|
Plagegeister aller Art und deren Bekämpfung: Avast! hat mehrere Viren gefundenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.01.2014, 00:26 | #16 |
| Avast! hat mehrere Viren gefunden Hallo, hier ist der FRST Scan FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014 Ran by P83x (administrator) on ALPHA on 05-01-2014 00:23:44 Running from C:\Users\P83x\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () C:\Windows\SysWOW64\HsMgr.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\system\HsMgr64.exe (Valve Corporation) G:\Programme\Steam\Steam.exe (CMedia) C:\Program Files\ASUS Xonar DG Audio\Customapp\AsusAudioCenter.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Flux Software LLC) C:\Users\P83x\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\SysWOW64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-15] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - G:\Programme\Steam\Steam.exe [1823656 2013-12-11] (Valve Corporation) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-03-03] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [F.lux] - C:\Users\P83x\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-10-23] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll c:\progra~2\gs_ena~1\browsafe.dll [4370944 2013-12-28] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x55011B838CEFCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: MiniMuumPrice - {0C14A4D5-FF69-8F73-AD91-37DFED857F86} - C:\ProgramData\MiniMuumPrice\3BiyHxUo.x64.dll () BHO: RanDomPrIcee - {1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} - C:\ProgramData\RanDomPrIcee\6.x64.dll () BHO-x32: MiniMuumPrice - {0C14A4D5-FF69-8F73-AD91-37DFED857F86} - C:\ProgramData\MiniMuumPrice\3BiyHxUo.dll () BHO-x32: RanDomPrIcee - {1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} - C:\ProgramData\RanDomPrIcee\6.dll () Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.de/" CHR Extension: (Magic Actions for YouTube\u2122) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\6.7.1_0 CHR Extension: (Freemake Video Downloader) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0 CHR Extension: (Adblock Plus) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (Freemake Youtube Download Button) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: () - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\haocganpkafanhkfldbbmhcpaelmkejg\3_0 CHR Extension: (LastPass) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\3.0.22_0 CHR Extension: (Google Wallet) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 066f0b2c; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation) R2 066f0b2c; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-15] (AVAST Software) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-01-10] (Ellora Assets Corp.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [149032 2012-08-16] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [745368 2012-11-26] (Tunngle.net GmbH) ==================== Drivers (Whitelisted) ==================== S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-03-06] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-03-06] (LG Electronics Inc.) S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2012-03-06] (LG Electronics Inc.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-12-15] (AVAST Software) R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-12-15] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-12-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-12-15] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-12-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-15] () R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2734080 2013-04-11] (C-Media Inc) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-08-16] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-08-16] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-08-16] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [31232 2013-06-07] (Razer Inc) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-01-04] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-05 00:21 - 2014-01-05 00:23 - 00013824 _____ C:\Users\P83x\Desktop\FRST.txt 2014-01-05 00:19 - 2014-01-05 00:20 - 01931368 _____ (Farbar) C:\Users\P83x\Desktop\FRST64.exe 2014-01-01 18:18 - 2014-01-01 18:18 - 00000000 _____ C:\autoexec.bat 2014-01-01 18:16 - 2014-01-01 18:38 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP 2014-01-01 18:16 - 2014-01-01 18:16 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-30 21:35 - 2014-01-01 18:16 - 00000000 ____D C:\ProgramData\RanDomPrIcee 2013-12-30 21:35 - 2014-01-01 18:15 - 00000000 ____D C:\ProgramData\MiniMuumPrice 2013-12-30 21:35 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\cljnaopmdlhkadappibkgihgnnagfcac 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Users\P83x\AppData\Local\Packages 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Program Files (x86)\GS_Enabler 2013-12-28 22:42 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\d08b7a74df8325dc 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\P83x\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$ 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-26 16:08 - 2013-12-26 16:08 - 00000000 ____D C:\Users\P83x\Documents\Square Enix 2013-12-21 16:31 - 2013-12-21 16:31 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard 2013-12-21 16:24 - 2014-01-04 03:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Battle.net 2013-12-21 16:24 - 2013-12-21 16:25 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Battle.net 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard Entertainment 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-12-21 16:22 - 2013-12-21 16:22 - 00000000 ____D C:\ProgramData\Battle.net 2013-12-21 13:38 - 2013-12-21 13:43 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-12-19 13:28 - 2013-12-19 13:28 - 00000000 ____D C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP 2013-12-15 17:09 - 2013-12-16 12:25 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Dwarfs 2013-12-15 17:08 - 2014-01-04 20:12 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-12-15 17:08 - 2013-12-15 17:08 - 00000000 ____D C:\Users\P83x\AppData\Roaming\AVAST Software 2013-12-11 13:29 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 13:29 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 13:29 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 13:29 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 13:29 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 13:29 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 13:29 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 13:29 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 13:29 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 13:29 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 13:29 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 13:29 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 13:29 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 13:29 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 13:29 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 13:29 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 13:29 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 13:29 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 13:29 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 13:29 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 13:29 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 13:29 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 13:29 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 13:29 