15:32:29 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013.08.14 15:32:29 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013.08.14 14:30:00 | 001,472,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll [2013.08.14 14:29:59 | 000,224,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wintrust.dll [2013.08.14 14:29:59 | 000,139,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll [2013.08.14 14:29:51 | 001,888,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL [2013.08.14 14:29:51 | 001,620,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL [2013.08.14 14:29:48 | 001,217,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll [2013.08.14 14:29:43 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013.08.14 14:29:42 | 005,550,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013.08.14 14:29:42 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013.08.14 14:29:41 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll [2013.08.14 14:29:41 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll [2013.08.14 14:29:40 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2013.08.14 14:29:40 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2013.08.14 14:29:40 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe [2013.08.14 14:29:40 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2013.08.14 14:29:40 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013.08.14 14:29:40 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2013.08.14 14:29:40 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013.08.14 14:29:40 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2013.08.14 14:29:40 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013.08.14 14:29:40 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2013.08.14 14:29:40 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2013.08.14 14:29:40 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2013.08.14 14:29:40 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2013.08.14 14:29:40 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013.08.14 14:29:40 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2013.08.14 14:29:40 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2013.08.14 14:29:40 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2013.08.14 14:29:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013.05.11 01:32:02 | 018,045,440 | ---- | C] (Profibot) -- C:\Users\Max\AppData\Roaming\IBot.exe [3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013.08.31 14:00:48 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.08.31 14:00:48 | 000,021,856 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.08.31 13:57:51 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Max\Desktop\OTL.exe [2013.08.31 13:53:54 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013.08.31 13:53:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.08.31 13:53:26 | 2078,732,287 | -HS- | M] () -- C:\hiberfil.sys [2013.08.31 09:41:00 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013.08.31 09:39:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.08.29 16:40:25 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr [2013.08.29 16:40:25 | 000,290,184 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013.08.29 16:39:30 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0 [2013.08.27 17:44:05 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk [2013.08.27 17:30:27 | 001,613,340 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.08.27 17:30:27 | 000,696,832 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.08.27 17:30:27 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.08.27 17:30:27 | 000,148,128 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.08.27 17:30:27 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.08.25 19:03:12 | 001,030,952 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys [2013.08.25 19:03:12 | 000,378,944 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys [2013.08.25 19:03:12 | 000,189,936 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys [2013.08.25 19:03:12 | 000,000,175 | ---- | M] () -- C:\Windows\SysNative\drivers\aswVmm.sys.sum [2013.08.25 19:03:12 | 000,000,175 | ---- | M] () -- C:\Windows\SysNative\drivers\aswSP.sys.sum [2013.08.25 19:03:12 | 000,000,175 | ---- | M] () -- C:\Windows\SysNative\drivers\aswSnx.sys.sum [2013.08.25 19:03:08 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.08.25 19:02:50 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt [2013.08.25 16:00:02 | 009,931,502 | ---- | M] () -- C:\Users\Max\Desktop\_MG_1284.jpg [2013.08.23 15:35:08 | 000,001,205 | ---- | M] () -- C:\Users\Max\Desktop\download-downloadfile-26830.zip [2013.08.22 18:41:07 | 000,000,834 | ---- | M] () -- C:\Users\Max\Desktop\Minecraft.lnk [2013.08.22 17:23:52 | 001,093,032 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll [2013.08.22 17:23:52 | 000,972,712 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\deployJava1.dll [2013.08.22 17:23:52 | 000,312,232 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe [2013.08.22 17:23:52 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe [2013.08.22 17:23:52 | 000,188,840 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe [2013.08.22 17:23:52 | 000,108,968 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll [2013.08.22 16:06:21 | 000,111,079 | ---- | M] () -- C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1.zip [2013.08.22 15:59:56 | 000,350,720 | ---- | M] () -- C:\Users\Max\Desktop\Minecraft.exe [2013.08.22 15:58:11 | 054,928,642 | ---- | M] () -- C:\Users\Max\Desktop\Minecraft1.6.1-Wazez.zip [2013.08.20 20:39:33 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013.08.20 20:39:33 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013.08.19 22:14:23 | 004,839,500 | ---- | M] () -- C:\Users\Max\Desktop\brennball.jpg [2013.08.19 22:12:20 | 437,283,794 | ---- | M] () -- C:\Users\Max\Desktop\Unbenannt-1.psd [2013.08.13 16:24:14 | 000,805,504 | ---- | M] () -- C:\Users\Max\Desktop\_MG_1059.jpg [2013.08.12 11:42:21 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk [3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2013.08.27 17:44:05 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk [2013.08.27 17:44:04 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk [2013.08.25 19:03:12 | 000,000,175 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys.sum [2013.08.25 19:03:12 | 000,000,175 | ---- | C] () -- C:\Windows\SysNative\drivers\aswSP.sys.sum [2013.08.25 19:03:12 | 000,000,175 | ---- | C] () -- C:\Windows\SysNative\drivers\aswSnx.sys.sum [2013.08.25 19:03:08 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk [2013.08.25 19:03:01 | 000,189,936 | ---- | C] () -- C:\Windows\SysNative\drivers\aswVmm.sys [2013.08.25 19:02:59 | 000,065,336 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRvrt.sys [2013.08.25 19:02:50 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt [2013.08.25 15:59:58 | 009,931,502 | ---- | C] () -- C:\Users\Max\Desktop\_MG_1284.jpg [2013.08.23 15:35:17 | 000,001,205 | ---- | C] () -- C:\Users\Max\Desktop\download-downloadfile-26830.zip [2013.08.22 16:06:40 | 000,019,686 | ---- | C] () -- C:\Users\Max\Desktop\TMIUtils.class [2013.08.22 16:06:40 | 000,009,671 | ---- | C] () -- C:\Users\Max\Desktop\TMIView.class [2013.08.22 16:06:40 | 000,005,522 | ---- | C] () -- C:\Users\Max\Desktop\TMIPrivateFields.class [2013.08.22 16:06:40 | 000,002,240 | ---- | C] () -- C:\Users\Max\Desktop\TMIReplaceItems.class [2013.08.22 16:06:40 | 000,000,714 | ---- | C] () -- C:\Users\Max\Desktop\TMIStateButtonData.class [2013.08.22 16:06:40 | 000,000,559 | ---- | C] () -- C:\Users\Max\Desktop\TMIReplaceItems$SpawnerBlock.class [2013.08.22 16:06:40 | 000,000,473 | ---- | C] () -- C:\Users\Max\Desktop\TMIReplaceItems$MetadataBlock.class [2013.08.22 16:06:40 | 000,000,385 | ---- | C] () -- C:\Users\Max\Desktop\TMIUtils$1.class [2013.08.22 16:06:29 | 000,111,079 | ---- | C] () -- C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1.zip [2013.08.22 15:58:57 | 000,350,720 | ---- | C] () -- C:\Users\Max\Desktop\Minecraft.exe [2013.08.22 15:58:43 | 054,928,642 | ---- | C] () -- C:\Users\Max\Desktop\Minecraft1.6.1-Wazez.zip [2013.08.19 22:14:19 | 004,839,500 | ---- | C] () -- C:\Users\Max\Desktop\brennball.jpg [2013.08.19 22:11:53 | 437,283,794 | ---- | C] () -- C:\Users\Max\Desktop\Unbenannt-1.psd [2013.08.13 16:24:12 | 000,805,504 | ---- | C] () -- C:\Users\Max\Desktop\_MG_1059.jpg [2013.05.26 13:57:34 | 000,000,132 | ---- | C] () -- C:\Users\Max\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen [2013.05.11 01:32:09 | 000,092,160 | ---- | C] () -- C:\Users\Max\AppData\Roaming\chrtmp [2013.04.30 22:24:51 | 001,589,618 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013.04.13 21:07:37 | 000,290,184 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe [2013.04.13 21:07:34 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe [2013.04.07 15:56:06 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll [2013.04.07 15:56:05 | 013,359,616 | ---- | C] () -- C:\Windows\SysWow64\ig4icd32.dll [2013.04.07 15:56:05 | 000,963,116 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin [2013.04.07 15:56:05 | 000,218,304 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin [2013.04.07 15:56:05 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin [2013.04.07 14:38:53 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe [2013.04.07 14:15:04 | 000,001,424 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini [2013.04.07 14:15:04 | 000,001,323 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini [2013.04.07 14:15:04 | 000,001,323 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini [2013.04.07 14:15:02 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2013.04.07 14:15:02 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2013.04.07 14:12:48 | 000,000,003 | ---- | C] () -- C:\Users\Max\AppData\Local\user_data.ini [2012.07.10 06:19:52 | 000,003,584 | ---- | C] () -- C:\Windows\SysWow64\HDREfexPro2FC32.dll [2012.02.10 04:21:24 | 000,003,584 | ---- | C] () -- C:\Windows\SysWow64\ColorEfexPro4FC32.dll [2011.09.28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 07:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 06:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2013.08.25 23:17:01 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\.minecraft [2013.04.30 21:44:08 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\.minecraft - Kopie [2013.08.22 15:50:31 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\.minecraft - Kopie (2) [2013.05.12 16:33:47 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Bierbuden Autoupdate [2013.04.09 18:38:27 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Canon [2013.04.08 21:21:40 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant [2013.04.18 21:42:58 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2013.06.21 18:57:59 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\convert [2013.04.07 14:17:07 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\DeviceVm [2013.04.10 17:26:56 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\dll-files.com [2013.04.09 18:38:27 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\HDRsoft [2013.07.07 00:09:52 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\loadtbs [2013.04.10 17:10:15 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Nik Software [2013.05.26 14:46:26 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Notepad++ [2013.04.09 18:38:27 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\onOne Software [2013.04.16 20:11:49 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\OpenOffice.org [2013.06.06 17:57:11 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Origin [2013.04.09 17:47:00 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\PDAppFlex [2013.06.08 16:45:31 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\SpinTires [2013.04.19 15:04:29 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1 [2013.04.09 18:38:27 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\TS3Client [2013.04.09 18:38:27 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\Wacom [2013.05.10 21:54:53 | 000,000,000 | ---D | M] -- C:\Users\Max\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1 ========== Purity Check ========== < End of report > Code:
