|
Plagegeister aller Art und deren Bekämpfung: Infizierte Webseite: trickzone.net/nicht-klicken-das-original.htmlWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.10.2013, 15:01 | #91 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html Sag mal Herr Professor, was muss ich denn tun, um meinen Adobe Flashplayer zu aktualisieren OHNE mir dabei diese äußerst lästige Google Toolbar und den, wie ich finde, genauso lästigen Google Chrome Rotz andrehen zu lassen?? Avast schickt mich ja schon auf die Original-Anbieterseite, aber da besteht diesmal nit die Möglichkeit das abzuwählen. Ich will aber den Schrott nit haben
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
09.10.2013, 21:28 | #92 |
/// the machine /// TB-Ausbilder | Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html Die Möglichkeit gibt es immer. Im Fenster auf der Seite unten schon den Halen raus machen.
__________________
__________________ |
09.10.2013, 21:52 | #93 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html Stimmt, hast mal wieder recht..
__________________sehr gut! Danke!
__________________ |
10.10.2013, 09:02 | #94 | |
/// the machine /// TB-Ausbilder | Infizierte Webseite: trickzone.net/nicht-klicken-das-original.htmlZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.10.2013, 09:27 | #95 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html Wenn ich da an Deine letzte PN denke muss ich Dir leider widersprechen
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
10.10.2013, 09:27 | #96 |
/// the machine /// TB-Ausbilder | Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html schau nochmal
__________________ --> Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html |
10.10.2013, 09:32 | #97 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html done na juut, dann hat der Schraubi doch fast immer recht, außer natürlich wenn ich anderer Meinung bin dann hab nämlich selbstverständlich ich recht
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
16.10.2013, 10:54 | #98 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013 Ran by Tanja at 2013-10-16 08:49:29 Running from C:\Users\Tanja\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x32) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) ALDI TALK Verbindungsassistent (x32 Version: ) avast! Ad Blocker (x32 Version: 1.0.0.0) avast! Free Antivirus (x32 Version: 8.0.1497.0) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition Feedback Tool (x32 Version: 1.2.0) Free YouTube to MP3 Converter version 3.12.12.827 (x32 Version: 3.12.12.827) GNU Backgammon (Version 1_02_000, 20130728) (x32) HUAWEI DataCard Driver 3.17.06.00 (x32 Version: 3.17.06.00) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Access MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft DCF MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Excel MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Groove MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Lync MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office 32-bit Components 2013 (Version: 15.0.4420.1017) Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4420.1017) Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017) Microsoft Office Proofing (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017) Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4420.1017) Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft OneNote MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Outlook MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Publisher MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Word MUI (German) 2013 (Version: 15.0.4420.1017) NVIDIA 3D Vision Treiber 327.23 (Version: 327.23) NVIDIA Display Control Panel (Version: 1.10) NVIDIA Grafiktreiber 327.23 (Version: 327.23) NVIDIA Install Application (Version: 2.1002.133.889) NVIDIA PhysX (x32 Version: 9.09.1112) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2723) NVIDIA Systemsteuerung 327.23 (Version: 327.23) NVIDIA Update 1.14.17 (Version: 1.14.17) NVIDIA Update Components (Version: 1.14.17) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017) Paint.NET v3.5.11 (Version: 3.61.0) PDF-Viewer (Version: 2.5.211.0) Realtek Ethernet Controller Driver (x32 Version: 7.54.309.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6680) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127) Revo Uninstaller Pro 3.0.7 (Version: 3.0.7) SiSoftware Sandra Lite 2013.SP5 (Version: 19.58.2013.9) TeamViewer 8 (x32 Version: 8.0.20202) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Excel 2013 (KB2760339) 64-Bit Edition Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition Update for Microsoft Office 2013 (KB2737954) 64-Bit Edition Update for Microsoft Office 2013 (KB2752025) 64-Bit Edition Update for Microsoft Office 2013 (KB2752094) 64-Bit Edition Update for Microsoft Office 2013 (KB2752101) 64-Bit Edition Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition Update for Microsoft Office 2013 (KB2760538) 64-Bit Edition Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition Update for Microsoft Office 2013 (KB2767860) 64-Bit Edition Update for Microsoft Office 2013 (KB2768016) 64-Bit Edition Update for Microsoft Office 2013 (KB2817320) 64-Bit Edition Update for Microsoft Office 2013 (KB2817482) 64-Bit Edition Update for Microsoft PowerPoint 2013 (KB2726947) 64-Bit Edition Update for Microsoft PowerPoint 2013 (KB2810006) 64-Bit Edition Update for Microsoft Word 2013 (KB2810086) 64-Bit Edition WinPatrol (Version: 28.6.2013.0) WOT for Internet Explorer (Version: 12.8.2.0) ==================== Restore Points ========================= 26-09-2013 23:18:46 Wiederherstellungsvorgang 27-09-2013 20:17:34 Windows Update 28-09-2013 15:31:59 Revo Uninstaller Pro's restore point - avast! Free Antivirus 28-09-2013 15:40:04 Revo Uninstaller Pro's restore point - avast! Free Antivirus 28-09-2013 15:44:59 Revo Uninstaller Pro's restore point - avast! Free Antivirus 28-09-2013 15:45:51 Revo Uninstaller Pro's restore point - avast! Free Antivirus 28-09-2013 15:46:33 avast! Free Antivirus Setup 28-09-2013 15:51:18 avast! Free Antivirus Setup 01-10-2013 21:49:05 Windows Update 08-10-2013 10:49:04 Windows Update 10-10-2013 00:00:14 Windows Update 12-10-2013 14:52:10 Installed Microsoft Fix it 50123 12-10-2013 20:35:18 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-09-03 22:08 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {401F0CC5-5E68-428B-A3CB-DFDBB95CE7E0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {424F3579-E36D-413F-A9F7-E17EBF3C26B0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software) Task: {6E91DED9-2C8E-4360-A758-11544F13BFE3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {700448E5-6348-429A-8E70-F3DFA1DF1F97} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {768A7A67-5584-44B3-A374-26B7F810B44D} - System32\Tasks\{6A200771-FD41-4EA9-97C8-37561BCB9A99} => C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-08-30] (AVAST Software) Task: {78BC1CE8-7B16-40BB-B9DB-B06BF055C393} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {7ADD72F1-9A7A-42EB-BB75-4CEEC263A3A9} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Tanja-PC-Tanja Tanja-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation) Task: {CCD199CC-E775-4702-88BA-B80703F668E0} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {DB81FB7D-4F95-4B26-936C-4B6801094DB8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {FCA83BC5-6633-43F1-86FC-EDF70F55C056} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1534933586-3234829136-843548077-1000 Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-15 22:08 - 2013-10-15 19:04 - 02105856 _____ () C:\Program Files\AVAST Software\Avast\defs\13101501\algo.