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 13:29 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 13:29 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 13:29 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 13:29 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 13:29 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 13:29 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 13:29 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 13:29 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 13:29 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 13:29 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 13:29 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 13:08 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 13:08 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 13:08 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 13:08 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 13:08 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 13:08 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 13:08 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 13:08 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 13:08 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 13:08 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 13:08 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 13:08 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 13:08 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 13:08 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 13:08 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 13:08 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 13:08 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 13:08 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 13:08 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-10 21:54 - 2013-12-10 22:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe ==================== One Month Modified Files and Folders ======= 2014-01-05 00:23 - 2014-01-05 00:21 - 00013824 _____ C:\Users\P83x\Desktop\FRST.txt 2014-01-05 00:22 - 2013-01-11 02:57 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Skype 2014-01-05 00:20 - 2014-01-05 00:19 - 01931368 _____ (Farbar) C:\Users\P83x\Desktop\FRST64.exe 2014-01-04 23:54 - 2013-01-11 02:15 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-04 23:48 - 2013-01-18 15:10 - 00000000 ____D C:\Users\P83x\AppData\Roaming\TS3Client 2014-01-04 23:25 - 2013-11-26 20:14 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-04 23:24 - 2013-01-11 00:12 - 01504601 _____ C:\Windows\WindowsUpdate.log 2014-01-04 20:43 - 2013-03-03 21:26 - 00000000 ____D C:\Users\P83x\AppData\Local\PMB Files 2014-01-04 20:18 - 2013-01-11 00:17 - 01688460 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-04 20:18 - 2009-07-14 18:58 - 00728118 _____ C:\Windows\system32\perfh007.dat 2014-01-04 20:18 - 2009-07-14 18:58 - 00160448 _____ C:\Windows\system32\perfc007.dat 2014-01-04 20:18 - 2009-07-14 05:45 - 00020480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-04 20:18 - 2009-07-14 05:45 - 00020480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-04 20:13 - 2013-11-26 20:14 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-04 20:13 - 2013-01-11 09:39 - 00002896 _____ C:\Windows\System32\Tasks\AutoKMS 2014-01-04 20:13 - 2013-01-11 09:39 - 00000266 _____ C:\Windows\Tasks\AutoKMS.job 2014-01-04 20:13 - 2013-01-11 09:02 - 00000000 ____D C:\Users\P83x\AppData\Local\LogMeIn Hamachi 2014-01-04 20:12 - 2013-12-15 17:08 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-01-04 20:12 - 2013-07-18 12:30 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-04 20:12 - 2013-01-11 01:25 - 00361606 _____ C:\Windows\PFRO.log 2014-01-04 20:12 - 2013-01-11 01:24 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2014-01-04 20:12 - 2013-01-11 01:20 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-01-04 20:12 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-04 20:12 - 2009-07-14 05:51 - 00152496 _____ C:\Windows\setupact.log 2014-01-04 19:08 - 2013-01-11 09:50 - 00000000 ____D C:\Users\P83x\AppData\Roaming\foobar2000 2014-01-04 15:17 - 2013-03-03 21:26 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-04 13:53 - 2013-01-11 01:20 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-01-04 03:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Battle.net 2014-01-01 18:44 - 2013-01-11 02:30 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-01 18:38 - 2014-01-01 18:16 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP 2014-01-01 18:31 - 2013-01-11 09:20 - 00000000 ____D C:\Users\P83x\AppData\Local\CrashDumps 2014-01-01 18:20 - 2013-07-04 19:44 - 00016146 _____ C:\Users\P83x\Elo Boosting.xlsx 2014-01-01 18:20 - 2013-01-11 00:13 - 00000000 ____D C:\Users\P83x 2014-01-01 18:18 - 2014-01-01 18:18 - 00000000 _____ C:\autoexec.bat 2014-01-01 18:16 - 2014-01-01 18:16 - 00000000 ____D C:\Program Files\Enigma Software Group 2014-01-01 18:16 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\RanDomPrIcee 2014-01-01 18:15 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\MiniMuumPrice 2013-12-30 21:35 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\cljnaopmdlhkadappibkgihgnnagfcac 2013-12-30 21:35 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\d08b7a74df8325dc 2013-12-30 14:33 - 2013-01-11 02:57 - 00000000 ____D C:\Program Files (x86)\SciLor's Grooveshark 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Users\P83x\AppData\Local\Packages 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Program Files (x86)\GS_Enabler 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\P83x\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$ 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-28 22:42 - 2013-11-26 20:14 - 00000000 ____D C:\Users\P83x\AppData\Local\Google 2013-12-26 17:57 - 2013-01-11 10:24 - 00760957 _____ C:\Windows\DirectX.log 2013-12-26 16:08 - 2013-12-26 16:08 - 00000000 ____D C:\Users\P83x\Documents\Square Enix 2013-12-24 15:40 - 2013-05-31 20:06 - 00000000 ____D C:\Users\P83x\Bilder 2013-12-21 16:31 - 2013-12-21 16:31 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard 2013-12-21 16:25 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Battle.net 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard Entertainment 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-12-21 16:22 - 2013-12-21 16:22 - 00000000 ____D C:\ProgramData\Battle.net 2013-12-21 13:43 - 2013-12-21 13:38 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-12-19 13:28 - 2013-12-19 13:28 - 00000000 ____D C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP 2013-12-16 12:25 - 2013-12-15 17:09 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Dwarfs 2013-12-15 17:08 - 2013-12-15 17:08 - 00000000 ____D C:\Users\P83x\AppData\Roaming\AVAST Software 2013-12-15 11:39 - 2013-07-30 08:54 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-15 11:39 - 2013-07-30 08:54 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-15 11:39 - 2013-01-11 02:30 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-12-15 11:39 - 2013-01-11 02:30 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-12-15 11:38 - 2013-01-11 02:30 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-15 11:38 - 2013-01-11 02:30 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-12-15 03:01 - 2013-07-26 02:00 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 03:00 - 2009-10-14 06:12 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 06:34 - 2013-01-11 02:28 - 00000000 ____D C:\Users\P83x\AppData\Roaming\vlc 2013-12-13 05:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-12 06:54 - 2013-02-14 18:11 - 