|
Log-Analyse und Auswertung: Problem: http://static.icmapp.com/blank.html# etc.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.11.2013, 02:53 | #1 |
| Problem: http://static.icmapp.com/blank.html# etc. Liebe Community! Ich habe ein Problem! Es gibt zwar schon 3 Threads diesbezüglich, aber wie ich gelesen habe, soll ich einen eigenen Thread eröffnen. Also... Ich habe mir das Problem wahrscheinlich eingehandelt, als ich dem Update von Free Driver Scout (Freemium) zugestimmt hatte.... vorher war noch alles okay! Wie in den anderen Threads ebenfalls beschrieben, gehen bei mir leere Fenster mit folgender URL auf: hxxp://static.icmapp.com/blank.html#{%22ad_type%22%3A%22window%22%2C%22percent%22%3A50%2C%22size%22%3A[{%22percent%22%3A50%2C%22width%22%3A800%2C%22height%22%3A440}%2C{%22percent%22%3A50%2C%22width%22%3A1200%2C%22height%22%3A900}]%2C%22ad_width%22%3A1200%2C%22ad_height%22%3A900} Bevor ich den ADWCleaner gelaufen lassen hatte, hatte ich zusätzlich noch Probleme mit etwas anderem, dass hieß ungefähr cm.g.doubleclick.net... Seit kurzem funktioniert auch mein Avira nicht mehr vollständig! Ich kann den E-Mail-Schutz nicht mehr aktivieren! Bei jedem zweiten Click auf irgendeiner Website, geht bei mir diese leere "static"-Seite auf. Abgesehen davon, gibt es bei Weiterleitungen (also wenn man auf einer Seite etwas anklickt, um woanders hinzukommen) zwischendurch manchmal ein weißes Fenster, mit einem leeren grau schattiertem Rahmen, bei dem man unten rechts auf "skip" klicken kann, um dahinzugelangen, wo man hin will. Ich habe schon alles mögliche probiert.... Zuerst habe ich auf einen Wiederherstellungspunkt (ein paar Tage alt - umfasst System- und Programm-Partitionen) zurückgesetzt. Ohne Erfolg! Dann habe ich die Systempartition per True Image Home recovert (ca. 2 Wochen alt). Ohne Erfolg! Gesammelte Logs bisher: hosts.txt (keine Ahnung woher das kommt!) # Copyright (c) 1993-2009 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host # localhost name resolution is handled within DNS itself. # 127.0.0.1 localhost # ::1 localhost hijackthis (Ich weiß! Benutzt man nicht mehr, weil veraltet. Läuft aber auch gar nicht normal an, wegen Fehlermeldung bezüglich der ersten 6 Einträge) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 23:19:33, on 29.11.2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16736) Boot mode: Normal Running processes: C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe D:\Downloads\HiJackThis204.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: WebEnhance - {814664b0-d93b-4da6-9216-722c56179397} - C:\Program Files (x86)\WebEnhance\webenhance.dll O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O4 - HKLM\..\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - P:\ICQ7.6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - P:\ICQ7.6\ICQ.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - P:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Acronis Nonstop Backup-Dienst (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe O23 - Service: Avira Email Schutz (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Avira Browser-Schutz (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\Windows\system32\brsvc01a.exe O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe O23 - Service: CECFLPKT - Chicony Electronics Co., Ltd. - C:\Program Files (x86)\ChiconyCam\CECPLFKT.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - P:\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - P:\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Netzmanager Infrastruktur Informationssystem Dienst (Netzmanager Service) - Deutsche Telekom AG - P:\Netzmanager\NMInfraIS2\Netzmanager_Service.exe O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: PowerBiosServer - Unknown owner - C:\Program Files (x86)\Hotkey\PowerBiosServer.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe O23 - Service: TomTomHOMEService - TomTom - P:\TomTom HOME 2\TomTomHOMEService.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - P:\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 10550 bytes Malwarebytes (ohne Befund) Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.29.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16736 OLYNT :: OLYNT-PC [Administrator] 29.11.2013 23:25:50 mbam-log-2013-11-29 (23-25-50).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|P:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 465710 Laufzeit: 1 Stunde(n), 10 Minute(n), 7 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) AdwCleaner (Dateien nach Befund gelöscht) # AdwCleaner v3.013 - Bericht erstellt am 30/11/2013 um 00:58:30 # Updated 24/11/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : OLYNT - OLYNT-PC # Gestartet von : D:\Downloads\adwcleaner313.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater Ordner Gelöscht : C:\Program Files (x86)\WebEnhance Ordner Gelöscht : C:\Program Files\SoftwareUpdater Ordner Gelöscht : C:\Users\OLYNT\AppData\Local\DownloadGuide Ordner Gelöscht : C:\Users\OLYNT\AppData\Local\Temp\OCS Ordner Gelöscht : C:\Users\OLYNT\AppData\LocalLow\GutscheinCodes Ordner Gelöscht : C:\Users\OLYNT\AppData\Roaming\dvdvideosoftiehelpers Datei Gelöscht : C:\Windows\System32\Tasks\FreeDriverScout Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater Ui Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{38e9e285-5266-4fe2-b5b5-c14c29b0cd45}] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mbegnhpbhfjiaelealfpieodkembdgbj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GutscheinCodes.GutscheinCodesBHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GutscheinCodes.GutscheinCodesBHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{59279625-EFF0-4F55-98F0-51EDDD800DD9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{814664B0-D93B-4DA6-9216-722C56179397} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{F905535E-9C87-4A3F-8A3E-4E3B54C461C5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{814664B0-D93B-4DA6-9216-722C56179397} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{814664B0-D93B-4DA6-9216-722C56179397} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{814664B0-D93B-4DA6-9216-722C56179397} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\FLEXnet Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16736 -\\ Mozilla Firefox v25.0.1 (de) ************************* AdwCleaner[R0].txt - [4432 octets] - [30/11/2013 00:56:21] AdwCleaner[S0].txt - [4077 octets] - [30/11/2013 00:58:30] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4137 octets] ########## Ich bin total gerockt... Kann mir jemand helfen? Vielen Dank im Voraus!!! Liebe Grüße olynt |
30.11.2013, 12:32 | #2 |
/// the machine /// TB-Ausbilder | Problem: http://static.icmapp.com/blank.html# etc. hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
01.12.2013, 00:09 | #3 |
| Problem: http://static.icmapp.com/blank.html# etc. Hallo Schrauber!