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00102400 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgDatabase.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00106496 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgUtil.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00090112 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgPorts.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00200704 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgDetection.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00086016 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgDialup.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00012288 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WTGDebugs.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00073728 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgDriverInstall.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00569344 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgCore.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00139264 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgBluetooth.dll 2013-09-11 17:16 - 2013-09-11 17:16 - 00204800 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\LiveBoxCM.dll 2013-09-11 17:16 - 2013-09-11 17:16 - 00823296 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\LIBEAY32.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00126976 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WtgWiFi.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00614400 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WTGXMLUtil.dll 2013-09-11 17:17 - 2013-09-11 17:17 - 00303104 _____ () C:\Program Files (x86)\ALDITALKVerbindungsassistent\WTGSMSPCClient.Dll 2012-08-02 18:15 - 2012-08-02 18:15 - 01542720 _____ () C:\Program Files (x86)\WOT\WOT.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (10/16/2013 01:13:24 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/16/2013 01:13:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (10/14/2013 07:05:53 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "UPnP-Gerätehost" ist vom Dienst "SSDP-Suche" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (10/14/2013 06:33:54 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "UPnP-Gerätehost" ist vom Dienst "SSDP-Suche" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (10/14/2013 06:33:54 AM) (Source: DCOM) (User: ) Description: 1068upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (10/13/2013 04:37:43 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Error: (10/13/2013 01:11:49 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Error: (10/12/2013 09:48:29 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Error: (10/12/2013 09:38:39 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Error: (10/12/2013 09:30:44 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Error: (10/12/2013 09:29:32 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Error: (10/12/2013 09:19:07 PM) (Source: DCOM) (User: Tanja-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Tanja-PCTanjaS-1-5-21-1534933586-3234829136-843548077-1000LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= Error: (10/16/2013 01:13:24 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/16/2013 01:13:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL ==================== Memory info =========================== Percentage of memory in use: 47% Total physical RAM: 4023.11 MB Available physical RAM: 2124.23 MB Total Pagefile: 8044.4 MB Available Pagefile: 5948.73 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:453.45 GB) (Free:408.46 GB) NTFS Drive d: () (Fixed) (Total:453.96 GB) (Free:452.51 GB) NTFS Drive f: (MEDION) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 18EB46D9) Partition 1: (Not Active) - (Size=24 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=454 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013 Ran by Tanja (administrator) on TANJA-PC on 16-10-2013 08:49:02 Running from C:\Users\Tanja\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Launcher.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\system32\LogonUI.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe (Microsoft Corporation) C:\Windows\system32\wbengine.exe (Microsoft Corporation) C:\Windows\System32\vds.exe ==================== Registry (Whitelisted) ================== HKLM\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe MountPoints2: {3158f715-0992-11e3-82da-806e6f6e6963} - F:\AutoRun.exe MountPoints2: {c0f88b84-1aba-11e3-9b75-4487fc7fc2b4} - F:\AutoRun.exe HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBE493160A49DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll () BHO: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll () BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker32.dll (AVAST Software) Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () DPF: HKLM-x32 {B8BE5E93-A60C-4D26-A2DC-220313175592} hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab DPF: HKLM-x32 {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll () Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation) Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll () Tcpip\..\Interfaces\{390C0067-88BE-4057-93E5-229D9E2C87E8}: [NameServer]212.23.115.148 212.23.115.132 Tcpip\..\Interfaces\{E352EA60-3E98-42BC-8840-B4B5E13417C4}: [NameServer]212.23.115.150 212.23.115.132 ==================== Services (Whitelisted) ================= R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-09-11] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP5\RpcAgentSrv.exe [71832 2008-08-29] (SiSoftware) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP5\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2013-09-11] () S3 cpuz132; \??\C:\Users\Tanja\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x] U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.) U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-05] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-16 08:48 - 2013-10-16 08:48 - 01954124 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-12 22:35 - 2013-09-04 14:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-12 22:35 - 2013-09-04 14:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-12 22:35 - 2013-09-04 14:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-12 22:35 - 2013-09-04 14:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-12 22:35 - 2013-09-04 14:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-12 22:35 - 2013-09-04 14:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-12 22:35 - 2013-09-04 14:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-10 02:07 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-10 02:07 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-10 02:07 - 2013-09-23 01:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-10 02:07 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-10 02:07 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-10 02:07 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-10 02:07 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-10 02:07 - 2013-09-23 00:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-10 02:07 - 2013-09-21 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-10 02:07 - 2013-09-21 05:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-10 02:07 - 2013-09-21 04:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-10 02:07 - 2013-09-21 04:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-09 23:57 - 2013-09-14 03:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-09 23:57 - 2013-09-08 04:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-09 23:57 - 2013-09-08 04:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-09 23:57 - 2013-09-08 04:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-09 23:57 - 2013-08-29 04:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-09 23:57 - 2013-08-29 04:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-09 23:57 - 2013-08-29 04:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-09 23:57 - 2013-08-29 04:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-09 23:57 - 2013-08-29 04:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-09 23:57 - 2013-08-29 03:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-09 23:57 - 2013-08-29 03:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-09 23:57 - 2013-08-29 03:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-09 23:57 - 2013-08-29 03:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-09 23:57 - 2013-08-29 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-09 23:57 - 2013-08-29 03:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-09 23:57 - 2013-08-29 02:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-09 23:57 - 2013-08-29 02:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-09 23:57 - 2013-08-29 02:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-09 23:57 - 2013-08-29 02:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-09 23:57 - 2013-08-28 03:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 23:57 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 23:57 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-09 23:57 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 23:57 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-09 23:57 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-09 23:57 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-09 23:57 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 23:57 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-09 23:57 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 23:57 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 23:57 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 23:57 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-09 23:57 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-09 23:57 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-09 23:57 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 23:57 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-09 23:57 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-09 23:57 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-09 23:57 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 23:57 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-09 23:57 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-09 23:52 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-09 23:52 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-09 23:52 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 23:52 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-06 18:33 - 2013-10-06 18:33 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\CrashDumps 2013-10-02 17:20 - 2013-10-02 17:20 - 00000000 ____D C:\FRST 2013-10-01 16:13 - 2013-10-01 16:15 - 00448512 _____ (OldTimer Tools) C:\Users\Tanja\Downloads\TFC.exe 2013-09-28 17:52 - 2013-09-29 19:34 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-28 17:52 - 2013-09-28 17:53 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-28 17:52 - 2013-09-28 17:52 - 00000000 ____D C:\Users\Tanja\AppData\Local\Google 2013-09-28 17:52 - 2013-08-30 09:48 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-09-28 17:52 - 2013-08-30 09:48 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-09-28 17:52 - 2013-08-30 09:48 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-09-28 17:52 - 2013-08-30 09:48 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-09-28 17:52 - 2013-08-30 09:48 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-09-28 17:51 - 2013-10-15 06:04 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-28 17:51 - 2013-08-30 09:48 - 00204880 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-09-28 17:51 - 2013-08-30 09:48 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-09-28 17:51 - 2013-08-30 09:48 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-09-28 17:51 - 2013-08-30 09:47 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-09-27 05:06 - 2013-10-16 01:11 - 00002699 _____ C:\Windows\setupact.log 2013-09-27 05:06 - 2013-09-27 05:06 - 00000000 _____ C:\Windows\setuperr.log 2013-09-26 19:38 - 2013-09-26 19:38 - 00699232 _____ C:\Users\Tanja\Downloads\VDownloader1614InstallerIC.exe 2013-09-26 19:10 - 2013-09-26 19:10 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\DVDVideoSoft 2013-09-26 19:10 - 2013-09-26 19:10 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-09-21 08:04 - 2013-09-21 08:04 - 00000218 _____ C:\Users\Tanja\.recently-used.xbel 2013-09-21 08:04 - 2013-09-21 08:04 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\gtk-2.0 2013-09-20 14:26 - 2013-09-20 14:26 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\NVIDIA 2013-09-20 14:16 - 2013-09-20 14:47 - 00000000 ____D C:\Users\Tanja\.gnubg 2013-09-20 14:16 - 2013-09-20 14:16 - 00000963 _____ C:\Users\Public\Desktop\GNU Backgammon.lnk 2013-09-20 14:16 - 2013-09-20 14:16 - 00000000 ____D C:\Program Files (x86)\gnubg 2013-09-20 13:36 - 2013-09-20 14:15 - 36019309 _____ (Free Software Foundation ) C:\Users\Tanja\Downloads\gnubg-release-1_02_000-20130728-setup.exe 2013-09-17 22:22 - 2013-09-17 22:22 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-17 22:22 - 2013-09-17 22:22 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll ==================== One Month Modified Files and Folders ======= 2013-10-16 08:48 - 2013-10-16 08:48 - 01954124 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-16 07:53 - 2013-08-24 05:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-16 05:38 - 2013-08-20 16:34 - 01446982 _____ C:\Windows\WindowsUpdate.log 2013-10-16 01:58 - 2013-08-21 21:35 - 00005072 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Tanja-PC-Tanja Tanja-PC 2013-10-16 01:19 - 2009-07-14 06:45 - 00018832 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-16 01:19 - 2009-07-14 06:45 - 00018832 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-16 01:16 - 2009-07-14 19:58 - 00655802 _____ C:\Windows\system32\perfh007.dat 2013-10-16 01:16 - 2009-07-14 19:58 - 00130434 _____ C:\Windows\system32\perfc007.dat 2013-10-16 01:16 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-16 01:13 - 2013-09-11 17:16 - 00000000 ____D C:\Program Files (x86)\ALDITALKVerbindungsassistent 2013-10-16 01:12 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-16 01:11 - 2013-09-27 05:06 - 00002699 _____ C:\Windows\setupact.log 2013-10-16 01:11 - 2013-08-20 16:00 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-15 21:14 - 2013-08-26 22:45 - 00000000 ____D C:\Users\Tanja\AppData\Local\Paint.NET 2013-10-15 20:51 - 2013-08-22 00:38 - 00000000 ____D C:\Users\Tanja\Desktop\Programme 2013-10-15 07:38 - 2013-08-20 17:02 - 00000000 ____D C:\Users\Tanja\Desktop\fotos 2013-10-15 06:04 - 2013-09-28 17:51 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-12 21:13 - 2013-09-13 10:14 - 00000000 ____D C:\Users\Tanja\AppData\Local\CrashDumps 2013-10-10 03:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-10-10 02:26 - 2013-08-20 18:44 - 00370352 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-10 02:04 - 2013-08-22 07:38 - 00000000 ____D