00000000 ____D C:\Users\P83x\Schule 2013-12-11 22:03 - 2009-07-14 19:18 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-12-11 17:31 - 2009-07-14 05:45 - 00407464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 13:29 - 2013-01-11 09:34 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-10 22:54 - 2013-12-10 21:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 22:54 - 2013-01-11 02:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 22:54 - 2013-01-11 02:15 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 01:16 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2013-12-07 00:45 - 2013-12-05 20:12 - 00000000 ____D C:\Users\P83x\Documents\JoWooD 2013-12-06 21:00 - 2013-11-16 00:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-06 21:00 - 2013-01-11 02:09 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Mozilla Some content of TEMP: ==================== C:\Users\P83x\AppData\Local\Temp\CRCCheck.exe C:\Users\P83x\AppData\Local\Temp\FLVPlayerSetup.exe C:\Users\P83x\AppData\Local\Temp\SHSetup.exe C:\Users\P83x\AppData\Local\Temp\Tsu53C12B79.dll C:\Users\P83x\AppData\Local\Temp\UpdateCheckerSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 14:21 ==================== End Of Log ============================ Aber fehlt da nicht auch der Addition.txt? Ich habe wie beschrieben nichts geändert, auf Scan gedrückt und ausgespuckt hat er mir nur FRST textdatei. |
05.01.2014, 16:39 | #17 |
/// the machine /// TB-Ausbilder | Avast! hat mehrere Viren gefunden Downloade Dir bitte Malwarebytes Anti-Malware
__________________
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
05.01.2014, 19:08 | #18 |
| Avast! hat mehrere Viren gefunden Malwarebytes
__________________Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.05.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 P83x :: ALPHA [Administrator] 05.01.2014 18:41:21 mbam-log-2014-01-05 (18-41-21).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 262833 Laufzeit: 1 Minute(n), 56 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 11 HKCR\CLSID\{0C14A4D5-FF69-8F73-AD91-37DFED857F86} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C14A4D5-FF69-8F73-AD91-37DFED857F86} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0C14A4D5-FF69-8F73-AD91-37DFED857F86} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0C14A4D5-FF69-8F73-AD91-37DFED857F86} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0C14A4D5-FF69-8F73-AD91-37DFED857F86} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252} (PUP.Optional.GreatSaver.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 6 C:\ProgramData\MiniMuumPrice\3BiyHxUo.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\RanDomPrIcee\6.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\MiniMuumPrice\3BiyHxUo.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\RanDomPrIcee\6.x64.dll (PUP.Optional.MultiPlug.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\P83x\AppData\Local\Temp\FLVPlayerSetup.exe (PUP.Optional.Somoto.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\P83x\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 05/01/2014 um 18:49:06 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : P83x - ALPHA # Gestartet von : C:\Users\P83x\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [785 octets] - [05/01/2014 18:48:21] AdwCleaner[S0].txt - [707 octets] - [05/01/2014 18:49:06] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [766 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.9 (01.01.2014:1) OS: Windows 7 Ultimate x64 Ran by P83x on 05.01.2014 at 18:51:27,18 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.01.2014 at 18:57:47,77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014 Ran by P83x (administrator) on ALPHA on 05-01-2014 19:05:46 Running from C:\Users\P83x\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\HsMgr.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Windows\system\HsMgr64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (CMedia) C:\Program Files\ASUS Xonar DG Audio\Customapp\AsusAudioCenter.exe (Valve Corporation) G:\Programme\Steam\Steam.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (Flux Software LLC) C:\Users\P83x\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.beta.2514\Agent.exe (Blizzard Entertainment) G:\Programme\Battle.net\Battle.net.4047\Battle.net.exe () G:\Programme\Hearthstone\Hearthstone.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\SysWOW64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-15] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - G:\Programme\Steam\Steam.exe [1823656 2013-12-11] (Valve Corporation) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-03-03] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [F.lux] - C:\Users\P83x\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-10-23] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll c:\progra~2\gs_ena~1\browsafe.dll [4370944 2013-12-28] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x55011B838CEFCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: MiniMuumPrice - {0C14A4D5-FF69-8F73-AD91-37DFED857F86} - C:\ProgramData\MiniMuumPrice\3BiyHxUo.x64.dll No File BHO: RanDomPrIcee - {1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} - C:\ProgramData\RanDomPrIcee\6.x64.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.de/" CHR Extension: (Magic Actions for YouTube\u2122) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\6.7.1_0 CHR Extension: (Freemake Video Downloader) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0 CHR Extension: (Adblock Plus) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (Freemake Youtube Download Button) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: () - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\haocganpkafanhkfldbbmhcpaelmkejg\3_0 CHR Extension: (LastPass) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\3.0.22_0 CHR Extension: (Google Wallet) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S2 066f0b2c; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation) S2 066f0b2c; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-15] (AVAST Software) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-01-10] (Ellora Assets Corp.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [149032 2012-08-16] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [745368 2012-11-26] (Tunngle.net GmbH) ==================== Drivers (Whitelisted) ==================== S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-03-06] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-03-06] (LG Electronics Inc.) S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2012-03-06] (LG Electronics Inc.