__________________Danke schon 'mal, dass Du Dich meiner annimmst! Hier der "FRST.txt". Einen "Addition.txt" kann ich auf meinem Desktop nicht entdecken! Muss ich dazu noch 'was anderes machen als den ersten Scan laufen zu lassen? FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-11-2013 Ran by OLYNT (administrator) on OLYNT-PC on 30-11-2013 23:44:54 Running from D:\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (brother Industries Ltd) C:\Windows\SysWOW64\BRSVC01A.EXE (brother Industries Ltd) C:\Windows\SysWOW64\BRSS01A.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Malwarebytes Corporation) P:\Malwarebytes' Anti-Malware\mbamscheduler.exe (Deutsche Telekom AG) P:\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (TuneUp Software) P:\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software) P:\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) P:\Firefox\firefox.exe (Mozilla Corporation) P:\Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_152.exe (Mozilla Corporation) P:\Thunderbird\thunderbird.exe (TomTom) P:\TomTom HOME 2\TomTomHOMEService.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-02-11] (Synaptics Incorporated) HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [679768 2013-04-25] (Alps Electric Co., Ltd.) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13657304 2013-10-18] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] - "C:\Windows\system32\hkcmd.exe" HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-21] (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [] - [x] MountPoints2: {45e76adb-d5ac-11e0-b8a0-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {45e76ae9-d5ac-11e0-b8a0-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {4e96ea7e-f009-11e0-8812-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {4e96ea97-f009-11e0-8812-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {704f42f2-90c1-11e1-b9cb-b7c6ae77d866} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {704f431e-90c1-11e1-b9cb-b7c6ae77d866} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {9871cb5a-f5e1-11e0-8fe1-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {b50c2da6-f11b-11e0-8fc4-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {b819c1a1-d8c4-11e0-a0e0-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {e9507518-d5dc-11e0-b2aa-0090f5bb630e} - E:\setup.exe AUTORUN=1 MountPoints2: {e950756e-d5dc-11e0-b2aa-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {fff74cf7-db3d-11e0-b8b3-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-14] (Avira Operations GmbH & Co. KG) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-10-23] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-10-23] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB7C67C0364CACD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {456DD89B-7A0C-4263-AFA3-A2B20C6CAB75} URL = hxxp://www.bing.com/?cc=de SearchScopes: HKLM-x32 - {EA5B04F7-CC76-4BB3-BC4F-5DD3AF272554} URL = hxxp://www.bing.com/?cc=de BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\OLYNT\AppData\Roaming\Mozilla\Firefox\D:\Firefox FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - P:\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - P:\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1206147.dll (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - P:\Foxit Reader\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - P:\Foxit Reader\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\OLYNT\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF StartMenuInternet: FIREFOX.EXE - P:\Firefox\firefox.exe ==================== Services (Whitelisted) ================= R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [1012280 2013-11-14] (Avira Operations GmbH & Co. KG) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [948296 2013-11-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-14] (Avira Operations GmbH & Co. KG) R2 Brother XP spl Service; C:\Windows\SysWow64\brsvc01a.exe [57344 2002-04-11] (brother Industries Ltd) S2 CECFLPKT; C:\Program Files (x86)\ChiconyCam\CECPLFKT.exe [84592 2010-09-09] (Chicony Electronics Co., Ltd.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-11-28] (IObit) R2 MBAMScheduler; P:\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; P:\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 Netzmanager Service; P:\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [33792 2011-01-27] () R2 TomTomHOMEService; P:\TomTom HOME 2\TomTomHOMEService.exe [93072 2013-07-02] (TomTom) R2 TuneUp.UtilitiesSvc; P:\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2144056 2013-10-17] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-02-12] (Avira GmbH) R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-02-12] (Avira GmbH) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] () S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] () S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99800 2013-05-09] (Intel Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 TelekomNM6; P:\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R3 TuneUpUtilitiesDrv; P:\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-08-09] (TuneUp Software) S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [x] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [x] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] U5 UnlockerDriver5; P:\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-30 00:55 - 2013-11-30 01:35 - 00000000 ____D C:\AdwCleaner 2013-11-29 02:40 - 2013-11-29 02:40 - 00000000 ____D C:\Program Files (x86)\ChiconyCam 2013-11-29 02:13 - 2013-11-29 02:14 - 00002892 _____ C:\Windows\logboot_29.11.2013.tureg.log 2013-11-29 01:26 - 2013-11-29 01:26 - 00001241 _____ C:\Users\OLYNT\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\ProductData 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\IObit 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\Program Files (x86)\IObit 2013-11-17 05:20 - 2013-11-17 05:20 - 00000000 ____D C:\Users\OLYNT\Intel 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Program Files\Realtek 2013-11-17 03:54 - 2013-10-22 20:38 - 03692632 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-11-17 03:54 - 2013-10-22 17:40 - 00673037 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-11-17 03:54 - 2013-10-22 17:11 - 00151256 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-11-17 03:54 - 2013-10-21 10:46 - 02587352 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-11-17 03:54 - 2013-10-18 16:41 - 01286360 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2013-11-17 03:54 - 2013-10-07 11:05 - 02810072 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-11-17 03:54 - 2013-10-02 17:10 - 00617176 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2013-11-17 03:54 - 2013-09-26 16:11 - 01021656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-11-17 03:54 - 2013-08-05 18:11 - 02743328 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-11-17 03:54 - 2013-07-30 14:04 - 00397080 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp64.dll 2013-11-17 03:54 - 2013-07-24 10:07 - 02032896 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-11-17 03:54 - 2013-07-23 15:40 - 02103040 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-11-17 03:54 - 2013-07-23 15:39 - 00922880 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-11-17 03:54 - 2013-04-24 17:16 - 01662024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-11-17 03:54 - 2013-01-11 16:27 - 00628504 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX64.dll 2013-11-17 03:54 - 2013-01-11 16:27 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\MBTHX32.dll 2013-11-17 03:54 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2013-11-17 03:54 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2013-11-17 03:54 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-11-17 03:54 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2013-11-17 03:53 - 2013-10-16 03:43 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-11-17 03:53 - 2013-10-11 12:47 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2013-11-17 03:53 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2013-11-17 03:47 - 2013-11-17 03:47 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-11-17 02:53 - 2013-11-17 02:53 - 00003062 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00003060 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center 