ATTFilter OTL Extras logfile created on: 31.08.2013 13:59:49 - Run 1 OTL by OldTimer - Version Folder = C:\Users\Max\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.10.9200.16660) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 7,91 Gb Total Physical Memory | 5,81 Gb Available Physical Memory | 73,47% Memory free 15,83 Gb Paging File | 13,69 Gb Available in Paging File | 86,49% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 247,85 Gb Free Space | 53,23% Space Free | Partition Type: NTFS Drive D: | 445,76 Gb Total Space | 0,01 Gb Free Space | 0,00% Space Free | Partition Type: NTFS Drive E: | 19,99 Gb Total Space | 10,68 Gb Free Space | 53,40% Space Free | Partition Type: FAT32 Drive F: | 6,76 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: MAX-PC | User Name: Max | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) [HKEY_USERS\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htafile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1" http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error. ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall" = 1 "DisableNotifications" = 0 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{00D80132-7B10-4DE9-BD76-2002630FCEE2}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0349DB3D-B110-446E-8DBE-C98521F4B344}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{045C1172-C961-4A9B-B161-C088019F995E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{07D5D82B-9F7D-4C8F-9B87-47AFB0611F6C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0973ED45-3EF0-40C9-8716-E85D84B22D72}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0A253BEA-B78C-49CC-BF81-1CD0A29B68B5}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0B42F405-5A3F-4CE0-98E9-6FB44E185F1E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0E005727-1D89-4125-8ACF-098E44B9AE21}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0EEBEDB6-7EBB-47CC-B069-843DB64A8448}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{0F783D54-4369-4096-9934-8AAF64B531A1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{12E34B37-5C1E-473D-9BDE-E943DCC5429F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{130575B4-E5C9-41D9-9FF9-91752D08DDCF}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{14BAA152-038E-4BA7-BC00-DB9274A5D09E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{15ADA608-29E1-46AD-BEB1-678539053570}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{18C1AC6E-A9F4-42F3-A245-8D91DD3DA976}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{1A970EA3-1B3B-46AA-8C8A-13B489AC038A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{1BA24528-2382-412A-931D-5EF5B0AAEA09}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{1E46FC8C-1616-4013-84BC-330E0977A417}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{1E4E7823-B7EF-4622-B14A-6276B570D898}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{1F3E4DE2-6C4D-4AFA-9FA5-73C8A2F5F455}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{203A67E3-F3E6-406E-A7D3-E4F3F7AE9767}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{21A1B679-42B6-43D1-A9B5-5F52809BDD38}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{231A3B48-0B4B-496A-B3F4-1FB416714AC9}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2402497A-C593-4058-8180-C7CEB5189697}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{245B9C2A-2FAF-49A3-88A8-D076A1AC2F52}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2806692C-3818-4545-82C6-0AA4BAEF576C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{28DF3FAC-A3EE-4C0C-AACE-D964DE21E881}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{29632F5B-79E8-4E8D-BE9D-2245721E764A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2D0298C2-3F85-41BA-BB9A-25C04B5C173D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2E197056-B5DF-4F2F-87F2-FC0199598468}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2E3A9ABC-CB65-457B-908D-2C7F7D16BC18}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2F2817D9-681D-4C44-A1F4-DC30DFB3E596}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2F8213BE-D9E4-474C-847A-192A4876728B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{316B9F39-6BF9-4532-B6A9-866ED6AB832E}" = lport=12345 | protocol=17 | dir=in | name=cubeworld | "{33527FAA-3FD7-462B-BBD9-15EB0AC80039}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{35EDF2AE-C3EE-4E26-85CD-16DB7528B7F6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{36595033-912E-41AC-A5CA-CFA38E72DE53}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3A1CB4CF-2C7D-44D2-995B-46ECA62C3EDD}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3A3B7368-3883-4526-BC58-9153CB27A91D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3C750019-6FFF-4711-B9C6-8D4C3BCA9A4B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3D189970-492C-4CF8-952C-72A7B9497887}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3ECCED60-C27F-4D83-B89D-9D373A6F75C1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3F0CF706-B8FB-4C3A-8AC4-E1CF435D035D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{3FB05A1B-B5AA-466F-B568-E97537DCD263}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{437EA6D1-8338-4BC5-8EDA-3FC434A16A8C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{46216068-12EF-4608-8B0D-589DB3AB2919}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{465A1434-D1FA-477F-8252-864A96CC7DFE}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{47323D1F-271F-46F6-8203-D2BDC20555E1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{4914005E-E55D-4E1E-B284-52E2971732B1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{499ED01F-9F40-4365-A182-4C44C1CCD8C2}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{4B50D8DF-56AD-4220-8A54-91F4C2FCAB1B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{4E8E88E7-22E8-4395-9426-D18327A32E01}" = lport=12345 | protocol=6 | dir=in | name=cubeworld | "{4E99EF6F-F8D1-4622-A029-5D920E2B0BAA}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{4FCC6322-AC70-418E-A657-F8AE1CBE1C2A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{5020E0BA-1548-447D-9B8A-7354D45FA472}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{52BABD15-3D7F-407E-A765-8D4C79B89567}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{54367E33-95E3-4328-81FD-E948A9BF8BAA}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{54FAA299-54EB-40A5-9F68-0B07E4260B3A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{552FCA5F-C894-41D3-9B7D-C19443AC2991}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{55A6F4B5-EF73-4BBE-8CE9-F4577FB0EE93}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{586776B5-3A3F-4E55-85F1-8C916E2F8D0F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{58A29116-1AB2-4AA7-8640-F96C23164A90}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{5B02267F-0081-4B25-9056-39D1E0C916C7}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{5D6F7D6E-B2E3-4DA2-BBF1-784E5F5307BB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{5E145FAB-E0D8-4290-A86D-C7925B673760}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{61C799D6-46EC-44BA-B1B5-52255203168B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{65003007-3B2F-44B5-B415-183B29D32215}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{65CF5583-1C8C-4933-982C-1947DDB1535B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{6772B24C-6F28-4F55-8FCA-0CB70A2A06AE}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{689C32D6-71C8-4A83-8A65-043ACD773385}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{6B3F14A1-FA41-464C-989F-0DA3624A0D64}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{70898FD6-ACCA-46A8-A038-0A78716688B2}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{73182500-AB50-4850-86E6-5C762C79CCFB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{75ED3853-06DE-48C2-ACC4-8CD321B72301}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{7645632B-306A-48D9-AFBE-09C4E1D684FD}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | "{7D27148A-072C-4192-9B7E-F13DB26FEF34}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{7E7EDCFC-4BD3-4660-9EF1-CFAD04F1B0E1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{7E8503F1-263A-44F1-9EE9-3D86EDEC0F03}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{817E455F-9B42-4A0A-A56A-B05F79918AEF}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{82DD8B83-8666-48F6-A95C-5E2A9C2EDC87}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{853B02F1-EE8A-4811-83A4-ECEF18B2DEBA}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{86DB5BD0-9137-41C1-AB93-57695FC34D60}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{86EA3DB7-7A5E-4861-9504-35B82AD0F012}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{89BD6CB7-1CA0-4982-BE7A-BF233AC3E649}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{8FF3CDD5-A2AB-4079-94E3-F4795E10D44C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{91F1F967-4BC3-43EA-BE9B-EDAEEF9F2356}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9286595D-23BB-4AF6-8423-B8A7E33B7C24}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{936A41B0-FDFD-4F38-9290-95C12DACC7B9}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9396134E-D2EE-42A5-A799-78609F7C9C6C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{968ABA55-784B-4378-A7C2-877785387DBD}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{97292631-3AE8-4C22-B511-3C90F89BAF47}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{976E8A34-0AEF-4DA3-A0EE-F22397E68FF1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{989878B3-AA45-44D0-913A-E47026BA4FA9}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9A1FA434-E7B9-4378-BB20-47A556365CEA}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9AD29300-C0F9-4247-B501-5DD03E94BF1F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9B20DE53-F808-4811-AC67-2FA886094460}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9C4C80C5-DB49-452E-888F-6D3DEE6ACFE4}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9D4D7479-970F-420B-97F1-B7FB4753B741}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A0A626D5-124C-4688-ADE0-75CC4455E949}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A235A9B0-6358-4D79-8F04-88324177928C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A3D4B997-46E7-4DF8-B52B-D3F3B03AF7C3}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A5055543-ADB5-42CA-A4E9-7C53FD46F4E6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A62F7B72-24F6-4DF4-A8EC-FCA6E122DA5C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A647932F-FAEA-4AAF-B7DD-A857A3E7945D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{A9E46B82-EA44-4916-AA8B-08358D09BF81}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AB514535-181A-4DB5-BEB3-202AAA24C1A6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AB8319B2-A5C3-4623-966A-D0483B271AC5}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AD50E14E-F596-4F15-BA7F-3DD623CA9534}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AE977BF9-526E-42D5-BFF3-1D955866B8B0}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AF94FD64-DF5D-45FA-AED2-E7DFEE7E4908}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B14BAB37-A4C5-42AB-B9BC-6E6CFA14128B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B2EBCAB4-2AD0-44B7-A2D8-EB61108F428B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B3436F0F-4AA5-4C19-A139-C4B8B9258F04}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B3F9E8D9-E71E-4337-8DB4-EB1100E70016}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B4324742-2FDE-4EA3-8526-A205568DD5CC}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B4B4294E-B2D5-4846-9D0A-B3B712AFCB36}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B4F15BCD-4E64-496C-94F9-43EDBB4701EB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B56B1E48-825D-480B-8787-53DBEF39383A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B693295C-A6C1-4272-B485-4823CDAE1463}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B6B8B616-2FAF-4EC1-BB88-B6A5E0AFBCBD}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B7136A14-7A31-4C91-8000-875C2DC02844}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B783258E-7148-4588-AC3B-A9DB3B0133BB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B7A0C634-8646-4252-9F47-B3BD801CA6A4}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B9B27959-F7D5-4467-A7C9-7B9E47939F7A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{BA2CE814-3E13-4977-ACC1-8F6C269A5D06}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{BAD9C150-C5A2-44D6-85C2-25155D96B08F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{BD92ACDF-6C62-4C26-85FB-964FB592BD23}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{BE5D653C-0684-47DD-8499-F04AC51770B0}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{C0345A11-49E2-4752-AAFD-577A6BCCC60B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{C25814FD-4679-4218-B049-926B87B1F460}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{C4F76AED-8438-4934-A8C3-554F0B37A13E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{C54EF37C-9968-4C83-AFE5-6063095CBFBA}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{C5684284-8D11-45F4-90F1-70EFDE2BF02F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{C6F534A8-4A59-4B6F-AF80-79CB86B55342}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{CD38CA35-FFFA-464F-B296-193E01E8C4BB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{CD752576-DCC6-4F4E-9870-BCC20D93778D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{CEC1A0B1-3D66-477A-B7A7-7A69A79B5797}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{CEFA2317-D29B-45A5-A0FB-101266051AE4}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{D3053C1C-56EB-49B2-839F-6FC1C2107E16}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{D5B9A019-E8E0-4A46-8F76-834CCD50A68B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{D695434C-8892-4A22-AAB8-50DCCD58376C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{D9743D06-1BA0-4480-AAB4-FE4DC0237184}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{DA290CCA-BA10-4DB0-8FE7-1526122EB51B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{DF9F1603-4B38-4E58-B844-63134DCE531C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{DFFC63A5-7D7D-4352-946E-FEE006AB7969}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E0651EBE-31E3-4666-A545-A401AD154180}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E12B39EF-0CED-4397-8A7C-DAD29FA823F0}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E2FFEB4C-0E73-4132-AD10-5CFC4751F5A9}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E350E3CE-C489-42A8-8EDD-A39D09D8A4C3}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E47A5538-AEC8-46A9-83B8-ED642CCAE605}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E53DC61F-5DDB-48AF-A237-6DB85553ABC1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E65B480B-C570-480E-BDD3-2998AAA80A0B}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{E7178DB1-C21C-4312-924E-988029023B0F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{EB7A1961-282D-4B26-AEF2-F8BE6301CC42}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{EC887919-EB80-4E36-944B-342FBA074ACC}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{ED687932-2DC5-41D8-BA77-0D9231CDB77E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{EDD4F043-F8BA-4741-A20A-7F4223A5A12F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{EDDDCD28-00AA-48C2-9EBA-9D95381CACE9}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{F19995CE-8FD4-4CC8-9C2F-B35D648C00FB}" = lport=1542 | protocol=6 | dir=in | name=realtek wps tcp prot | "{F1DEE2CC-BA92-4C4B-87A1-B6FE7724736E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{F3321B56-A88F-4374-912D-E88F53FBCE7A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{F4320939-BD21-41FD-80FC-34ED6BF32431}" = lport=1542 | protocol=17 | dir=in | name=realtek wps udp prot | "{F6BC1E97-64B4-446E-8FF4-6C88440A766A}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{F8A98413-32AD-475A-B975-C637BCD535F4}" = lport=53 | protocol=17 | dir=in | name=realtek ap udp prot | "{FB726E1E-0872-4CA6-9957-FDA6C817779F}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{FC373DDF-5D4C-437D-9E5A-A724F35C7EA1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{FD05464D-7F35-4FFE-8C90-C28ECAF93102}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{1EAC2F40-94A6-4181-AFC4-2EF87FD388FC}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\pce-n15 wlan card utilities\rtwlan.exe | "{3102B2F5-54E6-45D0-BB9D-A6CE159431C1}" = protocol=17 | dir=in | app=c:\users\max\desktop\cube world cracked\server.exe | "{3513A5A0-CFFC-4C4D-824C-934C6116AD4B}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\pce-n15 wlan card utilities\rtwlan.exe | "{377E44DC-4333-4FA0-AF92-CDF396BF35AF}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{39C06B04-5F3F-464C-9930-B96D6CBDC4DC}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{61911CD0-D771-45DF-BF20-818B32C5FCC8}" = protocol=6 | dir=in | app=c:\users\max\desktop\cube world cracked\server.exe | "{641F57BF-3590-455E-A962-A06B3814EB3C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{7C20824E-6530-47C7-BE02-10689952739A}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{CDC1DE17-EB59-4428-A201-5C15D1332192}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{CE5FD1E0-5401-410E-9381-FCF58D57C455}" = protocol=17 | dir=in | app=c:\program files (x86)\codemasters\dirt 3\dirt3_game.exe | "{D4990D6A-9C4F-429D-AF43-1D9B456B90D8}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{D6FB926A-E20C-46FE-A87E-3D8199190FD6}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe | "{D7EF5C93-00DF-498A-8899-F37B669F5BAB}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{E505CDBC-7BD5-4099-BA77-6989B7C69823}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{F60ACBA9-4F08-4E96-97BE-338681073064}" = protocol=6 | dir=in | app=c:\program files (x86)\codemasters\dirt 3\dirt3_game.exe | "TCP Query User{33C6529D-C808-4CF4-A93E-70960B4BE024}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "TCP Query User{8B706627-45BE-468D-9E98-483F942D29C6}C:\windows\syswow64\javaw.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\javaw.exe | "TCP Query User{AD323E29-08BC-40B5-A059-F6B5CC4E34BD}C:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe | "TCP Query User{BE050BE0-A80F-41CA-886D-829CF2A7EFC9}C:\users\max\desktop\cube world cracked\server.exe" = protocol=6 | dir=in | app=c:\users\max\desktop\cube world cracked\server.exe | "TCP Query User{DCF0498A-2DE0-49F1-B062-AD204ED03181}C:\gtr2\gtr2.exe" = protocol=6 | dir=in | app=c:\gtr2\gtr2.exe | "TCP Query User{DF60B307-4562-4A75-8E56-AA70EE3B4A30}C:\python27\pythonw.exe" = protocol=6 | dir=in | app=c:\python27\pythonw.exe | "TCP Query User{F52E283F-19C0-40BC-B200-93B15A73FDE2}C:\windows\syswow64\svchost.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\svchost.exe | "UDP Query User{0BB6C954-F33E-4BDD-9032-376D94DD4681}C:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\shift 2 unleashed\shift2u.exe | "UDP Query User{18F3374B-AFEB-482C-8AAF-273AC8F11927}C:\windows\syswow64\javaw.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\javaw.exe | "UDP Query User{39D698BE-6386-452D-A2FF-6BD73D985A46}C:\gtr2\gtr2.exe" = protocol=17 | dir=in | app=c:\gtr2\gtr2.exe | "UDP Query User{6DF8DC1D-C5D6-45C3-9819-6F2C417613CF}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "UDP Query User{9749C65B-FFF2-47A3-99AD-466ADB8A589B}C:\windows\syswow64\svchost.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\svchost.exe | "UDP Query User{CE48BA4C-037C-406A-B9C6-634CEF6AA41B}C:\users\max\desktop\cube world cracked\server.exe" = protocol=17 | dir=in | app=c:\users\max\desktop\cube world cracked\server.exe | "UDP Query User{D5CD7F72-F3B3-438F-B84B-3DD1B98C902D}C:\python27\pythonw.exe" = protocol=17 | dir=in | app=c:\python27\pythonw.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{11A955CD-4398-405A-886D-E464C3618FBF}" = Adobe Photoshop Lightroom 4.4 64-bit "{1ADC9982-65A8-45A2-B026-F63287600261}" = Fanatec Wheel "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 "{26A24AE4-039D-4CA4-87B4-2F86417025FF}" = Java 7 Update 25 (64-bit) "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{76D21FF6-B4B6-4BE1-A43D-AB01EA6A2B69}" = Effects Suite 64-bit "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{84ADC96C-B7E0-4938-9D6E-2B640D5DA225}" = Python 2.7.4 (64-bit) "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Treiber 314.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Systemsteuerung 314.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafiktreiber 314.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller-Treiber 314.22 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX-Systemsoftware 9.12.1031 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12 "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD-Audiotreiber "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components "{C91DCB72-F5BB-410D-A91A-314F5D1B4284}" = Broadcom Gigabit NetLink Controller "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "ASRock App Charger_is1" = ASRock App Charger v1.0.4 "Blender" = Blender "CCleaner" = CCleaner "EPSON Printer and Utilities" = EPSON Printer Software "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Pen Tablet Driver" = Wacom "VIRTU_is1" = VIRTU 1.2.103 "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 64 bit "WinRAR archiver" = WinRAR 4.20 (64-Bit) "wxPython2.8-unicode-py27_is1" = wxPython (unicode) for Python 2.7 "XFast LAN" = XFast LAN v6.61 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0ACC2993-2058-4BE7-9A92-9DCDAA9B3412}" = LogMeIn Hamachi "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}" = OpenOffice.org 3.4.1 "{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17 "{4176E7EF-8AD5-4FA9-9DC4-A75AA668B49C}}_is1" = IBot 5.23 "{434D0FA0-1558-4D8E-AC3D-BD1000008200}" = DiRT 3 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace "{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module "{556BEFE2-30FF-4113-98F4-01234396DF2B}" = ASUS PCE-N15 WLAN Card Utilities & Driver "{5B0CE14A-B9B6-4E25-A1BE-3EEC1998AC2C}" = SmartView Software Updater "{5E21B617-F52E-BB10-92F9-C8AB2C799A8A}" = Adobe Download Assistant "{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6 "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™ "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX "{924C3DC2-8E4E-432E-F973-9A2174A39774}" = safe Saave "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9AF7D6F5-50A5-432C-9F7B-83BCE03B11A0}" = SpinTires Tech Demo (June 060613) "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.03) - Deutsch "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime "{AFB907F5-C0E6-4753-8284-DE955EF86AC2}" = THX TruStudio "{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6 "{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}" = Browwse2siAvee "{C448EA30-BB7F-4D42-83BC-385EBA140AF2}" = SmartView for IE "{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" = SearchNewTab "{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game "{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso "{E8C37E27-5205-4C8A-BECB-B00533045AAE}" = SHIFT 2 UNLEASHED™ "{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "Adobe AIR" = Adobe AIR "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "ASRock eXtreme Tuner_is1" = ASRock eXtreme Tuner v0.1.98 "ASRock InstantBoot_is1" = ASRock InstantBoot v1.26 "avast" = avast! Free Antivirus "Battlelog Web Plugins" = Battlelog Web Plugins "Cheat Engine 6.2_is1" = Cheat Engine 6.2 "Color Efex Pro 4" = Color Efex Pro 4 "com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com "Dll-Files Fixer_is1" = Dll-Files Fixer "ESN Sonar-0.70.4" = ESN Sonar "GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}" = DiRT 3 "Google Chrome" = Google Chrome "HDR Efex Pro 2" = HDR Efex Pro 2 "InstallShield_{76D21FF6-B4B6-4BE1-A43D-AB01EA6A2B69}" = Effects Suite 64-bit "InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller "InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso "LogMeIn Hamachi" = LogMeIn Hamachi "MagniDriver" = marvell 91xx driver "MegaTrainer eXperience_is1" = MegaTrainer eXperience V1.1.0.4 "Mozilla Firefox 23.0.1 (x86 de)" = Mozilla Firefox 23.0.1 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NIS" = Norton Internet Security "Notepad++" = Notepad++ "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver "Origin" = Origin "PunkBusterSvc" = PunkBuster Services "SP_f5d3e0aa" = SafeSaver 1.74 "Topaz Adjust 5" = Topaz Adjust 5 "Topaz Clean 3" = Topaz Clean 3 "Topaz DeNoise 5" = Topaz DeNoise 5 "Topaz Detail 3" = Topaz Detail 3 "Topaz Fusion Express 2" = Topaz Fusion Express 2 "Topaz Fusion Express 2 (64-bit)" = Topaz Fusion Express 2 (64-bit) "Topaz InFocus" = Topaz InFocus "Wacom WebTabletPlugin for Internet Explorer and Netscape" = WebTablet FB Plugin 32 bit "XFastUsb" = XFastUsb ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1301480396-2720618616-1970420264-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Bierbuden Autoupdate" = Bierbuden Autoupdate (remove only) ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 26.08.2013 07:49:50 | Computer Name = Max-PC | Source = Application Hang | ID = 1002 Description = Programm RtWlan.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d8c Startzeit: 01cea25150b77141 Endzeit: 3 Anwendungspfad: C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtWlan.exe Berichts-ID: 9a9f0ebe-0e45-11e3-a808-002522fa4c93 Error - 27.08.2013 11:29:17 | Computer Name = Max-PC | Source = WinMgmt | ID = 10 Description = Error - 28.08.2013 08:37:42 | Computer Name = Max-PC | Source = WinMgmt | ID = 10 Description = Error - 28.08.2013 09:52:20 | Computer Name = Max-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: chrome.exe, Version: 28.0.1500.95, Zeitstempel: 0x51f05c5f Name des fehlerhaften Moduls: chrome.dll, Version: 28.0.1500.95, Zeitstempel: 0x51f05bf5 Ausnahmecode: 0x80000003 Fehleroffset: 0x00610905 ID des fehlerhaften Prozesses: 0xfb8 Startzeit der fehlerhaften Anwendung: 0x01cea3eb8530ad7c Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\chrome.dll Berichtskennung: 0e566710-0fe9-11e3-ac69-002522fa4c93 Error - 29.08.2013 08:04:26 | Computer Name = Max-PC | Source = WinMgmt | ID = 10 Description = Error - 29.08.2013 10:38:11 | Computer Name = Max-PC | Source = Application Hang | ID = 1002 Description = Programm firefox.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 171c Startzeit: 01cea4c53e553aa6 Endzeit: 23 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 9f22810d-10b8-11e3-a7be-002522fa4c93 Error - 30.08.2013 09:06:05 | Computer Name = Max-PC | Source = WinMgmt | ID = 10 Description = Error - 30.08.2013 12:42:14 | Computer Name = Max-PC | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: shift2u.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: shift2u.exe, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0077067e ID des fehlerhaften Prozesses: 0x1b50 Startzeit der fehlerhaften Anwendung: 0x01cea59e57bbf010 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exe Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exe Berichtskennung: 1f5bf3ad-1193-11e3-a801-002522fa4c93 Error - 31.08.2013 03:11:27 | Computer Name = Max-PC | Source = WinMgmt | ID = 10 Description = Error - 31.08.2013 07:55:11 | Computer Name = Max-PC | Source = WinMgmt | ID = 10 Description = [ System Events ] Error - 27.07.2013 06:59:15 | Computer Name = Max-PC | Source = volmgr | ID = 262190 Description = Die Initialisierung des Speicherabbildes ist fehlgeschlagen. Error - 27.07.2013 06:59:51 | Computer Name = Max-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?26.?07.?2013 um 18:48:11 unerwartet heruntergefahren. Error - 27.07.2013 09:16:27 | Computer Name = Max-PC | Source = EventLog | ID = 6008 Description = Das System wurde zuvor am ?27.?07.?2013 um 15:13:28 unerwartet heruntergefahren. Error - 28.07.2013 15:07:50 | Computer Name = Max-PC | Source = Microsoft-Windows-Kernel-General | ID = 6 Description = Error - 27.08.2013 11:28:26 | Computer Name = Max-PC | Source = Service Control Manager | ID = 7011 Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AsusSE erreicht. Error - 27.08.2013 11:28:36 | Computer Name = Max-PC | Source = Service Control Manager | ID = 7009 Description = Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error - 27.08.2013 11:28:36 | Computer Name = Max-PC | Source = Service Control Manager | ID = 7000 Description = Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error - 27.08.2013 11:28:37 | Computer Name = Max-PC | Source = DCOM | ID = 10005 Description = Error - 28.08.2013 08:42:39 | Computer Name = Max-PC | Source = Service Control Manager | ID = 7022 Description = Der Dienst "Windows Update" wurde nicht richtig gestartet. Error - 29.08.2013 08:03:25 | Computer Name = Max-PC | Source = Service Control Manager | ID = 7011 Description = Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AsusSE erreicht. < End of report > Geändert von Computer-max (31.08.2013 um 13:25 Uhr) |