C:\Windows\system32\MRT 2013-10-10 02:02 - 2013-08-22 07:38 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 22:53 - 2013-08-24 05:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 22:53 - 2013-08-24 05:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 22:53 - 2013-08-24 05:40 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 22:53 - 2013-08-20 17:34 - 00000000 ____D C:\Users\Tanja\AppData\Local\Adobe 2013-10-07 15:08 - 2013-09-09 12:20 - 00000000 ____D C:\Program Files (x86)\mbar 2013-10-07 15:08 - 2013-09-04 13:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-06 18:33 - 2013-10-06 18:33 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\CrashDumps 2013-10-02 17:20 - 2013-10-02 17:20 - 00000000 ____D C:\FRST 2013-10-01 16:15 - 2013-10-01 16:13 - 00448512 _____ (OldTimer Tools) C:\Users\Tanja\Downloads\TFC.exe 2013-09-29 19:34 - 2013-09-28 17:52 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-28 18:16 - 2013-08-20 17:13 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-09-28 18:10 - 2013-08-20 21:44 - 00056950 _____ C:\Windows\PFRO.log 2013-09-28 18:06 - 2013-08-20 17:13 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-09-28 18:06 - 2013-08-20 17:13 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-09-28 18:06 - 2013-08-20 17:13 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-09-28 17:53 - 2013-09-28 17:52 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-28 17:52 - 2013-09-28 17:52 - 00000000 ____D C:\Users\Tanja\AppData\Local\Google 2013-09-28 17:51 - 2013-08-20 17:12 - 00000000 ____D C:\Program Files\AVAST Software 2013-09-28 17:51 - 2013-08-20 17:11 - 00000000 ____D C:\ProgramData\AVAST Software 2013-09-27 05:06 - 2013-09-27 05:06 - 00000000 _____ C:\Windows\setuperr.log 2013-09-27 01:21 - 2013-08-20 14:25 - 00000000 ____D C:\Users\Tanja 2013-09-27 01:20 - 2013-08-20 17:28 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2013-09-27 01:20 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-09-26 20:25 - 2013-08-20 14:25 - 00001421 _____ C:\Users\Tanja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-26 19:38 - 2013-09-26 19:38 - 00699232 _____ C:\Users\Tanja\Downloads\VDownloader1614InstallerIC.exe 2013-09-26 19:10 - 2013-09-26 19:10 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\DVDVideoSoft 2013-09-26 19:10 - 2013-09-26 19:10 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-09-25 12:43 - 2013-09-09 21:34 - 00000000 ____D C:\Windows\System32\Tasks\Games 2013-09-23 23:33 - 2013-08-20 15:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-09-23 01:28 - 2013-10-10 02:07 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-09-23 01:28 - 2013-10-10 02:07 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-09-23 01:27 - 2013-10-10 02:07 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-09-23 00:55 - 2013-10-10 02:07 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-23 00:55 - 2013-10-10 02:07 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-23 00:55 - 2013-10-10 02:07 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-23 00:54 - 2013-10-10 02:07 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-23 00:54 - 2013-10-10 02:07 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-21 08:04 - 2013-09-21 08:04 - 00000218 _____ C:\Users\Tanja\.recently-used.xbel 2013-09-21 08:04 - 2013-09-21 08:04 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\gtk-2.0 2013-09-21 05:38 - 2013-10-10 02:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-21 05:30 - 2013-10-10 02:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-09-21 04:48 - 2013-10-10 02:07 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-21 04:39 - 2013-10-10 02:07 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-09-20 14:47 - 2013-09-20 14:16 - 00000000 ____D C:\Users\Tanja\.gnubg 2013-09-20 14:26 - 2013-09-20 14:26 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\NVIDIA 2013-09-20 14:16 - 2013-09-20 14:16 - 00000963 _____ C:\Users\Public\Desktop\GNU Backgammon.lnk 2013-09-20 14:16 - 2013-09-20 14:16 - 00000000 ____D C:\Program Files (x86)\gnubg 2013-09-20 14:15 - 2013-09-20 13:36 - 36019309 _____ (Free Software Foundation ) C:\Users\Tanja\Downloads\gnubg-release-1_02_000-20130728-setup.exe 2013-09-18 13:42 - 2013-09-12 04:15 - 00001218 _____ C:\Users\Public\Desktop\SiSoftware Sandra Lite 2013.SP5.lnk 2013-09-18 13:42 - 2013-09-11 15:11 - 00001121 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-09-17 22:22 - 2013-09-17 22:22 - 29337376 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 22102304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 15703688 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 11274528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-09-17 22:22 - 2013-09-17 22:22 - 09281032 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 07720576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 07648000 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 06329552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02970400 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02789152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02630304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02367264 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 02007328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432723.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432723.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00681760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00603424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00586016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-09-17 22:22 - 2013-09-17 22:22 - 00515360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-09-17 22:22 - 2013-08-20 15:58 - 00022814 _____ C:\Windows\system32\nvinfo.pb 2013-09-17 22:22 - 2013-02-26 00:32 - 15901448 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-09-17 22:22 - 2013-02-26 00:32 - 13628208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-09-17 22:22 - 2013-02-26 00:32 - 12947360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-09-17 22:22 - 2013-02-26 00:32 - 02986672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-09-17 20:41 - 2013-08-20 17:24 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-17 14:59 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Tanja\AppData\Local\Microsoft Games ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-11 10:15 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- ich bereinige mein System jetzt selber!!
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
16.10.2013, 11:30 | #99 |
/// the machine /// TB-Ausbilder | Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html schaut gut aus.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2013, 11:43 | #100 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html ne nicht gut, ich bin eingeschnappt das der Virus nicht mehr da ist wusste ich auch selber ich bereinige jetzt trotzdem und zwar mit combofix haha
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
16.10.2013, 11:50 | #101 |
/// the machine /// TB-Ausbilder | Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html da gibt es nix zu bereinigen, aber der rechner war ja auch schon lang nimmer zerschossen.....
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2013, 11:56 | #102 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html eben! und wir haben uns ja auch lang nit mehr gestritten
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
16.10.2013, 12:01 | #103 |
/// the machine /// TB-Ausbilder | Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html genau....