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-12-15] (AVAST Software) R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-12-15] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-12-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-12-15] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-12-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-15] () R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2734080 2013-04-11] (C-Media Inc) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-08-16] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-08-16] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-08-16] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [31232 2013-06-07] (Razer Inc) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-01-05] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-05 18:57 - 2014-01-05 18:57 - 00000620 _____ C:\Users\P83x\Desktop\JRT.txt 2014-01-05 18:50 - 2014-01-05 18:51 - 01036305 _____ (Thisisu) C:\Users\P83x\Desktop\JRT.exe 2014-01-05 18:50 - 2014-01-05 18:50 - 00000845 _____ C:\Users\P83x\Desktop\AdwCleaner[S0].txt 2014-01-05 18:48 - 2014-01-05 18:49 - 00000000 ____D C:\AdwCleaner 2014-01-05 18:47 - 2014-01-05 18:47 - 01233962 _____ C:\Users\P83x\Desktop\adwcleaner.exe 2014-01-05 18:39 - 2014-01-05 18:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\P83x\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-05 18:39 - 2014-01-05 18:39 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-05 18:39 - 2014-01-05 18:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-05 18:39 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-05 00:21 - 2014-01-05 19:05 - 00014039 _____ C:\Users\P83x\Desktop\FRST.txt 2014-01-05 00:19 - 2014-01-05 00:20 - 01931368 _____ (Farbar) C:\Users\P83x\Desktop\FRST64.exe 2014-01-01 18:18 - 2014-01-01 18:18 - 00000000 _____ C:\autoexec.bat 2014-01-01 18:16 - 2014-01-01 18:38 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP 2014-01-01 18:16 - 2014-01-01 18:16 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-30 21:35 - 2014-01-05 18:45 - 00000000 ____D C:\ProgramData\RanDomPrIcee 2013-12-30 21:35 - 2014-01-05 18:45 - 00000000 ____D C:\ProgramData\MiniMuumPrice 2013-12-30 21:35 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\cljnaopmdlhkadappibkgihgnnagfcac 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Users\P83x\AppData\Local\Packages 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Program Files (x86)\GS_Enabler 2013-12-28 22:42 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\d08b7a74df8325dc 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\P83x\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$ 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-26 16:08 - 2013-12-26 16:08 - 00000000 ____D C:\Users\P83x\Documents\Square Enix 2013-12-21 16:31 - 2013-12-21 16:31 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard 2013-12-21 16:24 - 2014-01-05 19:02 - 00000000 ____D C:\Users\P83x\AppData\Local\Battle.net 2013-12-21 16:24 - 2013-12-21 16:25 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Battle.net 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard Entertainment 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-12-21 16:22 - 2013-12-21 16:22 - 00000000 ____D C:\ProgramData\Battle.net 2013-12-21 13:38 - 2013-12-21 13:43 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-12-19 13:28 - 2013-12-19 13:28 - 00000000 ____D C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP 2013-12-15 17:09 - 2013-12-16 12:25 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Dwarfs 2013-12-15 17:08 - 2014-01-05 18:49 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-12-15 17:08 - 2013-12-15 17:08 - 00000000 ____D C:\Users\P83x\AppData\Roaming\AVAST Software 2013-12-11 13:29 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 13:29 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 13:29 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 13:29 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 13:29 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 13:29 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 13:29 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 13:29 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 13:29 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 13:29 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 13:29 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 13:29 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 13:29 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 13:29 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 13:29 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 13:29 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 13:29 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 13:29 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 13:29 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 13:29 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 13:29 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 13:29 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 13:29 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 13:29 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 13:29 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 13:29 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 13:29 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 13:29 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 13:29 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 13:29 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 13:29 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 13:29 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 13:29 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 13:29 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 13:29 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 13:08 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 13:08 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 13:08 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 13:08 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 13:08 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 13:08 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 13:08 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 13:08 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 13:08 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 13:08 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 13:08 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 13:08 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 13:08 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 13:08 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 13:08 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 13:08 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 13:08 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 13:08 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 13:08 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-10 21:54 - 2013-12-10 22:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe ==================== One Month Modified Files and Folders ======= 2014-01-05 19:05 - 2014-01-05 00:21 - 00014039 _____ C:\Users\P83x\Desktop\FRST.txt 2014-01-05 19:05 - 2013-03-03 21:26 - 00000000 ____D C:\Users\P83x\AppData\Local\PMB Files 2014-01-05 19:02 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Battle.net 2014-01-05 18:57 - 2014-01-05 18:57 - 00000620 _____ C:\Users\P83x\Desktop\JRT.txt 2014-01-05 18:55 - 2013-01-11 00:17 - 01688460 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-05 18:55 - 2009-07-14 18:58 - 00728118 _____ C:\Windows\system32\perfh007.dat 2014-01-05 18:55 - 2009-07-14 18:58 - 00160448 _____ C:\Windows\system32\perfc007.dat 2014-01-05 18:55 - 2009-07-14 05:45 - 00020480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-05 18:55 - 2009-07-14 05:45 - 00020480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-05 18:54 - 2013-01-11 02:15 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-05 18:51 - 2014-01-05 18:50 - 01036305 _____ (Thisisu) C:\Users\P83x\Desktop\JRT.exe 2014-01-05 18:50 - 2014-01-05 18:50 - 00000845 _____ C:\Users\P83x\Desktop\AdwCleaner[S0].txt 2014-01-05 18:50 - 2013-01-11 09:39 - 00002896 _____ C:\Windows\System32\Tasks\AutoKMS 2014-01-05 18:50 - 2013-01-11 09:39 - 00000266 _____ C:\Windows\Tasks\AutoKMS.job 2014-01-05 18:50 - 2013-01-11 09:02 - 00000000 ____D C:\Users\P83x\AppData\Local\LogMeIn Hamachi 2014-01-05 18:50 - 2013-01-11 02:57 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Skype 2014-01-05 18:49 - 2014-01-05 18:48 - 00000000 ____D C:\AdwCleaner 