2013-11-17 02:26 - 2013-11-17 02:26 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Easeware 2013-11-17 01:33 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-17 01:33 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-17 01:33 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-17 01:33 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-17 01:33 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-17 01:33 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-17 01:33 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-17 01:33 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-17 01:33 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-17 01:33 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-17 01:31 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-17 01:31 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-17 01:31 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-17 01:31 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-17 01:31 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-17 01:31 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-17 01:31 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-17 01:31 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-17 01:31 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-17 01:31 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-17 01:31 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-17 01:31 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-17 01:31 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-17 01:31 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-17 01:31 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-17 01:31 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-17 01:31 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-17 01:31 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-17 01:31 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-17 01:31 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-17 01:31 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-17 01:31 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-17 01:31 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-17 01:31 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-17 01:31 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-17 01:29 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-17 01:29 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-17 01:29 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-17 01:29 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-17 01:29 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-14 13:28 - 2013-11-14 13:28 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Software_Updater 2013-11-07 01:52 - 2013-11-07 01:52 - 13031424 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 12617216 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 11176448 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 10812928 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 09007616 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 05904856 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 05363200 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2013-11-07 01:52 - 2013-11-07 01:52 - 00515544 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00442880 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00442328 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00410624 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00399832 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00384512 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00279000 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00254936 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00185816 _____ (Intel Corporation) C:\Windows\system32\difx64.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00171992 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2013-11-07 01:52 - 2013-11-07 01:52 - 00116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v3347.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00110592 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00098304 _____ C:\Windows\system32\igdde64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00077312 _____ C:\Windows\SysWOW64\igdde32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00064000 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00017058 _____ C:\Windows\system32\iglhxs64.vp 2013-11-07 01:52 - 2013-11-07 01:52 - 00009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll ==================== One Month Modified Files and Folders ======= 2013-11-30 23:26 - 2009-07-14 05:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-30 23:26 - 2009-07-14 05:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-30 23:23 - 2010-11-21 07:50 - 00715512 _____ C:\Windows\system32\perfh007.dat 2013-11-30 23:23 - 2010-11-21 07:50 - 00155062 _____ C:\Windows\system32\perfc007.dat 2013-11-30 23:23 - 2009-07-14 06:13 - 01653086 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-30 23:19 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-30 23:19 - 2009-07-14 05:51 - 00199198 _____ C:\Windows\setupact.log 2013-11-30 23:17 - 2011-09-02 03:20 - 01740765 _____ C:\Windows\WindowsUpdate.log 2013-11-30 23:16 - 2012-06-15 02:19 - 01627366 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-30 23:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-11-30 04:46 - 2012-04-04 16:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-30 02:05 - 2012-06-01 21:08 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Google 2013-11-30 01:35 - 2013-11-30 00:55 - 00000000 ____D C:\AdwCleaner 2013-11-29 02:56 - 2011-10-26 03:31 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Skype 2013-11-29 02:52 - 2011-10-26 03:31 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-29 02:52 - 2011-10-26 02:50 - 00000000 ____D C:\ProgramData\Skype 2013-11-29 02:50 - 2011-09-02 04:31 - 00253784 _____ C:\Users\OLYNT\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-29 02:47 - 2010-11-21 04:47 - 00576638 _____ C:\Windows\PFRO.log 2013-11-29 02:47 - 2009-07-14 05:45 - 00901416 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-29 02:41 - 2011-09-16 23:27 - 00000000 ____D C:\ProgramData\InstallShield 2013-11-29 02:41 - 2011-09-02 04:13 - 00000155 _____ C:\setup.log 2013-11-29 02:41 - 2011-09-02 04:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-11-29 02:41 - 2009-07-14 04:20 - 00000000 __RSD C:\Windows\Media 2013-11-29 02:40 - 2013-11-29 02:40 - 00000000 ____D C:\Program Files (x86)\ChiconyCam 2013-11-29 02:40 - 2011-09-02 04:03 - 00172256 _____ C:\Windows\DPINST.LOG 2013-11-29 02:38 - 2011-09-08 00:37 - 00000000 ____D C:\ProgramData\Fiesta Download Manager 2013-11-29 02:37 - 2011-10-06 12:13 - 00000000 ____D C:\ProgramData\DatacardService 2013-11-29 02:32 - 2013-04-29 22:38 - 00000000 ____D C:\ProgramData\Nuance 2013-11-29 02:32 - 2013-04-29 22:38 - 00000000 ____D C:\Program Files (x86)\Nuance 2013-11-29 02:28 - 2013-10-10 03:30 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-29 02:25 - 2011-09-07 02:47 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\ICQ 2013-11-29 02:16 - 2011-09-02 03:42 - 00000000 ____D C:\Users\OLYNT 2013-11-29 02:15 - 2009-07-14 03:34 - 71827456 _____ C:\Windows\system32\config\SOFTWARE_tureg_old 2013-11-29 02:15 - 2009-07-14 03:34 - 25165824 _____ C:\Windows\system32\config\SYSTEM_tureg_old 2013-11-29 02:15 - 2009-07-14 03:34 - 00028672 _____ C:\Windows\system32\config\SECURITY_tureg_old 2013-11-29 02:14 - 2013-11-29 02:13 - 00002892 _____ C:\Windows\logboot_29.11.2013.tureg.log 2013-11-29 02:12 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\DEFAULT_tureg_old 2013-11-29 02:12 - 2009-07-14 03:34 - 00061440 _____ C:\Windows\system32\config\SAM_tureg_old 2013-11-29 01:54 - 2013-01-05 23:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-29 01:27 - 2013-10-25 02:36 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon 2013-11-29 01:27 - 2011-09-08 03:49 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Amazon 2013-11-29 01:26 - 2013-11-29 01:26 - 00001241 _____ C:\Users\OLYNT\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2013-11-29 00:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-11-29 00:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-29 00:47 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-29 00:20 - 2013-10-29 