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.10.2013, 13:08 | #104 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html Ahhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh Combofix hat mein System zerschossen Ne, Spaß Ich war brav! und was den Rest betrifft, ich denke es ist mal wieder an der Zeit für einen Roman Hatten wir ja seit damals nicht mehr kommt dann per pm
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
27.10.2013, 13:54 | #105 |
| Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2013 01 Ran by Tanja (administrator) on TANJA-PC on 27-10-2013 13:06:13 Running from C:\Users\Tanja\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe () C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MsoSync.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-09-19] (NVIDIA Corporation) HKLM\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe MountPoints2: {3158f715-0992-11e3-82da-806e6f6e6963} - F:\AutoRun.exe MountPoints2: {c0f88b84-1aba-11e3-9b75-4487fc7fc2b4} - F:\AutoRun.exe HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-10-14] (AVAST Software) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xBE493160A49DCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Bing StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll () BHO: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker64.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation) BHO-x32: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll () BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: avast! Ad Blocker - {FFCB3198-32F3-4E8B-9539-4324694ED663} - C:\Program Files (x86)\AVAST Software\avast! Ad Blocker IE\Adblocker32.dll (AVAST Software) Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () DPF: HKLM-x32 {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramewor....cab102118.cab DPF: HKLM-x32 {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} http://zone.msn.com/bingame/zpagames...n.cab64162.cab Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll () Handler-x32: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\syswow64\urlmon.dll (Microsoft Corporation) Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll () Tcpip\..\Interfaces\{390C0067-88BE-4057-93E5-229D9E2C87E8}: [NameServer]212.23.115.148 212.23.115.132 Tcpip\..\Interfaces\{61E5C6EC-242B-48E4-A734-C077BA2192F6}: [NameServer]212.23.115.150 212.23.115.132 ==================== Services (Whitelisted) ================= R2 ALDITALKVerbindungsassistent_Service; C:\Program Files (x86)\ALDITALKVerbindungsassistent\ALDITALKVerbindungsassistent_Service.exe [358968 2013-09-11] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-10-14] (AVAST Software) R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [109352 2013-10-26] (SurfRight B.V.) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-09-19] (NVIDIA Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-10-14] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-10-14] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-10-14] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-10-14] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-10-14] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-10-14] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-10-14] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-10-14] () R3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation) S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2013-09-11] () S3 cpuz132; \??\C:\Users\Tanja\AppData\Local\Temp\cpuz132\cpuz132_x64.sys [x] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x] U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.) U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-05] (Microsoft Corporation) S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP5\WNt500x64\Sandra.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-27 13:02 - 2013-10-27 13:02 - 00020381 _____ C:\Users\Tanja\Downloads\Addition.txt 2013-10-27 13:00 - 2013-10-27 13:01 - 01956160 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-26 21:37 - 2013-10-26 21:37 - 00001905 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2013-10-26 21:28 - 2013-10-26 21:37 - 00000000 ____D C:\Program Files\HitmanPro 2013-10-26 21:26 - 2013-10-26 21:37 - 00000000 ____D C:\ProgramData\HitmanPro 2013-10-26 21:26 - 2013-10-26 21:26 - 00000000 ____D C:\Users\Tanja\Downloads\HitmanPro_3.7.6.201 2013-10-26 21:24 - 2013-10-26 21:26 - 12223884 _____ C:\Users\Tanja\Downloads\HitmanPro_3.7.6.201.zip 2013-10-26 07:26 - 2013-10-26 07:26 - 00000000 ____D C:\Users\Tanja\AppData\Local\PDF24 2013-10-26 07:25 - 2013-10-26 07:25 - 00001074 _____ C:\Users\Public\Desktop\PDF24 Editor.lnk 2013-10-26 07:25 - 2013-10-26 07:25 - 00000000 ____D C:\Program Files (x86)\PDF24 2013-10-26 07:22 - 2013-10-26 07:24 - 15911976 _____ (Geek Software GmbH ) C:\Users\Tanja\Downloads\pdf24-creator-5.7.0.exe 2013-10-26 07:13 - 2013-10-26 07:31 - 00000000 ____D C:\Users\Tanja\Desktop\tanisha 2013-10-26 07:13 - 2013-10-26 07:13 - 00000000 ____D C:\Users\Tanja\Desktop\Tanysha 2013-10-24 19:25 - 2013-10-24 19:25 - 00448512 _____ (OldTimer Tools) C:\Users\Tanja\Downloads\TFC.exe 2013-10-21 18:47 - 2013-10-21 18:47 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 18:45 - 2013-10-21 18:45 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2013-10-21 18:45 - 2013-08-23 20:34 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help 2013-10-21 18:45 - 2013-08-21 22:13 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2013-10-21 18:45 - 2013-08-21 22:13 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2013-10-21 18:41 - 2013-10-22 07:48 - 01594042 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-21 17:19 - 2013-10-16 01:48 - 30344992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 15244272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-21 17:19 - 2013-10-16 01:48 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 02694664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-21 17:19 - 2013-10-16 01:48 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-21 17:19 - 2013-08-20 14:33 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2013-10-21 17:19 - 2013-08-20 14:32 - 00029984 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2013-10-21 17:19 - 2013-08-20 14:32 - 00028448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2013-10-21 17:14 - 2013-10-21 17:14 - 00000000 ____D C:\NVIDIA 2013-10-16 08:25 - 2013-10-20 09:10 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-10-15 15:54 - 2013-10-15 15:54 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-10-12 21:35 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-12 21:35 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-12 21:35 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-12 21:35 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-12 21:35 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-12 21:35 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-12 21:35 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-10 01:07 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-10 01:07 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-10 01:07 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-10 01:07 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-10 01:07 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-10 01:07 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-10 01:07 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-10 01:07 