2014-01-05 18:49 - 2013-12-15 17:08 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-01-05 18:49 - 2013-11-26 20:14 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-05 18:49 - 2013-07-18 12:30 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-05 18:49 - 2013-01-11 01:25 - 00363956 _____ C:\Windows\PFRO.log 2014-01-05 18:49 - 2013-01-11 01:24 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2014-01-05 18:49 - 2013-01-11 01:20 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-01-05 18:49 - 2013-01-11 00:12 - 01567051 _____ C:\Windows\WindowsUpdate.log 2014-01-05 18:49 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-05 18:49 - 2009-07-14 05:51 - 00153000 _____ C:\Windows\setupact.log 2014-01-05 18:47 - 2014-01-05 18:47 - 01233962 _____ C:\Users\P83x\Desktop\adwcleaner.exe 2014-01-05 18:45 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\RanDomPrIcee 2014-01-05 18:45 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\MiniMuumPrice 2014-01-05 18:42 - 2013-03-03 21:26 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-05 18:39 - 2014-01-05 18:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\P83x\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-05 18:39 - 2014-01-05 18:39 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-05 18:39 - 2014-01-05 18:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-05 18:25 - 2013-11-26 20:14 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-05 13:53 - 2013-01-11 01:20 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-01-05 13:17 - 2013-01-11 02:30 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-05 00:20 - 2014-01-05 00:19 - 01931368 _____ (Farbar) C:\Users\P83x\Desktop\FRST64.exe 2014-01-04 23:48 - 2013-01-18 15:10 - 00000000 ____D C:\Users\P83x\AppData\Roaming\TS3Client 2014-01-04 19:08 - 2013-01-11 09:50 - 00000000 ____D C:\Users\P83x\AppData\Roaming\foobar2000 2014-01-01 18:38 - 2014-01-01 18:16 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP 2014-01-01 18:31 - 2013-01-11 09:20 - 00000000 ____D C:\Users\P83x\AppData\Local\CrashDumps 2014-01-01 18:20 - 2013-07-04 19:44 - 00016146 _____ C:\Users\P83x\Elo Boosting.xlsx 2014-01-01 18:20 - 2013-01-11 00:13 - 00000000 ____D C:\Users\P83x 2014-01-01 18:18 - 2014-01-01 18:18 - 00000000 _____ C:\autoexec.bat 2014-01-01 18:16 - 2014-01-01 18:16 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-30 21:35 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\cljnaopmdlhkadappibkgihgnnagfcac 2013-12-30 21:35 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\d08b7a74df8325dc 2013-12-30 14:33 - 2013-01-11 02:57 - 00000000 ____D C:\Program Files (x86)\SciLor's Grooveshark 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Users\P83x\AppData\Local\Packages 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Program Files (x86)\GS_Enabler 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\P83x\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$ 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-28 22:42 - 2013-11-26 20:14 - 00000000 ____D C:\Users\P83x\AppData\Local\Google 2013-12-26 17:57 - 2013-01-11 10:24 - 00760957 _____ C:\Windows\DirectX.log 2013-12-26 16:08 - 2013-12-26 16:08 - 00000000 ____D C:\Users\P83x\Documents\Square Enix 2013-12-24 15:40 - 2013-05-31 20:06 - 00000000 ____D C:\Users\P83x\Bilder 2013-12-21 16:31 - 2013-12-21 16:31 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard 2013-12-21 16:25 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Battle.net 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard Entertainment 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-12-21 16:22 - 2013-12-21 16:22 - 00000000 ____D C:\ProgramData\Battle.net 2013-12-21 13:43 - 2013-12-21 13:38 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-12-19 13:28 - 2013-12-19 13:28 - 00000000 ____D C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP 2013-12-16 12:25 - 2013-12-15 17:09 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Dwarfs 2013-12-15 17:08 - 2013-12-15 17:08 - 00000000 ____D C:\Users\P83x\AppData\Roaming\AVAST Software 2013-12-15 11:39 - 2013-07-30 08:54 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-15 11:39 - 2013-07-30 08:54 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-15 11:39 - 2013-01-11 02:30 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-12-15 11:39 - 2013-01-11 02:30 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-12-15 11:38 - 2013-01-11 02:30 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-15 11:38 - 2013-01-11 02:30 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-12-15 03:01 - 2013-07-26 02:00 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 03:00 - 2009-10-14 06:12 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 06:34 - 2013-01-11 02:28 - 00000000 ____D C:\Users\P83x\AppData\Roaming\vlc 2013-12-13 05:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-12 06:54 - 2013-02-14 18:11 - 00000000 ____D C:\Users\P83x\Schule 2013-12-11 22:03 - 2009-07-14 19:18 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-12-11 17:31 - 2009-07-14 05:45 - 00407464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 13:29 - 2013-01-11 09:34 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-10 22:54 - 2013-12-10 21:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 22:54 - 2013-01-11 02:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 22:54 - 2013-01-11 02:15 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 01:16 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini 2013-12-07 00:45 - 2013-12-05 20:12 - 00000000 ____D C:\Users\P83x\Documents\JoWooD 2013-12-06 21:00 - 2013-11-16 00:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-06 21:00 - 2013-01-11 02:09 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Mozilla Some content of TEMP: ==================== C:\Users\P83x\AppData\Local\Temp\CRCCheck.exe C:\Users\P83x\AppData\Local\Temp\Quarantine.exe C:\Users\P83x\AppData\Local\Temp\SHSetup.exe C:\Users\P83x\AppData\Local\Temp\Tsu53C12B79.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 14:21 ==================== End Of Log ============================ |
06.01.2014, 16:24 | #19 |
/// the machine /// TB-Ausbilder | Avast! hat mehrere Viren gefundenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.01.2014, 02:44 | #20 |
| Avast! hat mehrere Viren gefundenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=06723d80c6fe94478f460591ac191617 # engine=16553 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-08 12:16:48 # local_time=2014-01-08 01:16:48 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 83 2020127 165850080 0 0 # compatibility_mode=5893 16776573 100 94 39981 140770058 0 0 # scanned=466845 # found=16 # cleaned=0 # scan_time=8524 sh=0DAFA42039405F8D49A6790180194076BD57C833 ft=1 fh=c71c001147036410 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-237219568-2535265190-807073775-1000\$R8DMB2J\Quarantine\C\Program Files (x86)\surf anD kkeeep\cYE3W5Rn.dll.vir" sh=61CB4B5228E6253863391EF3346C2F9920DBC554 ft=1 fh=c71c00112b13579c vn="a variant of Win64/Adware.MultiPlug.A application" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-237219568-2535265190-807073775-1000\$R8DMB2J\Quarantine\C\Program Files (x86)\surf anD kkeeep\cYE3W5Rn.x64.dll.vir" sh=0DAFA42039405F8D49A6790180194076BD57C833 ft=1 fh=c71c001147036410 vn="a variant of Win32/AdWare.MultiPlug.N application" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-237219568-2535265190-807073775-1000\$R8DMB2J\Quarantine\C\Program Files (x86)\YoutubeAdblocker\uf_UFGlvR.dll.vir" sh=61CB4B5228E6253863391EF3346C2F9920DBC554 ft=1 fh=c71c00112b13579c vn="a variant of Win64/Adware.MultiPlug.A