02:17 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-11-29 00:20 - 2013-10-29 02:17 - 00000000 ____D C:\Windows\system32\NV 2013-11-28 23:51 - 2013-04-29 22:39 - 00000000 ____D C:\ProgramData\ScanSoft 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\ProductData 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\IObit 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\Program Files (x86)\IObit 2013-11-17 05:22 - 2011-09-02 03:55 - 00000000 ____D C:\Program Files (x86)\Intel 2013-11-17 05:21 - 2011-09-02 04:16 - 00000000 ____D C:\ProgramData\Intel 2013-11-17 05:21 - 2011-09-02 04:16 - 00000000 ____D C:\Program Files\Intel 2013-11-17 05:20 - 2013-11-17 05:20 - 00000000 ____D C:\Users\OLYNT\Intel 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Program Files\Realtek 2013-11-17 03:47 - 2013-11-17 03:47 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-11-17 02:53 - 2013-11-17 02:53 - 00003062 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00003060 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center 2013-11-17 02:26 - 2013-11-17 02:26 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Easeware 2013-11-17 01:33 - 2011-09-05 02:27 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 13:38 - 2013-05-02 12:27 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-11-14 13:38 - 2013-04-13 01:56 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-11-14 13:38 - 2013-04-13 01:56 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-11-14 13:38 - 2013-04-13 01:56 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-11-14 13:34 - 2013-06-12 12:09 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Adobe 2013-11-14 13:34 - 2012-04-04 16:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-14 13:34 - 2012-04-04 16:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-11-14 13:34 - 2012-03-15 23:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-14 13:28 - 2013-11-14 13:28 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Software_Updater 2013-11-14 01:27 - 2012-02-10 02:06 - 00003704 _____ C:\Windows\System32\Tasks\Java Update Scheduler 2013-11-07 01:52 - 2013-11-07 01:52 - 13031424 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 12617216 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 11176448 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 10812928 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 09007616 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 05904856 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 05363200 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2013-11-07 01:52 - 2013-11-07 01:52 - 00515544 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00442880 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00442328 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00410624 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00399832 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00384512 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00279000 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00254936 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00185816 _____ (Intel Corporation) C:\Windows\system32\difx64.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00171992 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2013-11-07 01:52 - 2013-11-07 01:52 - 00116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v3347.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00110592 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00098304 _____ C:\Windows\system32\igdde64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00077312 _____ C:\Windows\SysWOW64\igdde32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00064000 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00017058 _____ C:\Windows\system32\iglhxs64.vp 2013-11-07 01:52 - 2013-11-07 01:52 - 00009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll 2013-11-07 01:52 - 2012-03-19 22:26 - 11049472 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll 2013-11-07 01:52 - 2011-09-02 03:57 - 12859392 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll Some content of TEMP: ==================== C:\Users\OLYNT\AppData\Local\Temp\avgnt.exe C:\Users\OLYNT\AppData\Local\Temp\mfc80.dll C:\Users\OLYNT\AppData\Local\Temp\mfc80u.dll C:\Users\OLYNT\AppData\Local\Temp\mfcm80.dll C:\Users\OLYNT\AppData\Local\Temp\mfcm80u.dll C:\Users\OLYNT\AppData\Local\Temp\msvcm80.dll C:\Users\OLYNT\AppData\Local\Temp\msvcp80.dll C:\Users\OLYNT\AppData\Local\Temp\msvcr80.dll C:\Users\OLYNT\AppData\Local\Temp\Quarantine.exe C:\Users\OLYNT\AppData\Local\Temp\SkypeSetup.exe C:\Users\OLYNT\AppData\Local\Temp\Uninstaller.exe C:\Users\OLYNT\AppData\Local\Temp\UninstallerGer.dll C:\Users\OLYNT\AppData\Local\Temp\WtgDriverInstallX.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-14 22:32 ==================== End Of Log ============================ --- --- --- [/CODE] Viele Grüße olynt ...ich musste zwar ungefragt einen Haken setzen - aber ich sollte das ja auch posten: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-11-2013 Ran by OLYNT at 2013-12-01 00:05:44 Running from D:\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Acronis*True*Image*Home 2011 (x32 Version: 14.0.6942) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152) Adobe Shockwave Player 12.0 (x32 Version: 12.0.6.147) ALPS Touch Pad Driver (Version: 8.201.1711.120) Ashampoo Burning Studio 11 v.11.0.2 (x32 Version: 11.0.2) ASIO4ALL (x32 Version: 2.10) Avira Internet Security (x32 Version: 14.0.1.749) Brother BRAdmin Light 1.21.0001 (x32 Version: 1.21.0001) Brother Driver Deployment Wizard (x32 Version: 1.09.000) Brother MFL-Pro Suite MFC-J5910DW (x32 Version: 1.0.5.0) ChiconyCam (x32 Version: 1.0.36.913) dm-Fotowelt (x32 Version: 5.0.4) Dropbox (HKCU Version: 2.0.22) EASEUS Partition Master 9.1.1 Home Edition (x32) Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.27.0) Foxit Reader (x32 Version: 6.0.2.413) Free Studio version 2013 (x32 Version: 6.1.12.925) FreeRIP MP3 Converter 4.4.1 (x32 Version: 4.4.1) GeForce Experience NvStream Client Components (Version: 1.6.28) Hard Disk Low Level Format Tool 4.12 (x32) Hotkey 3.3023 (x32 Version: 3.3023) ICQ 8.0 (build 6003, für aktuellen Benutzer) (HKCU Version: 8.0.6003.0) ICQ7.6 (x32 Version: 7.6) Intel(R) Management Engine Components (x32 Version: 9.5.3.1520) Intel(R) Processor Graphics (x32 Version: 9.17.10.3347) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016) Intel® PROSet/Wireless Software (x32 Version: 16.1.1) Intel® Trusted Connect Service Client (Version: 1.27.798.1) Intel® Watchdog Timer Driver (Intel® WDT) (x32) IObit Uninstaller (x32 Version: 3.0.4.922) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.33.3) JMicron Flash Media Controller Driver (x32 Version: 1.0.54.1) Logitech Gaming Software (Version: 8.45.88) Logitech Gaming Software 8.50 (Version: 8.50.281) MAGIX Music Maker MX Premium (x32 Version: 18.0.0.42) MAGIX Music Maker MX Premium Update (Version: 18.0.4.1) MAGIX Music Maker MX Premium Update (x32 Version: 18.0.3.0) MAGIX Screenshare (x32 Version: 4.3.6.1987) MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938) Microsoft Mouse and Keyboard Center (Version: 2.2.173.0) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1) Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) Mozilla Thunderbird 24.0.1 (x86 de) (x32 Version: 24.0.1) Mp3tag v2.58 (x32 Version: v2.58) MSVC80_x64_v2 (Version: 1.0.3.0) MSVC80_x86_v2 (x32 Version: 1.0.3.0) MSVC90_x64 (Version: 1.0.1.2) MSVC90_x86 (x32 Version: 1.0.1.2) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) Netzmanager (Version: 1.071) Netzmanager (x32 Version: 1.071) NirSoft BlueScreenView (x32) Nokia Connectivity Cable Driver (x32 Version: 7.1.172.0) Nokia Suite (x32 Version: 3.8.48.0) NVIDIA GeForce Experience 1.7 (Version: 1.7) NVIDIA Grafiktreiber 331.65 (Version: 331.65) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA Optimus 9.3.16 (Version: 9.3.16) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16) NVIDIA Systemsteuerung 331.65 (Version: 331.65) NVIDIA Update 9.3.16 (Version: 9.3.16) NVIDIA Update Components (Version: 9.3.16) NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9) Paint.NET v3.5.10 (Version: 3.60.0) Pando Media Booster (x32 Version: 2.6.0.7) PC Connectivity Solution (x32 Version: 12.0.109.0) PDFCreator (x32 Version: 1.6.2) Realtek High Definition Audio