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() t-online Brief erhalten (hackerangriffe wurden angeblich ausgeführt) hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
![]() | #3 |
| ![]() t-online Brief erhalten (hackerangriffe wurden angeblich ausgeführt) FRST.txt
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2013 03 Ran by Max (administrator) on MAX-PC on 31-08-2013 14:49:09 Running from C:\Users\Max\Desktop\Bereinigung Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Realtek) C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtlService.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtWlan.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin () C:\WINDOWS\system32\WinUpdate.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe () C:\Users\Max\Desktop\Minecraft.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\javaw.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [WinUpdate] - C:\WINDOWS\system32\WinUpdate.exe [1798144 2013-05-12] () HKLM\...\Run: [EPSON Stylus DX4200 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIAEE.EXE /F "C:\Windows\TEMP\E_S4EBB.tmp" /EF "HKLM" [x] HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKCU\...\Run: [ASRockXTU] - [x] HKCU\...\Run: [zASRockInstantBoot] - [x] HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [EADM] - C:\Program Files\Origin\Origin.exe [3497552 2013-03-26] (Electronic Arts) HKCU\...\Policies\system: [EnableLUA] 0 MountPoints2: {e2962c8c-9f84-11e2-bfa9-806e6f6e6963} - F:\Autorun.exe HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) AppInit_DLLs: C:\PROGRA~1\LUCIDL~1\VIRTU\APPINI~1.DLL,C:\Windows\system32\nvinitx.dll [250504 2013-03-15] (NVIDIA Corporation) AppInit_DLLs-x32: c:\progra~1\lucidl~1\virtu\x86\appini~1.dll,c:\windows\syswow64\nvinit.dll c:\progra~2\safesa~1\sprote~1.dll [1050112 2013-01-24] () Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.easylifeapp.com/?pid=512&src=ie1&r=2013/06/16&hid=1493084629&lg=EN&cc=DE URLSearchHook: (No Name) - {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - No File SearchScopes: HKLM-x32 - {01bd49d7-c76b-4310-8beb-14d7e5f322c6} URL = hxxp://search.easylifeapp.com/?q={searchTerms}&pid=512&src=ie2&r=2013/06/16&hid=1493084629&lg=EN&cc=DE SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {01bd49d7-c76b-4310-8beb-14d7e5f322c6} URL = hxxp://search.easylifeapp.com/?q={searchTerms}&pid=512&src=ie2&r=2013/06/16&hid=1493084629&lg=EN&cc=DE SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {81E806A5-46EE-49DA-9EFC-064FEAEBE60F} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=FC3831F8-9CB6-49DC-94B1-C39A904BFC7E&apn_sauid=DBB3DDFE-C0EF-452E-B08D-2449E06980A7 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartView VisualBookmark - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files (x86)\DeviceVM\SmartView\SmartView.dll (DeviceVM, Inc.) BHO-x32: Search-NeuWWTab - {15DE79EA-B60C-674F-C111-4E827FC5C6B1} - C:\ProgramData\Search-NeuWWTab\51703b13d77f2.dll () BHO-x32: Search-NeuWWTab - {1EA1558A-FD42-3B24-C760-5BAEDA12BF97} - C:\ProgramData\Search-NeuWWTab\517053bf97d72.dll () BHO-x32: Browwse2siAvee - {5807C1BC-9472-A080-48F5-067D09BD0920} - C:\ProgramData\Browwse2siAvee\51703afdeb1b7.dll () BHO-x32: safe Saave - {5EAA53FA-9A49-0815-D346-340A52DECABE} - C:\ProgramData\safe Saave\51bda6ebb650a.dll () BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: SearchNewTab - {B0A3DECF-0C8D-4E9D-48D8-9607E3729075} - C:\ProgramData\SearchNewTab\51bda7063d147.dll () BHO-x32: Browwse2siAvee - {CCFE5824-3446-7DD4-ED63-644CC4181B6E} - C:\ProgramData\Browwse2siAvee\517053bbddda5.dll () BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - No Name - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No File Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No File Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\lz9sjj8w.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ FF Extension: Symantec IPS - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (SearchNewTab) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbkjepneoomjodcmphebgobdinjoiad\1 CHR Extension: (Google Search) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (New Tab Website) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgkogmmlmfijkljjnhalncbabkljhceo\0.2_0 CHR Extension: (avast! Online Security) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0 CHR Extension: (ProxMate - Improve your Internet!) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\2.4.3_0 CHR Extension: (Gmail) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AsusSE; C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtlService.exe [36864 2012-04-09] (Realtek) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) S4 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [395136 2011-07-04] (cFos Software GmbH) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-04-14] () S4 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [125216 2010-09-02] (DeviceVM, Inc.) S4 WCUService; C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [456976 2010-09-02] (DeviceVM, Inc.) R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-25] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-25] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-25] () R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx64.sys [945200 2010-08-09] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx64.sys [945200 2010-08-09] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [475696 2010-08-13] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [475696 2010-08-13] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [132656 2010-08-13] (Symantec Corporation) S3 FanatecWheelFilterUsb; C:\Windows\System32\DRIVERS\FWFilterUsb.sys [61008 2012-02-01] (Windows (R) Codename Longhorn DDK provider) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-04-07] (FNet Co., Ltd.) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVia64.sys [463408 2010-06-27] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVia64.sys [463408 2010-06-27] (Symantec Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\ENG64.SYS [117808 2010-08-13] (Symantec Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\ENG64.SYS [117808 2010-08-13] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\EX64.SYS [1791536 2010-08-13] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\EX64.SYS [1791536 2010-08-13] (Symantec Corporation) S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1207020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2013-04-07] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Users\Max\AppData\Roaming\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-31 14:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-31 14:07 - 2013-08-31 14:48 - 00000000 ____D C:\Users\Max\Desktop\Bereinigung 2013-08-30 17:46 - 2013-08-30 17:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-28 15:55 - 2013-08-28 15:55 - 00001057 _____ C:\Users\Max\Documents\youtube 28.08.txt 2013-08-27 17:44 - 2013-08-27 17:44 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-27 17:30 - 2013-08-27 22:00 - 00000000 ____D C:\Users\Max\Desktop\backup handy 27.08.13 2013-08-25 19:03 - 2013-08-25 19:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-25 19:03 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-25 19:03 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-25 19:03 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-25 19:02 - 2013-08-31 13:54 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-25 19:02 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-25 19:02 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-25 19:02 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-25 19:02 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-25 18:56 - 2013-08-25 19:01 - 117478104 _____ C:\Users\Max\Downloads\avast_free_antivirus_setup.exe 2013-08-25 14:46 - 2013-08-28 14:35 - 00003830 _____ C:\Windows\PFRO.log 2013-08-23 21:10 - 2013-08-31 13:53 - 00001064 _____ C:\Windows\setupact.log 2013-08-23 21:10 - 2013-08-23 21:10 - 00000000 _____ C:\Windows\setuperr.log 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Downloads\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Desktop\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00000000 ____D C:\Users\Max\Desktop\download-downloadfile-26830 2013-08-22 17:23 - 2013-08-22 17:23 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00000000 ____D C:\Program Files\Java 2013-08-22 17:22 - 2013-08-22 17:23 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64(1).exe 2013-08-22 17:21 - 2013-08-22 17:23 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-22 17:21 - 2013-08-22 17:23 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-22 17:20 - 2013-08-22 17:20 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64.exe 2013-08-22 16:19 - 2013-08-22 16:19 - 00106977 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.2_Forge.jar 2013-08-22 16:14 - 2013-08-22 16:14 - 00095243 _____ C:\Users\Max\Downloads\EllianDetector.jar 2013-08-22 16:07 - 2013-08-22 16:07 - 00000000 ____D C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:06 - 2013-07-30 13:01 - 00019686 _____ C:\Users\Max\Desktop\TMIUtils.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00009671 _____ C:\Users\Max\Desktop\TMIView.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00005522 _____ C:\Users\Max\Desktop\TMIPrivateFields.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00002240 _____ C:\Users\Max\Desktop\TMIReplaceItems.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00000714 _____ C:\Users\Max\Desktop\TMIStateButtonData.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00000559 _____ C:\Users\Max\Desktop\TMIReplaceItems$SpawnerBlock.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00000473 _____ C:\Users\Max\Desktop\TMIReplaceItems$MetadataBlock.class 2013-08-22 16:06 - 2013-07-30 13:01 - 00000385 _____ C:\Users\Max\Desktop\TMIUtils$1.class 2013-08-22 16:03 - 2013-08-22 16:03 - 00106986 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1_Forge.jar 2013-08-22 15:59 - 2013-08-31 14:35 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft 2013-08-22 15:58 - 2013-08-22 15:59 - 00350720 _____ C:\Users\Max\Desktop\Minecraft.exe 2013-08-22 15:58 - 2013-08-22 15:58 - 54928642 _____ C:\Users\Max\Desktop\Minecraft1.6.1-Wazez.zip 2013-08-22 15:58 - 2013-08-22 15:58 - 00000000 ____D C:\Users\Max\Desktop\Minecraft1.6.1-Wazez 2013-08-22 15:57 - 2013-08-22 15:58 - 54928642 _____ C:\Users\Max\Downloads\Minecraft1.6.1-Wazez.zip 2013-08-22 15:52 - 2013-08-22 15:52 - 00675988 _____ C:\Users\Max\Downloads\Minecraft (1).exe 2013-08-22 15:49 - 2013-08-22 15:50 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft - Kopie (2) 2013-08-20 22:13 - 2013-08-20 22:13 - 85392925 _____ C:\Users\Max\Downloads\pavel.zip 2013-08-19 22:11 - 2013-08-19 22:12 - 437283794 _____ C:\Users\Max\Desktop\Unbenannt-1.psd 2013-08-14 15:32 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 15:32 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 15:32 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 15:32 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 15:32 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 15:32 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 15:32 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 15:32 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 15:32 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 15:32 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 15:32 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 15:32 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 14:30 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 14:30 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 14:29 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 14:29 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 14:29 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 14:29 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 14:29 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 14:29 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 14:29 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 14:29 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 14:29 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 14:29 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 14:29 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 14:29 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 14:29 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 14:29 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 14:29 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 14:29 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 14:29 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 14:29 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 14:29 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 14:29 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 14:29 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 14:29 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 14:29 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 14:29 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 14:29 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 14:29 - 2012-11-30 07:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-08-14 14:29 - 2012-11-30 07:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-08-14 14:29 - 2012-11-30 07:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-08-14 14:29 - 2012-11-30 07:41 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-08-14 14:29 - 2012-11-30 07:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-08-14 14:29 - 2012-11-30 06:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 05:23 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-08-14 14:29 - 2012-11-30 04:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 04:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 04:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 04:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll ==================== One Month Modified Files and Folders ======= 2013-08-31 14:48 - 2013-08-31 14:48 - 00000000 ____D C:\FRST 2013-08-31 14:48 - 2013-08-31 14:07 - 00000000 ____D C:\Users\Max\Desktop\Bereinigung 2013-08-31 14:41 - 2013-04-07 21:26 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-31 14:39 - 2013-04-20 17:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-31 14:35 - 2013-08-22 15:59 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Users\Max\AppData\Roaming\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-31 14:00 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-31 14:00 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-31 13:57 - 2013-04-07 15:15 - 02001813 _____ C:\Windows\WindowsUpdate.log 2013-08-31 13:55 - 2013-05-16 17:52 - 00003112 _____ C:\Windows\System32\Tasks\RDReminder 2013-08-31 13:55 - 2013-04-08 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-31 13:54 - 2013-08-25 19:02 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-31 13:54 - 2013-07-12 15:04 - 00000000 ____D C:\Users\Max\AppData\Local\LogMeIn Hamachi 2013-08-31 13:53 - 2013-08-23 21:10 - 00001064 _____ C:\Windows\setupact.log 2013-08-31 13:53 - 2013-04-07 21:26 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-31 13:53 - 2013-04-07 14:27 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-31 13:53 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-31 09:19 - 2013-04-08 21:11 - 00000000 ____D C:\Users\Max\AppData\Local\Adobe 2013-08-30 18:42 - 2013-04-20 15:49 - 00000000 ____D C:\Users\Max\AppData\Local\CrashDumps 2013-08-30 17:46 - 2013-08-30 17:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-29 16:40 - 2013-04-14 17:56 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-08-29 16:40 - 2013-04-13 21:07 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-08-29 16:39 - 2013-04-13 21:07 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-08-28 15:55 - 2013-08-28 15:55 - 00001057 _____ C:\Users\Max\Documents\youtube 28.08.txt 2013-08-28 14:35 - 2013-08-25 14:46 - 00003830 _____ C:\Windows\PFRO.log 2013-08-27 22:00 - 2013-08-27 17:30 - 00000000 ____D C:\Users\Max\Desktop\backup handy 27.08.13 2013-08-27 18:40 - 2013-04-07 15:20 - 00000000 ____D C:\Users\Max\AppData\Local\VirtualStore 2013-08-27 17:45 - 2013-04-07 14:14 - 00000000 ____D C:\Users\Max\AppData\Roaming\Adobe 2013-08-27 17:44 - 2013-08-27 17:44 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-27 17:43 - 2013-04-07 14:13 - 00000000 ____D C:\ProgramData\Adobe 2013-08-27 17:43 - 2013-04-07 14:13 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-08-27 17:30 - 2011-04-12 09:43 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-08-27 17:30 - 2011-04-12 09:43 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-08-27 17:30 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-25 19:03 - 2013-08-25 19:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-25 19:01 - 2013-08-25 18:56 - 117478104 _____ C:\Users\Max\Downloads\avast_free_antivirus_setup.exe 2013-08-23 22:44 - 2013-06-27 17:49 - 00000000 ____D C:\Users\Max\Desktop\100CANON 2013-08-23 21:10 - 2013-08-23 21:10 - 00000000 _____ C:\Windows\setuperr.log 2013-08-23 19:33 - 2013-04-07 16:12 - 00000000 ____D C:\Windows\Panther 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Downloads\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Desktop\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00000000 ____D C:\Users\Max\Desktop\download-downloadfile-26830 2013-08-22 18:41 - 2013-04-14 14:42 - 00000834 _____ C:\Users\Max\Desktop\Minecraft.lnk 2013-08-22 17:23 - 2013-08-22 17:23 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00000000 ____D C:\Program Files\Java 2013-08-22 17:23 - 2013-08-22 17:22 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64(1).exe 2013-08-22 17:23 - 2013-08-22 17:21 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-22 17:23 - 2013-08-22 17:21 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-22 17:20 - 2013-08-22 17:20 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64.exe 2013-08-22 16:19 - 2013-08-22 16:19 - 00106977 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.2_Forge.jar 2013-08-22 16:14 - 2013-08-22 16:14 - 00095243 _____ C:\Users\Max\Downloads\EllianDetector.jar 2013-08-22 16:07 - 2013-08-22 16:07 - 00000000 ____D C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:03 - 2013-08-22 16:03 - 00106986 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1_Forge.jar 2013-08-22 15:59 - 2013-08-22 15:58 - 00350720 _____ C:\Users\Max\Desktop\Minecraft.exe 2013-08-22 15:58 - 2013-08-22 15:58 - 54928642 _____ C:\Users\Max\Desktop\Minecraft1.6.1-Wazez.zip 2013-08-22 15:58 - 2013-08-22 15:58 - 00000000 ____D C:\Users\Max\Desktop\Minecraft1.6.1-Wazez 2013-08-22 15:58 - 2013-08-22 15:57 - 54928642 _____ C:\Users\Max\Downloads\Minecraft1.6.1-Wazez.zip 2013-08-22 15:52 - 2013-08-22 15:52 - 00675988 _____ C:\Users\Max\Downloads\Minecraft (1).exe 2013-08-22 15:50 - 2013-08-22 15:49 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft - Kopie (2) 2013-08-20 22:13 - 2013-08-20 22:13 - 85392925 _____ C:\Users\Max\Downloads\pavel.zip 2013-08-20 20:39 - 2013-04-20 17:53 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-20 20:39 - 2013-04-20 17:53 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-20 20:39 - 2013-04-20 17:53 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-19 22:12 - 2013-08-19 22:11 - 437283794 _____ C:\Users\Max\Desktop\Unbenannt-1.psd 2013-08-19 19:59 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-12 11:42 - 2013-04-07 21:27 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-22 23:07 ==================== End Of Log ============================ und die addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2013 03 Ran by Max at 2013-08-31 14:50:57 Running from C:\Users\Max\Desktop\Bereinigung Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.1.377) Adobe AIR (x32 Version: Adobe Download Assistant (x32 Version: 1.2.5) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Photoshop CS6 (x32 Version: 13.0) Adobe Photoshop Lightroom 4.4 64-bit (Version: 4.4.1) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: ASRock eXtreme Tuner v0.1.98 (x32) ASRock InstantBoot v1.26 (x32) ASUS PCE-N15 WLAN Card Utilities & Driver (x32 Version: avast! Free Antivirus (x32 Version: 8.0.1489.0) Battlefield 3™ (x32 Version: Battlelog Web Plugins (x32 Version: 2.1.7) Bierbuden Autoupdate (remove only) (HKCU) Blender (Version: 2.67) Broadcom Gigabit NetLink Controller (Version: Browwse2siAvee (x32 Version: ) CCleaner (Version: 4.01) Cheat Engine 6.2 (x32) Cisco EAP-FAST Module (x32 Version: 2.2.14) Cisco LEAP Module (x32 Version: 1.0.19) Cisco PEAP Module (x32 Version: 1.1.6) Color Efex Pro 4 (x32 Version: CyberLink MediaEspresso (x32 Version: 6.5.1611_37043) DiRT 3 (x32 Version: 1.0.0000.130) Dll-Files Fixer (x32 Version: 1.0) Effects Suite 64-bit (Version: 11.0.1) Effects Suite 64-bit (x32 Version: 11.0.1) EPSON Printer Software ESN Sonar (x32 Version: 0.70.4) Etron USB3.0 Host Controller (x32 Version: 0.96) Fanatec Wheel (Version: 8.11.6) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: HDR Efex Pro 2 (x32 Version: IBot 5.23 (x32 Version: 5.23) Intel(R) Control Center (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) Processor Graphics (x32 Version: Java 7 Update 17 (x32 Version: 7.0.170) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java Auto Updater (x32 Version: LogMeIn Hamachi (x32 Version: Malwarebytes Anti-Malware Version (x32 Version: marvell 91xx driver (x32 Version: MegaTrainer eXperience V1.1.0.4 (x32) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Games for Windows - LIVE Redistributable (x32 Version: Microsoft Games for Windows Marketplace (x32 Version: Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1) Mozilla Maintenance Service (x32 Version: 23.0.1) Norton Internet Security (x32 Version: Notepad++ (x32 Version: 6.3.3) NVIDIA 3D Vision Controller-Treiber 314.22 (Version: 314.22) NVIDIA 3D Vision Treiber 314.22 (Version: 314.22) NVIDIA Grafiktreiber 314.22 (Version: 314.22) NVIDIA HD-Audiotreiber (Version: NVIDIA Install Application (Version: 2.1002.115.743) NVIDIA PhysX (x32 Version: 9.12.1031) NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 314.22 (Version: 314.22) NVIDIA Update 1.12.12 (Version: 1.12.12) NVIDIA Update Components (Version: 1.12.12) ock App Charger v1.0.4 OpenOffice.org 3.4.1 (x32 Version: 3.41.9593) Origin (x32 Version: PDF Settings CS6 (x32 Version: 11.0) PunkBuster Services (x32 Version: 0.991) Python 2.7.4 (64-bit) (Version: 2.7.4150) QuickTime (x32 Version: Rapture3D 2.4.8 Game (x32) Realtek High Definition Audio Driver (x32 Version: safe Saave (x32 Version: ) SafeSaver 1.74 (x32) SearchNewTab (x32 Version: ) SHIFT 2 UNLEASHED™ (x32 Version: SmartView for IE (x32 Version: SmartView Software Updater (x32 Version: SpinTires Tech Demo (June 060613) (x32 Version: 1.3) THX TruStudio (x32 Version: 1.00.01) Topaz Adjust 5 (x32 Version: 5.0.0) Topaz Clean 3 (x32 Version: 3.0.2) Topaz DeNoise 5 (x32 Version: 5.0.1) Topaz Detail 3 (x32 Version: 3.1.0) Topaz Fusion Express 2 (64-bit) (x32 Version: 2.1.1) Topaz Fusion Express 2 (x32 Version: 2.1.3) Topaz InFocus (x32 Version: 1.0.0) VIRTU 1.2.103 (Version: 1.2.103) Wacom (Version: 5.3.2-1) WebTablet FB Plugin 32 bit (x32 Version: WebTablet FB Plugin 64 bit (Version: Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) WinRAR 4.20 (64-Bit) (Version: 4.20.0) wxPython (unicode) for Python 2.7 (Version: XFast LAN v6.61 (Version: 6.61) XFastUsb (x32) ==================== Restore Points ========================= 18-08-2013 19:30:53 Windows-Sicherung 20-08-2013 18:23:01 Windows Update 22-08-2013 15:20:54 Installed Java 7 Update 25 (64-bit) 22-08-2013 15:23:15 Removed Java 7 Update 25 (64-bit) 22-08-2013 15:23:39 Installed Java 7 Update 25 (64-bit) 25-08-2013 17:00:25 Windows-Sicherung 25-08-2013 17:02:19 avast! Free Antivirus Setup 27-08-2013 15:32:53 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {04D684C2-A7D3-43BE-B6FE-02FA9CDA6F43} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-07] (Google Inc.) Task: {0ADDB7EF-C6E1-46AA-8412-4AD57A952D7D} - System32\Tasks\RDReminder => C:\Program Files (x86)\Dll-Files.com No File Task: {0B851B0A-AA3C-4416-B8F4-AB22F80BFD1A} - System32\Tasks\Symantec\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\\SymErr.exe [2012-06-08] (Symantec Corporation) Task: {2007369A-6755-4403-8151-AAD49579BE31} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-04-11] (CyberLink) Task: {2A300E66-60D8-45F2-90D1-8B1F99ABDF6C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd) Task: {41E8B188-4B8F-49A6-B15F-D4CC4404BF20} - System32\Tasks\AdobeAAMUpdater-1.0-Max-PC-Max => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated) Task: {6085FFCD-4295-4B64-8940-D5DE7A8C98D9} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-21] (Microsoft Corporation) Task: {7E648E76-2E76-4D33-96D5-8432A4504A90} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {A70DD6F9-1C02-4596-A508-7CABFDA6948D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {AC1D1794-B4E9-4B90-8EC4-168E8E416BB8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-07] (Google Inc.) Task: {C8B63CA5-FCA5-4C8F-A9B7-EF9C56E2024F} - System32\Tasks\DLL-Files.Com Fixer_Updates => C:\Program Files (x86)\Dll-Files.com No File Task: {D76EEF00-A6F9-4F79-B557-DE7FBAA74FE0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-20] (Adobe Systems Incorporated) Task: {DAC328E7-B440-4060-A0D4-58B144ACBB2D} - System32\Tasks\Symantec\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\\SymErr.exe [2012-06-08] (Symantec Corporation) Task: {E16DF119-1621-401D-AE8D-8D04F9652258} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-21] (Microsoft Corporation) Task: {E389608C-187F-4C1F-8607-CFC360F7325E} - System32\Tasks\DLL-Files.Com Fixer_MONTHLY => C:\Program Files (x86)\Dll-Files.com No File Task: {E49B0D8A-7CDF-4091-8EAA-B3595DFC5C27} - System32\Tasks\{7D48034A-2147-4F26-B0B1-EA49C0916B20} => C:\Users\Max\Desktop\crk\iBot-Crack-Updater\iBot Crack Updater.exe No File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DLL-Files.Com Fixer_MONTHLY.