application" ac=I fn="C:\$RECYCLE.BIN\S-1-5-21-237219568-2535265190-807073775-1000\$R8DMB2J\Quarantine\C\Program Files (x86)\YoutubeAdblocker\uf_UFGlvR.x64.dll.vir" sh=4D8F98F1C52783651DE3DDEB5CD18FA018F4645D ft=1 fh=8f65465e4e7b4740 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNFHIBAP\F2nxyFXkI[1].exe" sh=334B62B0D7AFE9F79E8E72110E9B447AE3EEC8AB ft=1 fh=0f866f85f0c217bc vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNFHIBAP\glOySWk[1].exe" sh=52A73A034C1E40D136E2879745E9757055415CB0 ft=1 fh=1ecb06aceb07c954 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNFHIBAP\Jo4JYbAq[1].exe" sh=E6009C0AC554C797C5DECB727E176A545D019590 ft=1 fh=2597b51039844928 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF3GPVO3\f_CXDI8S[1].exe" sh=BF468235C45EE939C6F677F7EBE5B8E7739C709A ft=1 fh=a941014a54280aa3 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF3GPVO3\N6Gwtu99[1].exe" sh=52A73A034C1E40D136E2879745E9757055415CB0 ft=1 fh=1ecb06aceb07c954 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Temp\{E9137258-5340-4A81-A86A-1B6232F050AE}\Addons\browsecoupon_setup.exe" sh=BF468235C45EE939C6F677F7EBE5B8E7739C709A ft=1 fh=a941014a54280aa3 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Temp\{E9137258-5340-4A81-A86A-1B6232F050AE}\Addons\extIE_setup.exe" sh=334B62B0D7AFE9F79E8E72110E9B447AE3EEC8AB ft=1 fh=0f866f85f0c217bc vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Temp\{E9137258-5340-4A81-A86A-1B6232F050AE}\Addons\ext_setup.exe" sh=4D8F98F1C52783651DE3DDEB5CD18FA018F4645D ft=1 fh=8f65465e4e7b4740 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Temp\{E9137258-5340-4A81-A86A-1B6232F050AE}\Addons\ytab_setup.exe" sh=E6009C0AC554C797C5DECB727E176A545D019590 ft=1 fh=2597b51039844928 vn="a variant of Win32/AdWare.MultiPlug.M application" ac=I fn="C:\Users\P83x\AppData\Local\Temp\{E9137258-5340-4A81-A86A-1B6232F050AE}\Addons\ytbmk_setup.exe" sh=ACADF2B82AECDEDB4D590808EEB01D436999E91E ft=1 fh=f1e915411acfaf75 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="G:\Dateien\Assassin's Creedz II\SKIDROW\ubiorbitapi_r2.dll" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="G:\Dateien\Tom Clancy's Splinter Cell Conviction\sr-tcscc.iso" Code:
ATTFilter Results of screen317's Security Check version 0.99.78 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 10 Java version out of Date! Adobe Flash Player 11.9.900.170 Adobe Reader XI Google Chrome 31.0.1650.57 Google Chrome 31.0.1650.63 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014 Ran by P83x (administrator) on ALPHA on 08-01-2014 02:44:03 Running from C:\Users\P83x\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Windows\SysWOW64\HsMgr.exe () C:\Windows\system\HsMgr64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (CMedia) C:\Program Files\ASUS Xonar DG Audio\Customapp\AsusAudioCenter.exe (Valve Corporation) G:\Programme\Steam\Steam.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Flux Software LLC) C:\Users\P83x\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.beta.2514\Agent.exe (Blizzard Entertainment) G:\Programme\Battle.net\Battle.net.4047\Battle.net.exe () G:\Programme\Hearthstone\Hearthstone.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation) HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\SysWOW64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LifeCam] - C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-15] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - G:\Programme\Steam\Steam.exe [1823656 2013-12-11] (Valve Corporation) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-03-03] () HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [F.lux] - C:\Users\P83x\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-10-23] (NVIDIA Corporation) AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll c:\progra~2\gs_ena~1\browsafe.dll [4370944 2013-12-28] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x55011B838CEFCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: MiniMuumPrice - {0C14A4D5-FF69-8F73-AD91-37DFED857F86} - C:\ProgramData\MiniMuumPrice\3BiyHxUo.x64.dll No File BHO: RanDomPrIcee - {1B33F9E1-DFEE-9C90-7240-0DEBA4BE7E30} - C:\ProgramData\RanDomPrIcee\6.x64.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.de/" CHR Extension: (Magic Actions for YouTube\u2122) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif\6.7.1_0 CHR Extension: (Freemake Video Downloader) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0 CHR Extension: (Adblock Plus) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.2_0 CHR Extension: (Freemake Youtube Download Button) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0 CHR Extension: () - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\haocganpkafanhkfldbbmhcpaelmkejg\3_0 CHR Extension: (LastPass) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\3.0.22_0 CHR Extension: (Google Wallet) - C:\Users\P83x\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 066f0b2c; C:\Windows\system32\rundll32.exe [45568 2009-07-14] (Microsoft Corporation) R2 066f0b2c; C:\Windows\SysWow64\rundll32.exe [44544 2009-07-14] (Microsoft Corporation) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-15] (AVAST Software) R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-01-10] (Ellora Assets Corp.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-05] (Intel Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [149032 2012-08-16] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-21] (Intel Corporation) R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377104 2013-10-11] (LogMeIn, Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [745368 2012-11-26] (Tunngle.net GmbH) ==================== Drivers (Whitelisted) ==================== S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc) S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-03-06] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-03-06] (LG Electronics Inc.) S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93184 2012-03-06] (LG Electronics Inc.) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-12-15] (AVAST Software) R0 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-12-15] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-12-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-12-15] (AVAST Software) R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-12-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-15] () R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2734080 2013-04-11] (C-Media Inc) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-09-01] (Intel Corporation) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [20968 2012-08-16] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [19944 2012-08-16] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46016 2012-08-16] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [31232 2013-06-07] (Razer Inc) R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-01-07] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-08 02:43 - 2014-01-08 02:43 - 00000000 ____D C:\Users\P83x\Desktop\FRST-OlderVersion 2014-01-08 02:11 - 2014-01-08 02:11 - 00987410 _____ C:\Users\P83x\Desktop\SecurityCheck.exe 2014-01-07 22:47 - 2014-01-07 22:47 - 02347384 _____ (ESET) C:\Users\P83x\Desktop\esetsmartinstaller_enu.exe 2014-01-06 20:14 - 2014-01-06 20:17 - 00000000 ____D C:\Users\P83x\AppData\Local\Microsoft Games 2014-01-05 18:57 - 2014-01-05 18:57 - 00000620 _____ C:\Users\P83x\Desktop\JRT.txt 2014-01-05 18:50 - 2014-01-05 18:51 - 01036305 _____ (Thisisu) C:\Users\P83x\Desktop\JRT.exe 2014-01-05 18:50 - 2014-01-05 18:50 - 00000845 _____ C:\Users\P83x\Desktop\AdwCleaner[S0].txt 2014-01-05 