Driver (x32 Version: 6.0.1.7071) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.39.0) SHIELD Streaming (Version: 1.6.34) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.11 (x32 Version: 6.11.102) Synaptics Pointing Device Driver (Version: 15.0.8.0) System Requirements Lab (x32) System Requirements Lab for Intel (x32 Version: 4.5.15.0) TeamSpeak 3 Client (x32 Version: 3.0.6) TeamViewer 8 (x32 Version: 8.0.18051) Text-To-Speech-Runtime (x32 Version: 1.0.0.0) THX TruStudio Pro (x32 Version: TAMB-CVS1D-1-LB R07) TomTom HOME (x32 Version: 2.9.6) TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2) TuneUp Utilities 2012 (x32 Version: 12.0.3600.129) TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.129) Unity Web Player (HKCU Version: ) Unlocker 1.9.1-x64 (Version: 1.9.1) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2598290) 32-Bit Edition (x32) Update for Zip Opener (HKCU) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VLC media player 2.0.6 (Version: 2.0.6) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0) Yahoo! Messenger (x32) Z-defragRAM (x32 Version: 2.7) ==================== Restore Points ========================= 29-11-2013 02:53:59 vor HiJackThis 30-11-2013 22:14:37 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {2BE2F70C-CAA9-4190-A92A-741DE2A42335} - System32\Tasks\{ACA804A1-2A77-4D17-92B7-00364125955F} => D:\Downloads\Xpadder(1).exe Task: {2E3D543F-702F-423F-BBCF-D6CB46F2CDC6} - \Software Updater Ui No Task File Task: {395C6845-0179-4DBC-BD04-30D41060575B} - System32\Tasks\{FAA5FB71-F4F6-4F0C-B7CE-3685ECEAF6B4} => P:\Xpadder(1).exe [2012-07-21] () Task: {4DBBBA45-A2C7-41AC-A944-5D2FCD94042B} - System32\Tasks\{9ED9E1ED-59C4-4213-A776-15A008EF7CE6} => Firefox.exe hxxp://ui.skype.com/ui/0/5.5.0.124.259/de/abandoninstall?source=lightinstaller&page=tsProblems&LastError=12002&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled Task: {735B74B9-1E5B-4BFF-956A-B75B3A3F262C} - System32\Tasks\{3EEF37EF-7900-4BDE-B59A-C2923D3AE59D} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.5.0.124.259&LastError=12002 Task: {79BA2AFD-2C4B-4291-9A5D-94FAB064E7D9} - System32\Tasks\Google Updater and Installer => C:\Users\OLYNT\AppData\Local\Google\Update\GoogleUpdate.exe Task: {7BD27B3E-366F-45F1-B98D-43C5FB44C056} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => P:\TuneUp Utilities 2012\OneClick.exe [2013-10-17] (TuneUp Software) Task: {7CF6FBA5-5AB4-40AD-BCC3-DFC57C5D2D14} - \Software Updater No Task File Task: {83247E88-7F60-49C3-83AE-3A1CD92528F3} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {A6E8F11A-10EA-427C-8958-FDB797D1B37C} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {B407F380-8338-4977-AF88-370E15B7A5C7} - System32\Tasks\{D57A2F05-F991-450D-9271-6F4610AE8183} => P:\ultrachord\ultraChord.exe [2013-02-10] () Task: {B4F623F5-5992-4412-8116-0A3AAEE6A532} - \FreeDriverScout No Task File Task: {B9EB0A9B-93D1-4245-9D31-D29AF77362DA} - System32\Tasks\{CADB9278-FBBE-4491-97CA-63BC5A2B197E} => P:\ultrachord\ultraChord.exe [2013-02-10] () Task: {BE84A311-DE3E-4B5C-AD7E-4166365A6AEA} - System32\Tasks\{645622BC-C9CA-466C-86C9-1886CC8446CA} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.107/de/abandoninstall?page=tsProgressBar Task: {C25C2C5A-D317-45E1-8DCC-3808ED8A1C42} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {CA10141D-9792-4562-84D8-6213187C010D} - System32\Tasks\{5D405EF0-9E62-4A93-B7F5-05491543ACC3} => P:\ultrachord\ultraChord.exe [2013-02-10] () Task: {FA392611-764C-4FD4-AC61-E7819DD7EACE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-14] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2011-09-02 04:20 - 2010-11-12 11:38 - 00241152 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL 2011-09-02 03:57 - 2010-11-28 13:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-02-06 03:12 - 2013-02-06 03:05 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2011-09-02 04:20 - 2010-11-01 16:34 - 00159744 ____N () C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\de-DE\THXAudio.resources.dll 2013-10-10 04:01 - 2013-05-09 03:23 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2013-11-29 01:41 - 2013-11-13 04:39 - 03363952 _____ () P:\Firefox\mozjs.dll 2013-11-14 13:34 - 2013-11-14 13:34 - 16237448 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll 2013-11-19 23:31 - 2013-11-19 23:31 - 03008624 _____ () P:\Thunderbird\mozjs.dll 2013-11-19 23:31 - 2013-11-19 23:31 - 00158832 _____ () P:\Thunderbird\NSLDAP32V60.dll 2013-11-19 23:31 - 2013-11-19 23:31 - 00023152 _____ () P:\Thunderbird\NSLDAPPR32V60.dll ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/30/2013 11:20:09 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/30/2013 11:19:46 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CECPLFKT.exe, Version: 0.9.1.1030, Zeitstempel: 0x4aefec4e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039393 ID des fehlerhaften Prozesses: 0x960 Startzeit der fehlerhaften Anwendung: 0xCECPLFKT.exe0 Pfad der fehlerhaften Anwendung: CECPLFKT.exe1 Pfad des fehlerhaften Moduls: CECPLFKT.exe2 Berichtskennung: CECPLFKT.exe3 Error: (11/30/2013 11:10:46 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/30/2013 11:10:12 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CECPLFKT.exe, Version: 0.9.1.1030, Zeitstempel: 0x4aefec4e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039393 ID des fehlerhaften Prozesses: 0x97c Startzeit der fehlerhaften Anwendung: 0xCECPLFKT.exe0 Pfad der fehlerhaften Anwendung: CECPLFKT.exe1 Pfad des fehlerhaften Moduls: CECPLFKT.exe2 Berichtskennung: CECPLFKT.exe3 Error: (11/30/2013 04:10:55 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: OneClick.exe, Version: 12.0.3600.129, Zeitstempel: 0x525ff6e9 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002dfe4 ID des fehlerhaften Prozesses: 0x13bc Startzeit der fehlerhaften Anwendung: 0xOneClick.exe0 Pfad der fehlerhaften Anwendung: OneClick.exe1 Pfad des fehlerhaften Moduls: OneClick.exe2 Berichtskennung: OneClick.exe3 Error: (11/30/2013 03:31:25 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/30/2013 03:30:45 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CECPLFKT.exe, Version: 0.9.1.1030, Zeitstempel: 0x4aefec4e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039393 ID des fehlerhaften Prozesses: 0x958 Startzeit der fehlerhaften Anwendung: 0xCECPLFKT.exe0 Pfad der fehlerhaften Anwendung: CECPLFKT.exe1 Pfad des fehlerhaften Moduls: CECPLFKT.exe2 Berichtskennung: CECPLFKT.exe3 Error: (11/30/2013 01:38:42 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/30/2013 01:38:01 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CECPLFKT.exe, Version: 0.9.1.1030, Zeitstempel: 0x4aefec4e Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00039393 ID des fehlerhaften Prozesses: 0x94c Startzeit der fehlerhaften Anwendung: 0xCECPLFKT.exe0 Pfad der fehlerhaften Anwendung: CECPLFKT.exe1 Pfad des fehlerhaften Moduls: CECPLFKT.exe2 Berichtskennung: CECPLFKT.exe3 Error: (11/30/2013 01:17:42 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. System errors: ============= Error: (11/30/2013 11:28:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (11/30/2013 11:19:47 PM) (Source: Service Control Manager) (User: ) Description: Dienst "CECFLPKT" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/30/2013 11:19:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (11/30/2013 11:15:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (11/30/2013 11:10:14 PM) (Source: Service Control Manager) (User: ) Description: Dienst "CECFLPKT" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/30/2013 11:09:55 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (11/30/2013 05:12:51 AM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (11/30/2013 03:32:03 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Error: (11/30/2013 03:30:46 AM) (Source: Service Control Manager) (User: ) Description: Dienst "CECFLPKT" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/30/2013 03:30:29 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Avira Email Schutz" wurde mit folgendem dienstspezifischem Fehler beendet: %%1. Microsoft Office Sessions: ========================= Error: (07/08/2012 09:37:20 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1485 seconds with 660 seconds of active time. This session ended with a crash. Error: (03/04/2012 04:01:10 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 190 seconds with 180 seconds of active time. This session ended with a crash. Error: (02/17/2012 10:24:47 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 178 seconds with 120 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 8106.17 MB Available physical RAM: 4944.52 MB Total Pagefile: 20263.35 MB Available Pagefile: 17189.89 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:60 GB) (Free:17.11 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Daten) (Fixed) (Total:538.64 GB) (Free:337.96 GB) NTFS Drive f: (OLYNT EXTERN MOBIL 1) (Fixed) (Total:596.17 GB) (Free:285.59 GB) NTFS Drive p: (Programme) (Fixed) (Total:100 GB) (Free:78.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 76C8CFBD) Partition 1: (Active) - (Size=60 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=639 GB) - (Type=05) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: B414706E) Partition 1: (Not Active) - (Size=596 GB) - (Type=07 NTFS) ==================== End Of Log ============================ LG olynt |
01.12.2013, 16:10 | #4 |