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-10 01:07 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-10 01:07 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-10 01:07 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-10 01:07 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-09 22:57 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-09 22:57 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-09 22:57 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-09 22:57 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-09 22:57 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-09 22:57 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-09 22:57 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-09 22:57 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-09 22:57 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-09 22:57 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-09 22:57 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-09 22:57 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-09 22:57 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-09 22:57 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-09 22:57 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-09 22:57 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-09 22:57 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-09 22:57 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-09 22:57 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-09 22:57 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-09 22:57 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-09 22:57 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-09 22:57 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-09 22:57 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-09 22:57 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-09 22:57 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-09 22:57 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-09 22:57 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-09 22:57 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-09 22:57 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-09 22:57 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-09 22:57 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-09 22:57 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-09 22:57 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-09 22:57 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-09 22:57 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-09 22:57 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-09 22:57 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-09 22:57 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-09 22:57 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-09 22:57 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-09 22:52 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-09 22:52 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-09 22:52 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 22:52 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-02 16:20 - 2013-10-02 16:20 - 00000000 ____D C:\FRST 2013-09-28 16:52 - 2013-10-14 18:41 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-09-28 16:52 - 2013-10-14 18:41 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-09-28 16:52 - 2013-10-14 18:41 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-09-28 16:52 - 2013-10-14 18:41 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-09-28 16:52 - 2013-10-14 18:41 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-09-28 16:52 - 2013-09-29 18:34 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-28 16:52 - 2013-09-28 16:53 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-28 16:52 - 2013-09-28 16:52 - 00000000 ____D C:\Users\Tanja\AppData\Local\Google 2013-09-28 16:51 - 2013-10-25 04:08 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-09-28 16:51 - 2013-10-14 18:41 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-09-28 16:51 - 2013-10-14 18:41 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-09-28 16:51 - 2013-10-14 18:41 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-09-28 16:51 - 2013-10-14 18:41 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-09-27 04:06 - 2013-10-26 11:36 - 00002756 _____ C:\Windows\setupact.log 2013-09-27 04:06 - 2013-10-16 11:01 - 00000000 _____ C:\Windows\setuperr.log ==================== One Month Modified Files and Folders ======= 2013-10-27 13:02 - 2013-10-27 13:02 - 00020381 _____ C:\Users\Tanja\Downloads\Addition.txt 2013-10-27 13:01 - 2013-10-27 13:00 - 01956160 _____ (Farbar) C:\Users\Tanja\Downloads\FRST64.exe 2013-10-27 12:53 - 2013-08-24 04:40 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-10-27 12:51 - 2013-08-21 20:35 - 00005072 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Tanja-PC-Tanja Tanja-PC 2013-10-27 04:38 - 2013-08-20 15:34 - 01902136 _____ C:\Windows\WindowsUpdate.log 2013-10-26 21:37 - 2013-10-26 21:37 - 00001905 _____ C:\Users\Public\Desktop\HitmanPro.lnk 2013-10-26 21:37 - 2013-10-26 21:28 - 00000000 ____D C:\Program Files\HitmanPro 2013-10-26 21:37 - 2013-10-26 21:26 - 00000000 ____D C:\ProgramData\HitmanPro 2013-10-26 21:26 - 2013-10-26 21:26 - 00000000 ____D C:\Users\Tanja\Downloads\HitmanPro_3.7.6.201 2013-10-26 21:26 - 2013-10-26 21:24 - 12223884 _____ C:\Users\Tanja\Downloads\HitmanPro_3.7.6.201.zip 2013-10-26 11:43 - 2009-07-14 05:45 - 00018832 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-26 11:43 - 2009-07-14 05:45 - 00018832 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-26 11:41 - 2009-07-14 18:58 - 00698726 _____ C:\Windows\system32\perfh007.dat 2013-10-26 11:41 - 2009-07-14 18:58 - 00148782 _____ C:\Windows\system32\perfc007.dat 2013-10-26 11:41 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-26 11:36 - 2013-09-27 04:06 - 00002756 _____ C:\Windows\setupact.log 2013-10-26 11:36 - 2013-08-20 15:00 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-26 11:36 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-26 10:23 - 2013-08-21 23:38 - 00000000 ____D C:\Users\Tanja\Desktop\Programme 2013-10-26 10:22 - 2013-08-20 16:02 - 00000000 ____D C:\Users\Tanja\Desktop\fotos 2013-10-26 07:31 - 2013-10-26 07:13 - 00000000 ____D C:\Users\Tanja\Desktop\tanisha 2013-10-26 07:26 - 2013-10-26 07:26 - 00000000 ____D C:\Users\Tanja\AppData\Local\PDF24 2013-10-26 07:25 - 2013-10-26 07:25 - 00001074 _____ C:\Users\Public\Desktop\PDF24 Editor.lnk 2013-10-26 07:25 - 2013-10-26 07:25 - 00000000 ____D C:\Program Files (x86)\PDF24 2013-10-26 07:24 - 2013-10-26 07:22 - 15911976 _____ (Geek Software GmbH ) C:\Users\Tanja\Downloads\pdf24-creator-5.7.0.exe 2013-10-26 07:13 - 2013-10-26 07:13 - 00000000 ____D C:\Users\Tanja\Desktop\Tanysha 2013-10-26 06:46 - 2013-08-26 21:45 - 00000000 ____D C:\Users\Tanja\AppData\Local\Paint.NET 2013-10-25 15:29 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-10-25 04:08 - 2013-09-28 16:51 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-10-24 19:25 - 2013-10-24 19:25 - 00448512 _____ (OldTimer Tools) C:\Users\Tanja\Downloads\TFC.exe 2013-10-24 16:54 - 2013-09-11 10:12 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers 2013-10-24 02:44 - 2013-09-09 20:34 - 00000000 ____D C:\Windows\System32\Tasks\Games 2013-10-22 11:25 - 2013-08-20 20:44 - 00079798 _____ C:\Windows\PFRO.log 2013-10-22 07:48 - 2013-10-21 18:41 - 01594042 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-21 