18:48 - 2014-01-05 18:49 - 00000000 ____D C:\AdwCleaner 2014-01-05 18:47 - 2014-01-05 18:47 - 01233962 _____ C:\Users\P83x\Desktop\adwcleaner.exe 2014-01-05 18:39 - 2014-01-05 18:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\P83x\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-05 18:39 - 2014-01-05 18:39 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-05 18:39 - 2014-01-05 18:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-05 18:39 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-05 00:21 - 2014-01-08 02:44 - 00014325 _____ C:\Users\P83x\Desktop\FRST.txt 2014-01-05 00:19 - 2014-01-08 02:43 - 01931762 _____ (Farbar) C:\Users\P83x\Desktop\FRST64.exe 2014-01-01 18:18 - 2014-01-01 18:18 - 00000000 _____ C:\autoexec.bat 2014-01-01 18:16 - 2014-01-01 18:38 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP 2014-01-01 18:16 - 2014-01-01 18:16 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-30 21:35 - 2014-01-05 18:45 - 00000000 ____D C:\ProgramData\RanDomPrIcee 2013-12-30 21:35 - 2014-01-05 18:45 - 00000000 ____D C:\ProgramData\MiniMuumPrice 2013-12-30 21:35 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\cljnaopmdlhkadappibkgihgnnagfcac 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Users\P83x\AppData\Local\Packages 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Program Files (x86)\GS_Enabler 2013-12-28 22:42 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\d08b7a74df8325dc 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\P83x\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$ 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-26 16:08 - 2013-12-26 16:08 - 00000000 ____D C:\Users\P83x\Documents\Square Enix 2013-12-21 16:31 - 2013-12-21 16:31 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard 2013-12-21 16:24 - 2014-01-08 02:39 - 00000000 ____D C:\Users\P83x\AppData\Local\Battle.net 2013-12-21 16:24 - 2013-12-21 16:25 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Battle.net 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard Entertainment 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-12-21 16:22 - 2013-12-21 16:22 - 00000000 ____D C:\ProgramData\Battle.net 2013-12-21 13:38 - 2013-12-21 13:43 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-12-19 13:28 - 2013-12-19 13:28 - 00000000 ____D C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP 2013-12-15 17:09 - 2013-12-16 12:25 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Dwarfs 2013-12-15 17:08 - 2014-01-07 15:06 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-12-15 17:08 - 2013-12-15 17:08 - 00000000 ____D C:\Users\P83x\AppData\Roaming\AVAST Software 2013-12-11 13:29 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 13:29 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 13:29 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 13:29 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 13:29 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 13:29 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 13:29 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 13:29 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 13:29 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 13:29 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 13:29 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 13:29 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 13:29 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 13:29 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 13:29 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 13:29 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 13:29 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 13:29 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 13:29 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 13:29 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 13:29 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 13:29 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 13:29 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 13:29 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 13:29 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 13:29 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 13:29 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 13:29 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 13:29 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 13:29 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 13:29 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 13:29 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 13:29 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 13:29 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 13:29 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 13:08 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 13:08 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 13:08 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 13:08 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 13:08 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 13:08 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 13:08 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 13:08 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 13:08 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 13:08 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 13:08 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 13:08 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 13:08 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 13:08 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 13:08 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 13:08 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 13:08 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 13:08 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 13:08 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-10 21:54 - 2013-12-10 22:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe ==================== One Month Modified Files and Folders ======= 2014-01-08 02:44 - 2014-01-05 00:21 - 00014325 _____ C:\Users\P83x\Desktop\FRST.txt 2014-01-08 02:43 - 2014-01-08 02:43 - 00000000 ____D C:\Users\P83x\Desktop\FRST-OlderVersion 2014-01-08 02:43 - 2014-01-05 00:19 - 01931762 _____ (Farbar) C:\Users\P83x\Desktop\FRST64.exe 2014-01-08 02:43 - 2013-11-22 14:50 - 00000000 ____D C:\FRST 2014-01-08 02:39 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Battle.net 2014-01-08 02:26 - 2013-01-11 02:57 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Skype 2014-01-08 02:25 - 2013-11-26 20:14 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-08 02:11 - 2014-01-08 02:11 - 00987410 _____ C:\Users\P83x\Desktop\SecurityCheck.exe 2014-01-08 01:54 - 2013-01-11 02:15 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-08 01:27 - 2013-01-11 00:12 - 01706330 _____ C:\Windows\WindowsUpdate.log 2014-01-08 00:20 - 2013-03-03 21:26 - 00000000 ____D C:\Users\P83x\AppData\Local\PMB Files 2014-01-08 00:20 - 2013-03-03 21:26 - 00000000 ____D C:\ProgramData\PMB Files 2014-01-07 22:50 - 2013-01-11 00:17 - 01688460 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-07 22:50 - 2009-07-14 18:58 - 00728118 _____ C:\Windows\system32\perfh007.dat 2014-01-07 22:50 - 2009-07-14 18:58 - 00160448 _____ C:\Windows\system32\perfc007.dat 2014-01-07 22:47 - 2014-01-07 22:47 - 02347384 _____ (ESET) C:\Users\P83x\Desktop\esetsmartinstaller_enu.exe 2014-01-07 17:05 - 2009-07-14 05:45 - 00020480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-07 17:05 - 2009-07-14 05:45 - 00020480 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-07 15:06 - 2013-12-15 17:08 