/// the machine /// TB-Ausbilder | Problem: http://static.icmapp.com/blank.html# etc.Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.12.2013, 00:30 | #5 |
| Problem: http://static.icmapp.com/blank.html# etc. ...okay... Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Home Premium x64 Ran by OLYNT on 01.12.2013 at 20:08:38,12 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01.12.2013 at 20:12:58,95 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-11-2013 Ran by OLYNT (administrator) on OLYNT-PC on 01-12-2013 20:19:03 Running from D:\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (brother Industries Ltd) C:\Windows\SysWOW64\BRSVC01A.EXE (brother Industries Ltd) C:\Windows\SysWOW64\BRSS01A.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Malwarebytes Corporation) P:\Malwarebytes' Anti-Malware\mbamscheduler.exe (Deutsche Telekom AG) P:\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (TomTom) P:\TomTom HOME 2\TomTomHOMEService.exe (TuneUp Software) P:\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe (TuneUp Software) P:\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-02-11] (Synaptics Incorporated) HKLM\...\Run: [THXCfg64] - C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [679768 2013-04-25] (Alps Electric Co., Ltd.) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13657304 2013-10-18] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] - "C:\Windows\system32\hkcmd.exe" HKLM-x32\...\Winlogon: [Userinit] C:\Windows\sysWOW64\userinit.exe [26624 2010-11-21] (Microsoft Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [] - [x] MountPoints2: {45e76adb-d5ac-11e0-b8a0-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {45e76ae9-d5ac-11e0-b8a0-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {4e96ea7e-f009-11e0-8812-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {4e96ea97-f009-11e0-8812-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {704f42f2-90c1-11e1-b9cb-b7c6ae77d866} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {704f431e-90c1-11e1-b9cb-b7c6ae77d866} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {9871cb5a-f5e1-11e0-8fe1-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {b50c2da6-f11b-11e0-8fc4-0090f5bb630e} - E:\AutoRun.exe MountPoints2: {b819c1a1-d8c4-11e0-a0e0-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {e9507518-d5dc-11e0-b2aa-0090f5bb630e} - E:\setup.exe AUTORUN=1 MountPoints2: {e950756e-d5dc-11e0-b2aa-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 MountPoints2: {fff74cf7-db3d-11e0-b8b3-0090f5bb630e} - E:\.\Autorun.exe AUTORUN=1 HKLM-x32\...\Run: [THX Audio Control Panel] - C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe [1374720 2010-11-01] (Creative Technology Ltd) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-14] (Avira Operations GmbH & Co. KG) AppInit_DLLs: C:\Windows\System32\nvinitx.dll [168616 2013-10-23] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [141336 2013-10-23] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB7C67C0364CACD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {456DD89B-7A0C-4263-AFA3-A2B20C6CAB75} URL = hxxp://www.bing.com/?cc=de SearchScopes: HKLM-x32 - {EA5B04F7-CC76-4BB3-BC4F-5DD3AF272554} URL = hxxp://www.bing.com/?cc=de BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com/bin/srldetect_intel_4.5.15.0.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\OLYNT\AppData\Roaming\Mozilla\Firefox\D:\Firefox FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - P:\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - P:\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1206147.dll (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - P:\Foxit Reader\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - P:\Foxit Reader\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\OLYNT\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF StartMenuInternet: FIREFOX.EXE - P:\Firefox\firefox.exe ==================== Services (Whitelisted) ================= R2 AntiVirFirewallService; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [1012280 2013-11-14] (Avira Operations GmbH & Co. KG) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [948296 2013-11-14] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1164360 2013-11-14] (Avira Operations GmbH & Co. KG) R2 Brother XP spl Service; C:\Windows\SysWow64\brsvc01a.exe [57344 2002-04-11] (brother Industries Ltd) S2 CECFLPKT; C:\Program Files (x86)\ChiconyCam\CECPLFKT.exe [84592 2010-09-09] (Chicony Electronics Co., Ltd.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-11-28] (IObit) R2 MBAMScheduler; P:\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; P:\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 Netzmanager Service; P:\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15122208 2013-10-18] (NVIDIA Corporation) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [33792 2011-01-27] () R2 TomTomHOMEService; P:\TomTom HOME 2\TomTomHOMEService.exe [93072 2013-07-02] (TomTom) R2 TuneUp.UtilitiesSvc; P:\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2144056 2013-10-17] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [114608 2013-02-12] (Avira GmbH) R1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [141376 2013-02-12] (Avira GmbH) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [106904 2013-11-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] () S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] () S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech) S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99800 2013-05-09] (Intel Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) S3 TelekomNM6; P:\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R3 TuneUpUtilitiesDrv; P:\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-08-09] (TuneUp Software) S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [x] S3 ew_usbenumfilter; system32\DRIVERS\ew_usbenumfilter.sys [x] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [x] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x] S3 huawei_ext_ctrl; system32\DRIVERS\ew_juextctrl.sys [x] S3 huawei_wwanecm; system32\DRIVERS\ew_juwwanecm.sys [x] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [x] U5 UnlockerDriver5; P:\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-01 20:08 - 2013-12-01 20:08 - 00000000 ____D C:\Windows\ERUNT 2013-11-30 00:55 - 2013-11-30 01:35 - 00000000 ____D C:\AdwCleaner 2013-11-29 02:40 - 2013-11-29 02:40 - 00000000 ____D C:\Program Files (x86)\ChiconyCam 2013-11-29 02:13 - 2013-11-29 02:14 - 00002892 _____ C:\Windows\logboot_29.11.2013.tureg.log 2013-11-29 01:26 - 2013-11-29 01:26 - 00001241 _____ C:\Users\OLYNT\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\ProductData 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\IObit 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\Program Files (x86)\IObit 2013-11-17 05:20 - 2013-11-17 05:20 - 00000000 ____D C:\Users\OLYNT\Intel 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Program Files\Realtek 2013-11-17 03:54 - 2013-10-22 20:38 - 03692632 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-11-17 03:54 - 2013-10-22 17:40 - 00673037 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-11-17 03:54 - 2013-10-22 17:11 - 00151256 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-11-17 03:54 - 2013-10-21 