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job => C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-25 19:02 - 2013-05-09 10:58 - 00302224 _____ (AVAST Software) C:\Program Files\AVAST Software\Avast\snxhk64.dll 2013-04-07 14:26 - 2013-03-15 07:53 - 00250504 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-04-07 14:26 - 2013-03-15 07:53 - 00327248 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\CoProcManager\nvd3d9wrapx.dll 2013-04-07 14:26 - 2013-03-15 07:53 - 00228880 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\CoProcManager\nvdxgiwrapx.dll 2013-04-07 14:26 - 2013-03-15 07:53 - 01118776 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-04-07 14:26 - 2013-03-15 07:53 - 15508512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-08-25 19:02 - 2013-05-09 10:58 - 00133840 _____ (AVAST Software) C:\Program Files\AVAST Software\Avast\ashShA64.dll 2013-04-08 22:05 - 2011-04-17 02:57 - 01031040 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\\ccL100U.dll 2013-04-08 22:05 - 2011-04-17 02:45 - 00113536 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\\ccVrTrst.dll 2013-04-08 22:05 - 2011-06-01 18:16 - 00086952 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\\EFACli64.dll 2013-04-08 22:05 - 2011-04-17 02:45 - 00420224 ____R (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine64\\ccSet.dll 2013-04-07 14:26 - 2013-03-15 06:16 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-04-07 15:56 - 2011-04-15 04:29 - 00286720 _____ (Intel Corporation) C:\Windows\system32\igfxrDEU.lrc 2009-07-14 01:41 - 2009-07-14 03:41 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll 2013-04-09 17:01 - 2012-06-09 19:20 - 00196096 _____ (Alexander Roshal) C:\Program Files\WinRAR\rarext.dll 2013-05-10 21:56 - 2012-12-11 13:07 - 01184640 _____ () C:\Program Files\Tablet\Pen\libxml2.dll 2013-05-10 21:56 - 2012-12-11 13:07 - 01981312 _____ (Wacom Technology, Corp.) C:\Windows\system32\Pen_Tablet.dll 2013-04-07 15:56 - 2011-04-15 04:27 - 00109056 _____ (Intel Corporation) C:\Windows\System32\hccutils.DLL 2013-04-07 15:56 - 2011-04-15 04:28 - 00062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2013-04-07 15:56 - 2011-04-15 04:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-04-07 14:26 - 2013-03-15 06:16 - 04138272 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvUI.dll 2013-04-07 14:27 - 2013-03-15 07:53 - 00779040 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Common\easyDaemonAPIU64.DLL 2013-04-07 14:27 - 2013-03-15 07:53 - 03595040 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll 2013-04-07 14:27 - 2013-03-15 07:53 - 00981280 _____ (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Common\NVUPDTR.DLL 2013-07-11 16:13 - 2013-04-24 00:56 - 09991832 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll 2013-07-12 10:36 - 2013-07-12 10:36 - 15577088 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\88744044294787b99dd4a8704ab75a79\mscorlib.ni.dll 2013-04-08 16:46 - 2012-10-05 12:52 - 01574496 _____ (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll 2013-08-14 21:26 - 2013-08-14 21:26 - 10655744 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System\af0a0b96a02f9925eb84392ee65a5cfa\System.ni.dll 2013-08-14 21:27 - 2013-08-14 21:27 - 02320384 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\868d117286ad259249f31d3fe813d39a\System.Drawing.ni.dll 2013-08-14 21:27 - 2013-08-14 21:27 - 17383424 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\95674cb72317e3a5380ea450b913786f\System.Windows.Forms.ni.dll 2013-08-14 21:26 - 2013-08-14 21:26 - 01320448 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\1031b311ee568364d4ca1c4db634eaf0\System.Configuration.ni.dll 2013-08-14 21:26 - 2013-08-14 21:26 - 06964736 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\3975acf49313ceea1280da91f0383480\System.Xml.ni.dll 2013-04-08 16:46 - 2010-11-13 01:26 - 00315392 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\mscorlib.resources\\mscorlib.resources.dll 2011-04-12 09:43 - 2011-04-12 09:43 - 00212992 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\System.resources\\System.resources.dll 2013-04-08 16:46 - 2010-11-13 01:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\assembly\GAC_MSIL\System.Drawing.resources\\System.Drawing.resources.dll 2009-07-14 01:19 - 2009-07-14 03:41 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\ktmw32.dll 2009-07-14 01:46 - 2009-07-14 03:41 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\tschannel.dll 2010-11-21 05:24 - 2010-11-21 05:24 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\Cabinet.dll 2013-04-07 15:34 - 2012-06-03 00:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2013-08-14 22:30 - 2013-08-14 22:30 - 02131968 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\Microsoft.VisualBas#\603248adb7974762df07835b282cc90f\Microsoft.VisualBasic.ni.dll 2013-08-14 21:28 - 2013-08-14 21:28 - 01022976 _____ (Microsoft Corporation) C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Runtime.Remo#\bda1d99ab089bb2f18a48ba06d5a4923\System.Runtime.Remoting.ni.dll 2013-04-08 18:08 - 2013-04-08 18:08 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\D3D10Warp.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-08-25 19:02 - 2013-05-09 10:58 - 00136936 _____ (AVAST Software) C:\Program Files\AVAST Software\Avast\aswJsFlt64.dll 2013-08-25 19:02 - 2013-05-09 11:02 - 00208536 _____ (AVAST Software) C:\PROGRA~1\AVASTS~1\Avast\AavmRpch64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 07240104 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\server\jvm.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00049064 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\verify.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00151464 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\java.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00075176 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\zip.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00090536 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\net.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00059304 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\nio.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00069544 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\unpack.dll 2013-08-22 15:59 - 2013-07-02 21:19 - 00306176 _____ () C:\Users\Max\AppData\Roaming\.minecraft\versions\natives\lwjgl64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 01504168 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\awt.dll 2013-04-07 14:26 - 2013-03-15 07:53 - 26956576 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.DLL 2013-08-22 15:59 - 2013-07-02 21:19 - 00382464 _____ () C:\Users\Max\AppData\Roaming\.minecraft\versions\natives\OpenAL64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00034728 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\management.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00134568 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\sunec.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00031656 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\sunmscapi.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00240040 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\fontmanager.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00252328 _____ (Oracle Corporation) C:\Program Files\Java\jre7\bin\t2k.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Windows:nlsPreferences ==================== Faulty Device Manager Devices ============= Name: ASUS PCE-N15 11n Wireless LAN PCI-E Card Description: ASUS PCE-N15 11n Wireless LAN PCI-E Card Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: ASUSTeK Computer Inc. Service: RTL8192Ce Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (08/31/2013 02:06:28 PM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 11e0 Startzeit: 01cea64270933290 Endzeit: 50 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: c2779e8a-1235-11e3-bf6a-002522fa4c93 Error: (08/31/2013 02:05:26 PM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1148 Startzeit: 01cea640f11e0834 Endzeit: 35 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 9ccca2d1-1235-11e3-bf6a-002522fa4c93 Error: (08/31/2013 01:55:11 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/31/2013 09:11:27 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/30/2013 06:42:14 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: shift2u.exe, Version:, Zeitstempel: 0x00000000 Name des fehlerhaften Moduls: shift2u.exe, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0077067e ID des fehlerhaften Prozesses: 0x1b50 Startzeit der fehlerhaften Anwendung: 0xshift2u.exe0 Pfad der fehlerhaften Anwendung: shift2u.exe1 Pfad des fehlerhaften Moduls: shift2u.exe2 Berichtskennung: shift2u.exe3 Error: (08/30/2013 03:06:05 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/29/2013 04:38:11 PM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 171c Startzeit: 01cea4c53e553aa6 Endzeit: 23 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 9f22810d-10b8-11e3-a7be-002522fa4c93 Error: (08/29/2013 02:04:26 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/28/2013 03:52:20 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 28.0.1500.95, Zeitstempel: 0x51f05c5f Name des fehlerhaften Moduls: chrome.dll, Version: 28.0.1500.95, Zeitstempel: 0x51f05bf5 Ausnahmecode: 0x80000003 Fehleroffset: 0x00610905 ID des fehlerhaften Prozesses: 0xfb8 Startzeit der fehlerhaften Anwendung: 0xchrome.exe0 Pfad der fehlerhaften Anwendung: chrome.exe1 Pfad des fehlerhaften Moduls: chrome.exe2 Berichtskennung: chrome.exe3 Error: (08/28/2013 02:37:42 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/29/2013 02:03:25 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AsusSE erreicht. Error: (08/28/2013 02:42:39 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (08/27/2013 05:28:37 PM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (08/27/2013 05:28:36 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (08/27/2013 05:28:36 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (08/27/2013 05:28:26 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AsusSE erreicht. Error: (07/28/2013 09:07:50 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT) Description: 0xc000014d0 Error: (07/27/2013 03:16:27 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 27.07.2013 um 15:13:28 unerwartet heruntergefahren. Error: (07/27/2013 00:59:51 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 26.07.2013 um 18:48:11 unerwartet heruntergefahren. Error: (07/27/2013 00:59:15 PM) (Source: volmgr) (User: ) Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen. Microsoft Office Sessions: ========================= Error: (08/31/2013 02:06:28 PM) (Source: Application Hang)(User: ) Description: firefox.exe23.0.1.497411e001cea6427093329050C:\Program Files (x86)\Mozilla Firefox\firefox.exec2779e8a-1235-11e3-bf6a-002522fa4c93 Error: (08/31/2013 02:05:26 PM) (Source: Application Hang)(User: ) Description: firefox.exe23.0.1.4974114801cea640f11e083435C:\Program Files (x86)\Mozilla Firefox\firefox.exe9ccca2d1-1235-11e3-bf6a-002522fa4c93 Error: (08/31/2013 01:55:11 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/31/2013 09:11:27 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/30/2013 06:42:14 PM) (Source: Application Error)(User: ) Description: shift2u.exe1.0.2.000000000shift2u.exe1.0.2.000000000c00000050077067e1b5001cea59e57bbf010C:\Program Files (x86)\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exeC:\Program Files (x86)\Electronic Arts\SHIFT 2 UNLEASHED\shift2u.exe1f5bf3ad-1193-11e3-a801-002522fa4c93 Error: (08/30/2013 03:06:05 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/29/2013 04:38:11 PM) (Source: Application Hang)(User: ) Description: firefox.exe22.0.0.4917171c01cea4c53e553aa623C:\Program Files (x86)\Mozilla Firefox\firefox.exe9f22810d-10b8-11e3-a7be-002522fa4c93 Error: (08/29/2013 02:04:26 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/28/2013 03:52:20 PM) (Source: Application Error)(User: ) Description: chrome.exe28.0.1500.9551f05c5fchrome.dll28.0.1500.9551f05bf58000000300610905fb801cea3eb8530ad7cC:\Program Files (x86)\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\chrome.dll0e566710-0fe9-11e3-ac69-002522fa4c93 Error: (08/28/2013 02:37:42 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 43% Total physical RAM: 8104.58 MB Available physical RAM: 4550.96 MB Total Pagefile: 16207.35 MB Available Pagefile: 12205.48 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:247.97 GB) NTFS Drive d: (Datenträger ) (Fixed) (Total:445.76 GB) (Free:0.01 GB) NTFS Drive e: (RECOVER) (Fixed) (Total:19.99 GB) (Free:10.68 GB) FAT32 Drive f: (20110511_124433) (CDROM) (Total:6.76 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 4F40A143) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: CE74067F) Partition 1: (Active) - (Size=446 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
ATTFilter ComboFix 13-08-30.02 - Max 31.08.2013 15:38:43.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8105.5469 [GMT 2:00] ausgeführt von:: C:\Users\Max\Desktop\Bereinigung\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Norton Internet Security *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Norton Internet Security *Disabled/Outdated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) C:\MicrosoftUpdate.txt C:\ProgramData\Browwse2siAvee C:\ProgramData\Browwse2siAvee\51703afdeb1b7.dll C:\ProgramData\Browwse2siAvee\51703afdeb1b7.tlb C:\ProgramData\Browwse2siAvee\517053bbddda5.dll C:\ProgramData\Browwse2siAvee\517053bbddda5.tlb C:\ProgramData\Browwse2siAvee\data\Browwse2siAvee.dat C:\ProgramData\Browwse2siAvee\settings.ini C:\ProgramData\Browwse2siAvee\uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browwse2siAvee C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browwse2siAvee\Browwse2siAvee.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browwse2siAvee\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\safe Saave C:\ProgramData\Microsoft\Windows\Start Menu\Programs\safe Saave\safe Saave.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\safe Saave\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search-NeuWWTab C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search-NeuWWTab\Search-NeuWWTab.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search-NeuWWTab\Uninstall.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab\SearchNewTab.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab\Uninstall.lnk C:\ProgramData\safe Saave C:\ProgramData\safe Saave\51bda6ebb650a.dll C:\ProgramData\safe Saave\51bda6ebb650a.tlb C:\ProgramData\safe Saave\data\safe Saave.dat C:\ProgramData\safe Saave\settings.ini C:\ProgramData\safe Saave\uninstall.exe C:\ProgramData\Search-NeuWWTab C:\ProgramData\Search-NeuWWTab\51703b13d77f2.dll C:\ProgramData\Search-NeuWWTab\51703b13d77f2.tlb C:\ProgramData\Search-NeuWWTab\517053bf97d72.dll C:\ProgramData\Search-NeuWWTab\517053bf97d72.tlb C:\ProgramData\Search-NeuWWTab\data\Search-NeuWWTab.dat C:\ProgramData\Search-NeuWWTab\settings.ini C:\ProgramData\Search-NeuWWTab\uninstall.exe C:\ProgramData\SearchNewTab C:\ProgramData\SearchNewTab\51bda7063d147.dll C:\ProgramData\SearchNewTab\51bda7063d147.tlb C:\ProgramData\SearchNewTab\data\SearchNewTab.dat C:\ProgramData\SearchNewTab\settings.ini C:\ProgramData\SearchNewTab\uninstall.exe C:\Users\Max\AppData\Local\MicrosoftUpdate C:\Users\Max\AppData\Local\MicrosoftUpdate\iBot_Cracked_Patcher.exe_Url_20hw03giaxjwasxcfkasmyqwdnmbq2st\\user.config C:\Users\Max\AppData\Local\MicrosoftUpdate\WinUpdate.exe_Url_5qfrom13cwewwukuksqc0ya1hrbcgv5m\\user.config C:\Users\Max\AppData\Roaming\chrtmp C:\Users\Max\AppData\Roaming\convert\convert.exe C:\Users\Max\AppData\Roaming\iBot.exe C:\Windows\IsUn0407.exe C:\Windows\SysWow64\tmp4A7F.tmp C:\Windows\SysWow64\tmp4A80.tmp C:\Windows\SysWow64\tmpE14B.tmp C:\Windows\winupdate.txt D:\install.exe ((((((((((((((((((((((( Dateien erstellt von 2013-07-28 bis 2013-08-31 )))))))))))))))))))))))))))))) |