18:47 - 2013-10-21 18:47 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 18:47 - 2013-08-22 06:42 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-10-21 18:47 - 2013-08-20 14:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-21 18:47 - 2013-08-20 14:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-21 18:45 - 2013-10-21 18:45 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten 2013-10-21 18:45 - 2013-10-21 18:45 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten 2013-10-21 17:14 - 2013-10-21 17:14 - 00000000 ____D C:\NVIDIA 2013-10-21 07:10 - 2013-08-20 16:13 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-10-20 09:26 - 2013-09-04 12:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-20 09:10 - 2013-10-16 08:25 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-10-18 20:12 - 2013-09-13 09:14 - 00000000 ____D C:\Users\Tanja\AppData\Local\CrashDumps 2013-10-16 11:18 - 2013-08-20 16:11 - 00000000 ____D C:\ProgramData\AVAST Software 2013-10-16 11:01 - 2013-09-27 04:06 - 00000000 _____ C:\Windows\setuperr.log 2013-10-16 11:01 - 2013-09-11 14:19 - 00002566 _____ C:\Windows\diagwrn.xml 2013-10-16 11:01 - 2013-09-11 14:19 - 00001908 _____ C:\Windows\diagerr.xml 2013-10-16 09:51 - 2013-08-20 16:28 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2013-10-16 09:51 - 2013-08-20 13:25 - 00000000 ____D C:\Users\Tanja 2013-10-16 09:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat 2013-10-16 09:50 - 2013-09-11 16:17 - 00000000 ____D C:\Users\Tanja\AppData\Roaming\ALDITALKVerbindungsassistent 2013-10-16 09:50 - 2013-08-20 16:24 - 00000000 __RHD C:\MSOCache 2013-10-16 09:50 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-10-16 01:48 - 2013-10-21 17:19 - 30344992 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 22933280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 15244272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 12537632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-16 01:48 - 2013-10-21 17:19 - 11415232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 11362672 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 09516872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 09472600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 02694664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433158.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433158.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-16 01:48 - 2013-10-21 17:19 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-16 01:48 - 2013-09-17 21:22 - 18243632 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-10-16 01:48 - 2013-08-20 14:58 - 00023287 _____ C:\Windows\system32\nvinfo.pb 2013-10-16 01:48 - 2013-02-25 23:32 - 18290536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-10-16 01:48 - 2013-02-25 23:32 - 15858664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-16 01:48 - 2013-02-25 23:32 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-10-16 00:13 - 2013-09-11 16:16 - 00000000 ____D C:\Program Files (x86)\ALDITALKVerbindungsassistent 2013-10-15 22:47 - 2010-02-17 09:47 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-10-15 22:47 - 2010-02-17 09:47 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-10-15 22:47 - 2010-02-17 09:47 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-10-15 22:47 - 2010-02-17 09:47 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-10-15 22:47 - 2010-02-17 09:47 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-10-15 22:47 - 2010-02-17 09:46 - 06665504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-10-15 15:54 - 2013-10-15 15:54 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-10-14 18:41 - 2013-09-28 16:52 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-10-14 18:41 - 2013-09-28 16:52 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-10-14 18:41 - 2013-09-28 16:52 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-10-14 18:41 - 2013-09-28 16:52 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-10-14 18:41 - 2013-09-28 16:52 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-10-14 18:41 - 2013-09-28 16:51 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-10-14 18:41 - 2013-09-28 16:51 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-10-14 18:41 - 2013-09-28 16:51 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-10-14 18:41 - 2013-09-28 16:51 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-10-14 18:41 - 2013-08-20 16:13 - 00295544 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-10-10 02:03 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-10 01:26 - 2013-08-20 17:44 - 00370352 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-10 01:04 - 2013-08-22 06:38 - 00000000 ____D C:\Windows\system32\MRT 2013-10-10 01:02 - 2013-08-22 06:38 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-09 21:53 - 2013-08-24 04:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-09 21:53 - 2013-08-24 04:40 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-09 21:53 - 2013-08-24 04:40 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-09 21:53 - 2013-08-20 16:34 - 00000000 ____D C:\Users\Tanja\AppData\Local\Adobe 2013-10-07 14:08 - 2013-09-09 11:20 - 00000000 ____D C:\Program Files (x86)\mbar 2013-10-02 16:20 - 2013-10-02 16:20 - 00000000 ____D C:\FRST 2013-09-29 18:34 - 2013-09-28 16:52 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-09-28 17:06 - 2013-08-20 16:13 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-09-28 17:06 - 2013-08-20 16:13 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-09-28 17:06 - 2013-08-20 16:13 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-09-28 16:53 - 2013-09-28 16:52 - 00000000 ____D C:\Program Files (x86)\Google 2013-09-28 16:52 - 2013-09-28 16:52 - 00000000 ____D C:\Users\Tanja\AppData\Local\Google 2013-09-28 16:51 - 2013-08-20 16:12 - 00000000 ____D C:\Program Files\AVAST Software ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 05:38 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2013 01 Ran by Tanja at 2013-10-27 13:06:30 Running from C:\Users\Tanja\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x32) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) ALDI TALK Verbindungsassistent (x32 Version: ) avast! Ad Blocker (x32 Version: 1.0.0.0) avast! Free Antivirus (x32 Version: 8.0.1500.0) Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition Feedback Tool (x32 Version: 1.2.0) Free YouTube to MP3 Converter version 3.12.12.827 (x32 Version: 3.12.12.827) GeForce Experience NvStream Client Components (Version: 0.1.87) GNU Backgammon (Version 1_02_000, 20130728) (x32) HitmanPro 3.7 (Version: 3.7.8.207) HUAWEI DataCard Driver 3.17.06.00 (x32 Version: 3.17.06.00) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Access MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft DCF MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Excel MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Groove MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft InfoPath MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Lync MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office 32-bit Components 2013 (Version: 15.0.4420.1017) Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4420.1017) Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office OSM UX MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017) Microsoft Office Proofing (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017) Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4420.1017) Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft OneNote MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Outlook MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft PowerPoint MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Publisher MUI (German) 2013 (Version: 15.0.4420.1017) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Word MUI (German) 2013 (Version: 15.0.4420.1017) NVIDIA 3D Vision Controller-Treiber 331.58 (Version: 331.58) NVIDIA 3D Vision Treiber 331.58 (Version: 331.58) NVIDIA Display Control Panel (Version: 1.10) NVIDIA GeForce Experience 1.6.1.2 (Version: 1.6.1.2) NVIDIA Grafiktreiber 331.58 (Version: 331.58) NVIDIA Install Application (Version: 2.1002.133.902) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3158) NVIDIA Systemsteuerung 331.58 (Version: 331.58) NVIDIA Update 8.3.23 (Version: 8.3.23) NVIDIA Update Components (Version: 8.3.23) NVIDIA Virtual Audio 1.2.5 (Version: 1.2.5) Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017) Paint.NET v3.5.11 (Version: 3.61.0) PDF24 Creator 5.7.0 (x32) PDF-Viewer (Version: 2.5.211.0) Realtek Ethernet Controller Driver (x32 Version: 7.54.309.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6680) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127) SHIELD Streaming (Version: 1.05.42) TeamViewer 8 (x32 Version: 8.0.20202) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Update for Microsoft Excel 2013 (KB2760339) 64-Bit Edition Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition Update for Microsoft Office 2013 (KB2737954) 64-Bit Edition Update for Microsoft Office 2013 (KB2752025) 64-Bit Edition Update for Microsoft Office 2013 (KB2752094) 64-Bit Edition Update for Microsoft Office 2013 (KB2752101) 64-Bit Edition Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition Update for Microsoft Office 2013 (KB2760538) 64-Bit Edition Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition Update for Microsoft Office 2013 (KB2767860) 64-Bit Edition Update for Microsoft Office 2013 (KB2768016) 64-Bit Edition Update for Microsoft Office 2013 (KB2817320) 64-Bit Edition Update for Microsoft Office 2013 (KB2817482) 64-Bit Edition Update for Microsoft PowerPoint 2013 (KB2726947) 64-Bit Edition Update for Microsoft PowerPoint 2013 (KB2810006) 64-Bit Edition Update for Microsoft Word 2013 (KB2810086) 64-Bit Edition WinPatrol (Version: 28.6.2013.0) WOT for Internet Explorer (Version: 12.8.2.0) ==================== Restore Points ========================= 16-10-2013 10:44:42 avast! antivirus system restore point 21-10-2013 06:11:30 avast! antivirus system restore point 22-10-2013 00:00:27 Windows Update 22-10-2013 06:43:22 Windows Update 24-10-2013 15:49:17 Installed SlimDrivers 25-10-2013 23:04:09 Windows Update 26-10-2013 09:20:22 SiSoftware Sandra Lite ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-09-03 21:08 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {401F0CC5-5E68-428B-A3CB-DFDBB95CE7E0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {6E91DED9-2C8E-4360-A758-11544F13BFE3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {700448E5-6348-429A-8E70-F3DFA1DF1F97} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {768A7A67-5584-44B3-A374-26B7F810B44D} - System32\Tasks\{6A200771-FD41-4EA9-97C8-37561BCB9A99} => C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-10-14] (AVAST Software) Task: {78BC1CE8-7B16-40BB-B9DB-B06BF055C393} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation) Task: {7ADD72F1-9A7A-42EB-BB75-4CEEC263A3A9} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Tanja-PC-Tanja Tanja-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation) Task: {CCD199CC-E775-4702-88BA-B80703F668E0} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {DB81FB7D-4F95-4B26-936C-4B6801094DB8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation) Task: {E26908DF-ADAE-4898-BEF7-79A04940B4FB} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-10-14] (AVAST Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-10-26 21:40 - 2013-10-26 18:45 - 02105856 _____ () C:\Program Files\AVAST Software\Avast\defs\13102602\algo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (10/27/2013 06:02:17 AM) (Source: Office 2013 Licensing Service) (User: ) Description: Subscription licensing service failed: -1073418154 Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/26/2013 09:30:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (10/26/2013 10:21:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "UPnP-Gerätehost" ist vom Dienst "SSDP-Suche" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (10/26/2013 10:21:22 PM) (Source: DCOM) (User: ) Description: 1068upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56} Error: (10/26/2013 08:25:02 PM) (Source: Service Control Manager) (User: ) Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/26/2013 10:27:35 AM) (Source: Service Control Manager) (User: ) Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/25/2013 07:32:44 AM) (Source: Service Control Manager) (User: ) Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/24/2013 07:26:20 PM) (Source: Service Control Manager) (User: ) Description: Dienst "NVIDIA Stereoscopic 3D Driver Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/23/2013 10:20:29 PM) (Source: Service Control Manager) (User: ) Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Netzwerkspeicher-Schnittstellendienst" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: %%1056 Error: (10/23/2013 10:18:29 PM) (Source: Service Control Manager) (User: ) Description: Dienst "Diagnosediensthost" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/23/2013 10:18:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SSTP-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Error: (10/23/2013 10:18:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerkspeicher-Schnittstellendienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts. Microsoft Office Sessions: ========================= Error: (10/27/2013 06:02:17 AM) (Source: Office 2013 Licensing Service)(User: ) Description: Subscription licensing service failed: -1073418154 Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL Error: (10/26/2013 09:30:43 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files (x86)\ALDITALKVerbindungsassistent\MFC80U.DLL ==================== Memory info =========================== Percentage of memory in use: 33% Total physical RAM: 4023.11 MB Available physical RAM: 2690.11 MB Total Pagefile: 8044.4 MB Available Pagefile: 6667.6 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:453.45 GB) (Free:407.63 GB) NTFS Drive d: () (Fixed) (Total:453.96 GB) (Free:452.51 GB) NTFS Drive f: (MEDION) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 18EB46D9) Partition 1: (Not Active) - (Size=24 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=453 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=454 GB) - (Type=07 NTFS) ==================== End Of Log ============================
__________________ lg, tanysha Ich bin so wie ich bin. Die einen kennen mich, die anderen können mich. |
Themen zu Infizierte Webseite: trickzone.net/nicht-klicken-das-original.html |
anklicken, applaus, besonders, euren, grüner, guten, infizierte, installier, klicke, klicken, lustig, melde, meldet, morgen, nachricht, pferd, schöne, schönen, seite, troja, trojanisches, trojanisches pferd, verseuchte, vertrauenswürdig, webseite |