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-01-07 15:06 - 2013-11-26 20:14 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-07 15:06 - 2013-01-11 09:39 - 00002896 _____ C:\Windows\System32\Tasks\AutoKMS 2014-01-07 15:06 - 2013-01-11 09:39 - 00000266 _____ C:\Windows\Tasks\AutoKMS.job 2014-01-07 15:06 - 2013-01-11 09:02 - 00000000 ____D C:\Users\P83x\AppData\Local\LogMeIn Hamachi 2014-01-07 15:06 - 2013-01-11 01:24 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2014-01-07 15:06 - 2013-01-11 01:20 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-01-07 15:06 - 2009-07-14 05:51 - 00153504 _____ C:\Windows\setupact.log 2014-01-07 15:05 - 2013-07-18 12:30 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-07 15:05 - 2013-01-11 01:25 - 00364938 _____ C:\Windows\PFRO.log 2014-01-07 15:05 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-07 01:29 - 2013-01-11 09:50 - 00000000 ____D C:\Users\P83x\AppData\Roaming\foobar2000 2014-01-06 20:17 - 2014-01-06 20:14 - 00000000 ____D C:\Users\P83x\AppData\Local\Microsoft Games 2014-01-06 13:53 - 2013-01-11 01:20 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-01-06 10:42 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2014-01-05 20:41 - 2013-01-18 15:10 - 00000000 ____D C:\Users\P83x\AppData\Roaming\TS3Client 2014-01-05 20:36 - 2013-01-11 09:20 - 00000000 ____D C:\Users\P83x\AppData\Local\CrashDumps 2014-01-05 18:57 - 2014-01-05 18:57 - 00000620 _____ C:\Users\P83x\Desktop\JRT.txt 2014-01-05 18:51 - 2014-01-05 18:50 - 01036305 _____ (Thisisu) C:\Users\P83x\Desktop\JRT.exe 2014-01-05 18:50 - 2014-01-05 18:50 - 00000845 _____ C:\Users\P83x\Desktop\AdwCleaner[S0].txt 2014-01-05 18:49 - 2014-01-05 18:48 - 00000000 ____D C:\AdwCleaner 2014-01-05 18:47 - 2014-01-05 18:47 - 01233962 _____ C:\Users\P83x\Desktop\adwcleaner.exe 2014-01-05 18:45 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\RanDomPrIcee 2014-01-05 18:45 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\MiniMuumPrice 2014-01-05 18:39 - 2014-01-05 18:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\P83x\Desktop\mbam-setup-1.75.0.1300.exe 2014-01-05 18:39 - 2014-01-05 18:39 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-05 18:39 - 2014-01-05 18:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-05 13:17 - 2013-01-11 02:30 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2014-01-01 18:38 - 2014-01-01 18:16 - 00000000 ____D C:\Windows\72AAF4551E54475BB0AB5413C78D0E63.TMP 2014-01-01 18:20 - 2013-07-04 19:44 - 00016146 _____ C:\Users\P83x\Elo Boosting.xlsx 2014-01-01 18:20 - 2013-01-11 00:13 - 00000000 ____D C:\Users\P83x 2014-01-01 18:18 - 2014-01-01 18:18 - 00000000 _____ C:\autoexec.bat 2014-01-01 18:16 - 2014-01-01 18:16 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-12-30 21:35 - 2013-12-30 21:35 - 00000000 ____D C:\ProgramData\cljnaopmdlhkadappibkgihgnnagfcac 2013-12-30 21:35 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\d08b7a74df8325dc 2013-12-30 14:33 - 2013-01-11 02:57 - 00000000 ____D C:\Program Files (x86)\SciLor's Grooveshark 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Users\P83x\AppData\Local\Packages 2013-12-28 22:43 - 2013-12-28 22:43 - 00000000 ____D C:\Program Files (x86)\GS_Enabler 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\P83x\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\HomeGroupUser$ 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Gast 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Torch 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\Users\Administrator 2013-12-28 22:42 - 2013-12-28 22:42 - 00000000 ____D C:\ProgramData\InstallMate 2013-12-28 22:42 - 2013-11-26 20:14 - 00000000 ____D C:\Users\P83x\AppData\Local\Google 2013-12-26 17:57 - 2013-01-11 10:24 - 00760957 _____ C:\Windows\DirectX.log 2013-12-26 16:08 - 2013-12-26 16:08 - 00000000 ____D C:\Users\P83x\Documents\Square Enix 2013-12-24 15:40 - 2013-05-31 20:06 - 00000000 ____D C:\Users\P83x\Bilder 2013-12-21 16:31 - 2013-12-21 16:31 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard 2013-12-21 16:25 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Battle.net 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\Users\P83x\AppData\Local\Blizzard Entertainment 2013-12-21 16:24 - 2013-12-21 16:24 - 00000000 ____D C:\ProgramData\Blizzard Entertainment 2013-12-21 16:22 - 2013-12-21 16:22 - 00000000 ____D C:\ProgramData\Battle.net 2013-12-21 13:43 - 2013-12-21 13:38 - 00000000 ____D C:\Program Files (x86)\LastPass 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-21 13:38 - 2013-12-21 13:38 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass 2013-12-19 13:28 - 2013-12-19 13:28 - 00000000 ____D C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP 2013-12-16 12:25 - 2013-12-15 17:09 - 00000000 ____D C:\Users\P83x\AppData\Roaming\Dwarfs 2013-12-15 17:08 - 2013-12-15 17:08 - 00000000 ____D C:\Users\P83x\AppData\Roaming\AVAST Software 2013-12-15 11:39 - 2013-07-30 08:54 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-12-15 11:39 - 2013-07-30 08:54 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-12-15 11:39 - 2013-01-11 02:30 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-12-15 11:39 - 2013-01-11 02:30 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-12-15 11:39 - 2013-01-11 02:30 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-12-15 11:38 - 2013-01-11 02:30 - 00000000 ____D C:\ProgramData\AVAST Software 2013-12-15 11:38 - 2013-01-11 02:30 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-12-15 03:01 - 2013-07-26 02:00 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 03:00 - 2009-10-14 06:12 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 06:34 - 2013-01-11 02:28 - 00000000 ____D C:\Users\P83x\AppData\Roaming\vlc 2013-12-13 05:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-12 06:54 - 2013-02-14 18:11 - 00000000 ____D C:\Users\P83x\Schule 2013-12-11 22:03 - 2009-07-14 19:18 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-12-11 17:31 - 2009-07-14 05:45 - 00407464 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 13:29 - 2013-01-11 09:34 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-12-10 22:54 - 2013-12-10 21:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 22:54 - 2013-01-11 02:15 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 22:54 - 2013-01-11 02:15 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-10 01:16 - 2009-07-14 03:34 - 00000478 _____ C:\Windows\win.ini Some content of TEMP: ==================== C:\Users\P83x\AppData\Local\Temp\CRCCheck.exe C:\Users\P83x\AppData\Local\Temp\Quarantine.exe C:\Users\P83x\AppData\Local\Temp\SHSetup.exe C:\Users\P83x\AppData\Local\Temp\Tsu53C12B79.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 14:21 ==================== End Of Log ============================ Danke für die Hilfe |
08.01.2014, 12:28 | #21 |
/// the machine /// TB-Ausbilder | Avast! hat mehrere Viren gefunden Java updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\$RECYCLE.BIN Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Avast! hat mehrere Viren gefunden |
11.01.2014, 10:49 | #22 |
| Avast! hat mehrere Viren gefunden Danke vielmals!!!! Ich werde die Tipps beherzigen und hoffentlich in Zukunft nicht wiederkommen müssen Nochmals vielen Dank und beste Grüße p83x |
12.01.2014, 07:41 | #23 |
/// the machine /// TB-Ausbilder | Avast! hat mehrere Viren gefunden Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Avast! hat mehrere Viren gefunden |
autostart, avast, avast!, code, daemon, dateien, funktionier, gefunde, google, hilfe, hilfe!, konnte, log, schonmal, schritte, screenshot, tools, viren, virusfund, zip-datei |