10:46 - 02587352 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-11-17 03:54 - 2013-10-18 16:41 - 01286360 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2013-11-17 03:54 - 2013-10-07 11:05 - 02810072 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-11-17 03:54 - 2013-10-02 17:10 - 00617176 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2013-11-17 03:54 - 2013-09-26 16:11 - 01021656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-11-17 03:54 - 2013-08-05 18:11 - 02743328 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-11-17 03:54 - 2013-07-30 14:04 - 00397080 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp64.dll 2013-11-17 03:54 - 2013-07-24 10:07 - 02032896 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-11-17 03:54 - 2013-07-23 15:40 - 02103040 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-11-17 03:54 - 2013-07-23 15:39 - 00922880 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-11-17 03:54 - 2013-04-24 17:16 - 01662024 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-11-17 03:54 - 2013-01-11 16:27 - 00628504 _____ (Creative Technology Ltd.) C:\Windows\system32\MBTHX64.dll 2013-11-17 03:54 - 2013-01-11 16:27 - 00563992 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\MBTHX32.dll 2013-11-17 03:54 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2013-11-17 03:54 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2013-11-17 03:54 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2013-11-17 03:54 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-11-17 03:54 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2013-11-17 03:54 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2013-11-17 03:53 - 2013-10-16 03:43 - 00209096 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-11-17 03:53 - 2013-10-11 12:47 - 00113576 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2013-11-17 03:53 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2013-11-17 03:47 - 2013-11-17 03:47 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-11-17 02:53 - 2013-11-17 02:53 - 00003062 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00003060 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center 2013-11-17 02:26 - 2013-11-17 02:26 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Easeware 2013-11-17 01:33 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-17 01:33 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-17 01:33 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-17 01:33 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-17 01:33 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-17 01:33 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-17 01:33 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-17 01:33 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-17 01:33 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-17 01:33 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-17 01:33 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-17 01:33 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-17 01:31 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-17 01:31 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-17 01:31 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-17 01:31 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-17 01:31 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-17 01:31 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-17 01:31 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-17 01:31 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-17 01:31 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-17 01:31 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-17 01:31 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-17 01:31 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-17 01:31 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-17 01:31 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-17 01:31 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-17 01:31 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-17 01:31 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-17 01:31 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-17 01:31 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-17 01:31 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-17 01:31 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-17 01:31 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-17 01:31 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-17 01:31 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-17 01:31 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-17 01:29 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-17 01:29 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-17 01:29 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-17 01:29 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-17 01:29 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-14 13:28 - 2013-11-14 13:28 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Software_Updater 2013-11-07 01:52 - 2013-11-07 01:52 - 13031424 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 12617216 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 11176448 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 10812928 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 09007616 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 05904856 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 05363200 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2013-11-07 01:52 - 2013-11-07 01:52 - 00515544 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00442880 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00442328 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00410624 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00399832 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00384512 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00279000 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00254936 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00185816 _____ (Intel Corporation) C:\Windows\system32\difx64.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00171992 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2013-11-07 01:52 - 2013-11-07 01:52 - 00116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v3347.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00110592 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00098304 _____ C:\Windows\system32\igdde64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00077312 _____ C:\Windows\SysWOW64\igdde32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00064000 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00017058 _____ C:\Windows\system32\iglhxs64.vp 2013-11-07 01:52 - 2013-11-07 01:52 - 00009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll ==================== One Month Modified Files and Folders ======= 2013-12-01 20:08 - 2013-12-01 20:08 - 00000000 ____D C:\Windows\ERUNT 2013-12-01 20:04 - 2009-07-14 05:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-01 20:04 - 2009-07-14 05:45 - 00021856 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-01 20:01 - 2010-11-21 07:50 - 00715512 _____ C:\Windows\system32\perfh007.dat 2013-12-01 20:01 - 2010-11-21 07:50 - 00155062 _____ C:\Windows\system32\perfc007.dat 2013-12-01 20:01 - 2009-07-14 06:13 - 01653086 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-01 19:57 - 2009-07-14 05:51 - 00199366 _____ C:\Windows\setupact.log 2013-12-01 19:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-01 01:31 - 2011-09-02 03:20 - 01750940 _____ C:\Windows\WindowsUpdate.log 2013-12-01 00:46 - 2012-04-04 16:05 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-30 23:16 - 2012-06-15 02:19 - 01627366 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-30 23:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-11-30 02:05 - 2012-06-01 21:08 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Google 2013-11-30 01:35 - 2013-11-30 00:55 - 00000000 ____D C:\AdwCleaner 2013-11-29 02:56 - 2011-10-26 03:31 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Skype 2013-11-29 02:52 - 2011-10-26 03:31 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-29 02:52 - 2011-10-26 02:50 - 00000000 ____D C:\ProgramData\Skype 2013-11-29 02:50 - 2011-09-02 04:31 - 00253784 _____ C:\Users\OLYNT\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-29 