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> t-online Brief erhalten (hackerangriffe wurden angeblich ausgeführt) |
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.08.31.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 Max :: MAX-PC [Administrator] 31.08.2013 19:52:37 mbam-log-2013-08-31 (19-52-37).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 250853 Laufzeit: 3 Minute(n), 5 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 9 HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} (PUP.Optional.EasyLife.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6} (PUP.Optional.EasyLife.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{924C3DC2-8E4E-432E-F973-9A2174A39774} (PUP.Optional.SilentInstall) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C1EC38CE-DE18-5046-42C6-99FEC68E4F5F} (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A6DC4414-2255-BE62-4641-B96B29AE4176} (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B0A3DECF-0C8D-4E9D-48D8-9607E3729075} (PUP.Optional.SearchNewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{B0A3DECF-0C8D-4E9D-48D8-9607E3729075} (PUP.Optional.SearchNewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B0A3DECF-0C8D-4E9D-48D8-9607E3729075} (PUP.Optional.SearchNewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B0A3DECF-0C8D-4E9D-48D8-9607E3729075} (PUP.Optional.SearchNewTab.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 2 C:\Users\Max\AppData\Roaming\loadtbs (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateien: 22 C:\ProgramData\InstallMate\{262BFB97-79F7-47D5-A53E-31D5FDC8D961}\Setup.exe (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InstallMate\{262BFB97-79F7-47D5-A53E-31D5FDC8D961}\TsuDll.dll (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InstallMate\{3205C3D2-B1D0-4463-A688-F9F2E9E6E124}\Setup.exe (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\InstallMate\{3205C3D2-B1D0-4463-A688-F9F2E9E6E124}\TsuDll.dll (PUP.Optional.Tarma.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\7ZipSetup-7GDgYRD.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\cheat engine setup.exe (PUP.Soft32Downloader) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\cossacks_setup.exe (PUP.Optional.Softonic) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\Download.exe (PUP.Optional.Installex) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\Player_Plugin.exe (Adware.DomaIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\PSN.rar (PUP.Optional.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\setup (1).exe (PUP.Optional.Bundlore) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\Downloads\ZipOpenerSetup.exe (PUP.Optional.InstallCore) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\keyHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\config.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\domHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\evHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\uninstall.exe (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\updateHash.txt (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\html\dimensions.ini (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\html\install.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\html\uninstall.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Max\AppData\Roaming\loadtbs\html\uninstallComplete.html (PUP.LoadTubes) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.001 - Report created 01/09/2013 at 13:32:41 # Updated 24/08/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Max - MAX-PC # Running from : C:\Users\Max\Desktop\Bereinigung\adwcleaner3001.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\DeviceVM Folder Deleted : C:\ProgramData\InstallMate Folder Deleted : C:\ProgramData\SoftSafe Folder Deleted : C:\ProgramData\StarApp Folder Deleted : C:\Program Files (x86)\DeviceVM Folder Deleted : C:\Program Files (x86)\EasyLife Folder Deleted : C:\Program Files (x86)\optimizer pro Folder Deleted : C:\Program Files (x86)\SafeSaver Folder Deleted : C:\Users\Max\AppData\Local\PackageAware Folder Deleted : C:\Users\Max\AppData\Roaming\DeviceVM File Deleted : C:\Windows\System32\roboot64.exe ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_f5d3e0aa Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0F3DC9E0-C459-4A40-BCF8-747BD9322E10} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0F3DC9E0-C459-4A40-BCF8-747BD9322E10}] Key Deleted : HKCU\Software\OCS Key Deleted : HKCU\Software\Softonic Key Deleted : HKCU\Software\AppDataLow\SProtector Key Deleted : HKLM\Software\SP Global Key Deleted : HKLM\Software\SProtector Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1 ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\lz9sjj8w.default-1374351635069\prefs.js ] Line Deleted : user_pref("aol_toolbar.default.homepage.check", false); Line Deleted : user_pref("aol_toolbar.default.search.check", false); Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", ""); -\\ Google Chrome v28.0.1500.95 [ File : C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [4272 octets] - [01/09/2013 13:30:15] AdwCleaner[S0].txt - [4134 octets] - [01/09/2013 13:32:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4194 octets] ########## Auch, wenn ich das Programm als Administrator ausführe passiert nichts. Wenn ich allerdings eine halbe Stunde nach doppelklick warte popt ein Fenster von Norton auf (obwohl ich norton nicht installiert habe) und fordert mich auf den PC neu zu starten. Nach dem Neustart sind dann sämtliche Dateien von dem Removal tool verschwunden. Und noch die FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2013 03 Ran by Max (administrator) on MAX-PC on 01-09-2013 14:09:48 Running from C:\Users\Max\Desktop\Bereinigung Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Realtek) C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtlService.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtWlan.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [EPSON Stylus DX4200 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIAEE.EXE /F "C:\Windows\TEMP\E_S4EBB.tmp" /EF "HKLM" [x] HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [ASRockXTU] - [x] HKCU\...\Run: [zASRockInstantBoot] - [x] HKCU\...\Run: [AdobeBridge] - [x] HKCU\...\Run: [EADM] - C:\Program Files\Origin\Origin.exe [3497552 2013-03-26] (Electronic Arts) HKCU\...\Policies\system: [EnableLUA] 0 HKCU\...\Policies\Explorer: [NoDrives] 0 HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) AppInit_DLLs: C:\PROGRA~1\LUCIDL~1\VIRTU\APPINI~1.DLL,C:\Windows\system32\nvinitx.dll [250504 2013-03-15] (NVIDIA Corporation) AppInit_DLLs-x32: c:\PROGRA~1\LUCIDL~1\VIRTU\x86\APPINI~1.DLL c:\Windows\SysWOW64\nvinit.dll [157792 2011-06-19] (Lucidlogix Inc.) Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=ASRK SearchScopes: HKCU - {81E806A5-46EE-49DA-9EFC-064FEAEBE60F} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=FC3831F8-9CB6-49DC-94B1-C39A904BFC7E&apn_sauid=DBB3DDFE-C0EF-452E-B08D-2449E06980A7 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Search-NeuWWTab - {15DE79EA-B60C-674F-C111-4E827FC5C6B1} - C:\ProgramData\Search-NeuWWTab\51703b13d77f2.dll No File BHO-x32: Search-NeuWWTab - {1EA1558A-FD42-3B24-C760-5BAEDA12BF97} - C:\ProgramData\Search-NeuWWTab\517053bf97d72.dll No File BHO-x32: Browwse2siAvee - {5807C1BC-9472-A080-48F5-067D09BD0920} - C:\ProgramData\Browwse2siAvee\51703afdeb1b7.dll No File BHO-x32: safe Saave - {5EAA53FA-9A49-0815-D346-340A52DECABE} - C:\ProgramData\safe Saave\51bda6ebb650a.dll No File BHO-x32: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) BHO-x32: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Browwse2siAvee - {CCFE5824-3446-7DD4-ED63-644CC4181B6E} - C:\ProgramData\Browwse2siAvee\517053bbddda5.dll No File BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FireFox: ======== FF ProfilePath: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\lz9sjj8w.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @wacom.com/wtPlugin,version= - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.4 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.1.7 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @wacom.com/wtPlugin,version= - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ FF Extension: Symantec IPS - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_13_2 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR HomePage: hxxp://www.google.de/ CHR RestoreOnStartup: "https://de-de.facebook.com/", "hxxp://www.google.de/", "hxxp://www.google.de/" CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Extension: (Google Docs) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (SearchNewTab) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\chbkjepneoomjodcmphebgobdinjoiad\1 CHR Extension: (Google Search) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (New Tab Website) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgkogmmlmfijkljjnhalncbabkljhceo\0.2_0 CHR Extension: (avast! Online Security) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0 CHR Extension: (ProxMate - Improve your Internet!) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgjpnmnpjmabddgmjdiaggacbololbjm\2.4.3_0 CHR Extension: (Gmail) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 AsusSE; C:\Program Files (x86)\ASUS\PCE-N15 WLAN Card Utilities\RtlService.exe [36864 2012-04-09] (Realtek) S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) S4 cFosSpeedS; C:\Program Files\ASRock\XFast LAN\spd.exe [395136 2011-07-04] (cFos Software GmbH) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\\ccSvcHst.exe [130008 2011-04-17] (Symantec Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-04-14] () R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.) S4 SmartViewService; C:\Program Files (x86)\DeviceVM\SmartView\SmartViewService.exe [x] S4 WCUService; C:\Program Files (x86)\DeviceVM\SmartView Software Updater\WCUService.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-25] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-25] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-25] () R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx64.sys [945200 2010-08-09] (Symantec Corporation) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20100810.004\BHDrvx64.sys [945200 2010-08-09] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [475696 2010-08-13] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [475696 2010-08-13] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [132656 2010-08-13] (Symantec Corporation) S3 FanatecWheelFilterUsb; C:\Windows\System32\DRIVERS\FWFilterUsb.sys [61008 2012-02-01] (Windows (R) Codename Longhorn DDK provider) R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [15936 2013-04-07] (FNet Co., Ltd.) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVia64.sys [463408 2010-06-27] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20100706.002\IDSVia64.sys [463408 2010-06-27] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\ENG64.SYS [117808 2010-08-13] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\ENG64.SYS [117808 2010-08-13] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\EX64.SYS [1791536 2010-08-13] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20100813.009\EX64.SYS [1791536 2010-08-13] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1207020.003\SRTSP64.SYS [744568 2011-03-31] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1207020.003\SRTSPX64.SYS [40568 2011-03-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1207020.003\SYMDS64.SYS [450680 2011-01-27] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1207020.003\SYMEFA64.SYS [912504 2011-03-15] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [174200 2013-04-07] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1207020.003\Ironx64.SYS [171128 2011-01-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1207020.003\SYMNETS.SYS [386168 2011-04-21] (Symantec Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-31 15:37 - 2013-08-31 16:05 - 00000000 ____D C:\ComboFix 2013-08-31 15:37 - 2013-08-31 15:52 - 00000000 ____D C:\Qoobox 2013-08-31 15:37 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-31 15:37 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-31 15:37 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-31 15:37 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-31 15:37 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-31 15:37 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-31 15:37 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-31 15:37 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-31 15:36 - 2013-08-31 15:36 - 00000000 ____D C:\Windows\erdnt 2013-08-31 14:48 - 2013-08-31 14:48 - 00000000 ____D C:\FRST 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Users\Max\AppData\Roaming\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-31 14:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-31 14:07 - 2013-09-01 14:09 - 00000000 ____D C:\Users\Max\Desktop\Bereinigung 2013-08-30 17:46 - 2013-08-30 17:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-28 15:55 - 2013-08-28 15:55 - 00001057 _____ C:\Users\Max\Documents\youtube 28.08.txt 2013-08-27 17:44 - 2013-08-27 17:44 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-27 17:30 - 2013-08-27 22:00 - 00000000 ____D C:\Users\Max\Desktop\backup handy 27.08.13 2013-08-25 19:03 - 2013-08-25 19:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-25 19:03 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-25 19:03 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-25 19:03 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-25 19:02 - 2013-09-01 13:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-25 19:02 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-25 19:02 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-25 19:02 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-25 19:02 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-25 18:56 - 2013-08-25 19:01 - 117478104 _____ C:\Users\Max\Downloads\avast_free_antivirus_setup.exe 2013-08-25 14:46 - 2013-08-31 21:55 - 00011294 _____ C:\Windows\PFRO.log 2013-08-23 21:10 - 2013-09-01 14:05 - 00001512 _____ C:\Windows\setupact.log 2013-08-23 21:10 - 2013-08-23 21:10 - 00000000 _____ C:\Windows\setuperr.log 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Downloads\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Desktop\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00000000 ____D C:\Users\Max\Desktop\download-downloadfile-26830 2013-08-22 17:23 - 2013-08-22 17:23 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00000000 ____D C:\Program Files\Java 2013-08-22 17:22 - 2013-08-22 17:23 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64(1).exe 2013-08-22 17:21 - 2013-08-22 17:23 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-22 17:21 - 2013-08-22 17:23 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-22 17:20 - 2013-08-22 17:20 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64.exe 2013-08-22 16:19 - 2013-08-22 16:19 - 00106977 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.2_Forge.jar 2013-08-22 16:14 - 2013-08-22 16:14 - 00095243 _____ C:\Users\Max\Downloads\EllianDetector.jar 2013-08-22 16:07 - 2013-08-22 16:07 - 00000000 ____D C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:03 - 2013-08-22 16:03 - 00106986 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1_Forge.jar 2013-08-22 15:59 - 2013-08-31 21:46 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft 2013-08-22 15:58 - 2013-08-22 15:59 - 00350720 _____ C:\Users\Max\Desktop\Minecraft.exe 2013-08-22 15:58 - 2013-08-22 15:58 - 54928642 _____ C:\Users\Max\Desktop\Minecraft1.6.1-Wazez.zip 2013-08-22 15:57 - 2013-08-22 15:58 - 54928642 _____ C:\Users\Max\Downloads\Minecraft1.6.1-Wazez.zip 2013-08-22 15:52 - 2013-08-22 15:52 - 00675988 _____ C:\Users\Max\Downloads\Minecraft (1).exe 2013-08-22 15:49 - 2013-08-22 15:50 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft - Kopie (2) 2013-08-20 22:13 - 2013-08-20 22:13 - 85392925 _____ C:\Users\Max\Downloads\pavel.zip 2013-08-19 22:11 - 2013-08-19 22:12 - 437283794 _____ C:\Users\Max\Desktop\Unbenannt-1.psd 2013-08-14 15:32 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-14 15:32 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-14 15:32 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-14 15:32 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-14 15:32 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-14 15:32 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-14 15:32 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-14 15:32 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-14 15:32 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-14 15:32 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-14 15:32 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-14 15:32 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-14 15:32 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-14 15:32 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 14:30 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 14:30 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 14:29 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 14:29 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 14:29 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 14:29 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 14:29 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 14:29 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 14:29 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 14:29 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 14:29 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 14:29 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 14:29 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 14:29 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 14:29 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 14:29 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 14:29 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 14:29 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 14:29 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 14:29 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 14:29 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 14:29 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 14:29 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 14:29 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 14:29 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 14:29 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 14:29 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-14 14:29 - 2012-11-30 07:45 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2013-08-14 14:29 - 2012-11-30 07:45 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2013-08-14 14:29 - 2012-11-30 07:43 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2013-08-14 14:29 - 2012-11-30 07:41 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-08-14 14:29 - 2012-11-30 07:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 07:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:53 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-08-14 14:29 - 2012-11-30 06:53 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 06:45 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 05:23 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-08-14 14:29 - 2012-11-30 04:38 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 04:38 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 04:38 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-08-14 14:29 - 2012-11-30 04:38 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll ==================== One Month Modified Files and Folders ======= 2013-09-01 14:09 - 2013-08-31 14:07 - 00000000 ____D C:\Users\Max\Desktop\Bereinigung 2013-09-01 14:08 - 2013-05-16 17:52 - 00003112 _____ C:\Windows\System32\Tasks\RDReminder 2013-09-01 14:07 - 2013-07-12 15:04 - 00000000 ____D C:\Users\Max\AppData\Local\LogMeIn Hamachi 2013-09-01 14:07 - 2013-04-07 21:26 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-01 14:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-01 14:05 - 2013-08-23 21:10 - 00001512 _____ C:\Windows\setupact.log 2013-09-01 14:05 - 2013-04-07 14:27 - 00000000 ____D C:\ProgramData\NVIDIA 2013-09-01 14:04 - 2013-04-07 15:15 - 02072995 _____ C:\Windows\WindowsUpdate.log 2013-09-01 13:42 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-01 13:42 - 2009-07-14 06:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-01 13:41 - 2013-04-07 21:26 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-01 13:39 - 2013-04-20 17:53 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-01 13:35 - 2013-08-25 19:02 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-01 13:32 - 2013-09-01 13:30 - 00000000 ____D C:\AdwCleaner 2013-09-01 13:32 - 2013-04-08 21:11 - 00000000 ____D C:\Users\Max\AppData\Local\Adobe 2013-08-31 21:55 - 2013-08-25 14:46 - 00011294 _____ C:\Windows\PFRO.log 2013-08-31 21:46 - 2013-08-22 15:59 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft 2013-08-31 19:56 - 2013-04-10 17:27 - 00000288 _____ C:\Windows\Tasks\DLL-Files.Com Fixer_Updates.job 2013-08-31 16:32 - 2013-04-08 21:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-31 16:05 - 2013-08-31 15:37 - 00000000 ____D C:\ComboFix 2013-08-31 16:03 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-31 15:52 - 2013-08-31 15:37 - 00000000 ____D C:\Qoobox 2013-08-31 15:51 - 2013-06-21 18:57 - 00000000 ____D C:\Users\Max\AppData\Roaming\convert 2013-08-31 15:37 - 2013-04-20 15:49 - 00000000 ____D C:\Users\Max\AppData\Local\CrashDumps 2013-08-31 15:36 - 2013-08-31 15:36 - 00000000 ____D C:\Windows\erdnt 2013-08-31 14:48 - 2013-08-31 14:48 - 00000000 ____D C:\FRST 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Users\Max\AppData\Roaming\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-31 14:09 - 2013-08-31 14:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-30 17:46 - 2013-08-30 17:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-29 16:40 - 2013-04-14 17:56 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-08-29 16:40 - 2013-04-13 21:07 - 00290184 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-08-29 16:39 - 2013-04-13 21:07 - 00280904 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-08-28 15:55 - 2013-08-28 15:55 - 00001057 _____ C:\Users\Max\Documents\youtube 28.08.txt 2013-08-27 22:00 - 2013-08-27 17:30 - 00000000 ____D C:\Users\Max\Desktop\backup handy 27.08.13 2013-08-27 18:40 - 2013-04-07 15:20 - 00000000 ____D C:\Users\Max\AppData\Local\VirtualStore 2013-08-27 17:45 - 2013-04-07 14:14 - 00000000 ____D C:\Users\Max\AppData\Roaming\Adobe 2013-08-27 17:44 - 2013-08-27 17:44 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-27 17:43 - 2013-04-07 14:13 - 00000000 ____D C:\ProgramData\Adobe 2013-08-27 17:43 - 2013-04-07 14:13 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-08-27 17:30 - 2011-04-12 09:43 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-08-27 17:30 - 2011-04-12 09:43 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-08-27 17:30 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-25 19:03 - 2013-08-25 19:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-25 19:03 - 2013-08-25 19:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-25 19:02 - 2013-08-25 19:02 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-25 19:01 - 2013-08-25 18:56 - 117478104 _____ C:\Users\Max\Downloads\avast_free_antivirus_setup.exe 2013-08-23 22:44 - 2013-06-27 17:49 - 00000000 ____D C:\Users\Max\Desktop\100CANON 2013-08-23 21:10 - 2013-08-23 21:10 - 00000000 _____ C:\Windows\setuperr.log 2013-08-23 19:33 - 2013-04-07 16:12 - 00000000 ____D C:\Windows\Panther 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Downloads\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00001205 _____ C:\Users\Max\Desktop\download-downloadfile-26830.zip 2013-08-23 15:35 - 2013-08-23 15:35 - 00000000 ____D C:\Users\Max\Desktop\download-downloadfile-26830 2013-08-22 18:41 - 2013-04-14 14:42 - 00000834 _____ C:\Users\Max\Desktop\Minecraft.lnk 2013-08-22 17:23 - 2013-08-22 17:23 - 00312232 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00188840 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-08-22 17:23 - 2013-08-22 17:23 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-08-22 17:23 - 2013-08-22 17:23 - 00000000 ____D C:\Program Files\Java 2013-08-22 17:23 - 2013-08-22 17:22 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64(1).exe 2013-08-22 17:23 - 2013-08-22 17:21 - 01093032 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-08-22 17:23 - 2013-08-22 17:21 - 00972712 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-08-22 17:20 - 2013-08-22 17:20 - 33150376 _____ (Oracle Corporation) C:\Users\Max\Downloads\jre-7u25-windows-x64.exe 2013-08-22 16:19 - 2013-08-22 16:19 - 00106977 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.2_Forge.jar 2013-08-22 16:14 - 2013-08-22 16:14 - 00095243 _____ C:\Users\Max\Downloads\EllianDetector.jar 2013-08-22 16:07 - 2013-08-22 16:07 - 00000000 ____D C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:06 - 2013-08-22 16:06 - 00111079 _____ C:\Users\Max\Desktop\TooManyItems2013_07_30_1.6.1.zip 2013-08-22 16:03 - 2013-08-22 16:03 - 00106986 _____ C:\Users\Max\Downloads\TooManyItems2013_07_30_1.6.1_Forge.jar 2013-08-22 15:59 - 2013-08-22 15:58 - 00350720 _____ C:\Users\Max\Desktop\Minecraft.exe 2013-08-22 15:58 - 2013-08-22 15:58 - 54928642 _____ C:\Users\Max\Desktop\Minecraft1.6.1-Wazez.zip 2013-08-22 15:58 - 2013-08-22 15:57 - 54928642 _____ C:\Users\Max\Downloads\Minecraft1.6.1-Wazez.zip 2013-08-22 15:52 - 2013-08-22 15:52 - 00675988 _____ C:\Users\Max\Downloads\Minecraft (1).exe 2013-08-22 15:50 - 2013-08-22 15:49 - 00000000 ____D C:\Users\Max\AppData\Roaming\.minecraft - Kopie (2) 2013-08-20 22:13 - 2013-08-20 22:13 - 85392925 _____ C:\Users\Max\Downloads\pavel.zip 2013-08-20 20:39 - 2013-04-20 17:53 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-20 20:39 - 2013-04-20 17:53 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-20 20:39 - 2013-04-20 17:53 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-19 22:12 - 2013-08-19 22:11 - 437283794 _____ C:\Users\Max\Desktop\Unbenannt-1.psd 2013-08-19 19:59 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-12 11:42 - 2013-04-07 21:27 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk Files to move or delete: ==================== C:\Users\Max\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-01 13:57 ==================== End Of Log ============================ |
ESET Online Scanner
Downloade Dir bitte
und ein frisches FRST log bitte. Noch Probleme?
Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM!