02:47 - 2010-11-21 04:47 - 00576638 _____ C:\Windows\PFRO.log 2013-11-29 02:47 - 2009-07-14 05:45 - 00901416 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-29 02:41 - 2011-09-16 23:27 - 00000000 ____D C:\ProgramData\InstallShield 2013-11-29 02:41 - 2011-09-02 04:13 - 00000155 _____ C:\setup.log 2013-11-29 02:41 - 2011-09-02 04:05 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-11-29 02:41 - 2009-07-14 04:20 - 00000000 __RSD C:\Windows\Media 2013-11-29 02:40 - 2013-11-29 02:40 - 00000000 ____D C:\Program Files (x86)\ChiconyCam 2013-11-29 02:40 - 2011-09-02 04:03 - 00172256 _____ C:\Windows\DPINST.LOG 2013-11-29 02:38 - 2011-09-08 00:37 - 00000000 ____D C:\ProgramData\Fiesta Download Manager 2013-11-29 02:37 - 2011-10-06 12:13 - 00000000 ____D C:\ProgramData\DatacardService 2013-11-29 02:32 - 2013-04-29 22:38 - 00000000 ____D C:\ProgramData\Nuance 2013-11-29 02:32 - 2013-04-29 22:38 - 00000000 ____D C:\Program Files (x86)\Nuance 2013-11-29 02:28 - 2013-10-10 03:30 - 00000000 ____D C:\ProgramData\Package Cache 2013-11-29 02:25 - 2011-09-07 02:47 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\ICQ 2013-11-29 02:16 - 2011-09-02 03:42 - 00000000 ____D C:\Users\OLYNT 2013-11-29 02:15 - 2009-07-14 03:34 - 71827456 _____ C:\Windows\system32\config\SOFTWARE_tureg_old 2013-11-29 02:15 - 2009-07-14 03:34 - 25165824 _____ C:\Windows\system32\config\SYSTEM_tureg_old 2013-11-29 02:15 - 2009-07-14 03:34 - 00028672 _____ C:\Windows\system32\config\SECURITY_tureg_old 2013-11-29 02:14 - 2013-11-29 02:13 - 00002892 _____ C:\Windows\logboot_29.11.2013.tureg.log 2013-11-29 02:12 - 2009-07-14 03:34 - 00262144 _____ C:\Windows\system32\config\DEFAULT_tureg_old 2013-11-29 02:12 - 2009-07-14 03:34 - 00061440 _____ C:\Windows\system32\config\SAM_tureg_old 2013-11-29 01:54 - 2013-01-05 23:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-29 01:27 - 2013-10-25 02:36 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon 2013-11-29 01:27 - 2011-09-08 03:49 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Amazon 2013-11-29 01:26 - 2013-11-29 01:26 - 00001241 _____ C:\Users\OLYNT\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2013-11-29 00:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-11-29 00:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-29 00:47 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-29 00:20 - 2013-10-29 02:17 - 00000000 ____D C:\Windows\SysWOW64\NV 2013-11-29 00:20 - 2013-10-29 02:17 - 00000000 ____D C:\Windows\system32\NV 2013-11-28 23:51 - 2013-04-29 22:39 - 00000000 ____D C:\ProgramData\ScanSoft 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\ProductData 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\ProgramData\IObit 2013-11-28 23:38 - 2013-11-28 23:38 - 00000000 ____D C:\Program Files (x86)\IObit 2013-11-17 05:22 - 2011-09-02 03:55 - 00000000 ____D C:\Program Files (x86)\Intel 2013-11-17 05:21 - 2011-09-02 04:16 - 00000000 ____D C:\ProgramData\Intel 2013-11-17 05:21 - 2011-09-02 04:16 - 00000000 ____D C:\Program Files\Intel 2013-11-17 05:20 - 2013-11-17 05:20 - 00000000 ____D C:\Users\OLYNT\Intel 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-11-17 03:54 - 2013-11-17 03:54 - 00000000 ____D C:\Program Files\Realtek 2013-11-17 03:47 - 2013-11-17 03:47 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-11-17 02:53 - 2013-11-17 02:53 - 00003062 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00003060 _____ C:\Windows\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_dc3d_01011.Wdf 2013-11-17 02:52 - 2013-11-17 02:52 - 00000000 ____D C:\Program Files\Microsoft Mouse and Keyboard Center 2013-11-17 02:26 - 2013-11-17 02:26 - 00000000 ____D C:\Users\OLYNT\AppData\Roaming\Easeware 2013-11-17 01:33 - 2011-09-05 02:27 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-14 13:38 - 2013-05-02 12:27 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-11-14 13:38 - 2013-04-13 01:56 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-11-14 13:38 - 2013-04-13 01:56 - 00106904 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-11-14 13:38 - 2013-04-13 01:56 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-11-14 13:34 - 2013-06-12 12:09 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Adobe 2013-11-14 13:34 - 2012-04-04 16:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-14 13:34 - 2012-04-04 16:05 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-11-14 13:34 - 2012-03-15 23:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-14 13:28 - 2013-11-14 13:28 - 00000000 ____D C:\Users\OLYNT\AppData\Local\Software_Updater 2013-11-14 01:27 - 2012-02-10 02:06 - 00003704 _____ C:\Windows\System32\Tasks\Java Update Scheduler 2013-11-07 01:52 - 2013-11-07 01:52 - 13031424 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 12617216 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 11176448 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 10812928 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 09007616 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 05904856 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 05363200 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys 2013-11-07 01:52 - 2013-11-07 01:52 - 00515544 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00442880 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00442328 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00410624 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00399832 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00384512 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc 2013-11-07 01:52 - 2013-11-07 01:52 - 00279000 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00254936 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00185816 _____ (Intel Corporation) C:\Windows\system32\difx64.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00171992 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe 2013-11-07 01:52 - 2013-11-07 01:52 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl 2013-11-07 01:52 - 2013-11-07 01:52 - 00116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v3347.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00110592 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00098304 _____ C:\Windows\system32\igdde64.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00077312 _____ C:\Windows\SysWOW64\igdde32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00064000 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll 2013-11-07 01:52 - 2013-11-07 01:52 - 00017058 _____ C:\Windows\system32\iglhxs64.vp 2013-11-07 01:52 - 2013-11-07 01:52 - 00009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll 2013-11-07 01:52 - 2012-03-19 22:26 - 11049472 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll 2013-11-07 01:52 - 2011-09-02 03:57 - 12859392 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll Some content of TEMP: ==================== C:\Users\OLYNT\AppData\Local\Temp\avgnt.exe C:\Users\OLYNT\AppData\Local\Temp\mfc80.dll C:\Users\OLYNT\AppData\Local\Temp\mfc80u.dll C:\Users\OLYNT\AppData\Local\Temp\mfcm80.dll C:\Users\OLYNT\AppData\Local\Temp\mfcm80u.dll C:\Users\OLYNT\AppData\Local\Temp\msvcm80.dll C:\Users\OLYNT\AppData\Local\Temp\msvcp80.dll C:\Users\OLYNT\AppData\Local\Temp\msvcr80.dll C:\Users\OLYNT\AppData\Local\Temp\Quarantine.exe C:\Users\OLYNT\AppData\Local\Temp\SkypeSetup.exe C:\Users\OLYNT\AppData\Local\Temp\Uninstaller.exe C:\Users\OLYNT\AppData\Local\Temp\UninstallerGer.dll C:\Users\OLYNT\AppData\Local\Temp\WtgDriverInstallX.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-14 22:32 ==================== End Of Log ============================ --- --- --- ...ach ja... 'ne Addition habe ich vorhin auch gemacht... poste ich 'mal ungefragt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-11-2013 Ran by OLYNT at 2013-12-01 20:19:45 Running from D:\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Acronis*True*Image*Home 2011 (x32 Version: 14.0.6942) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152) Adobe Shockwave Player 12.0 (x32 Version: 12.0.6.147) ALPS Touch Pad Driver (Version: 8.201.1711.120) Ashampoo Burning Studio 11 v.11.0.2 (x32 Version: 11.0.2) ASIO4ALL (x32 Version: 2.10) Avira Internet Security (x32 Version: 14.0.1.749) Brother BRAdmin Light 1.21.0001 (x32 Version: 1.21.0001) Brother Driver Deployment Wizard (x32 Version: 1.09.000) Brother MFL-Pro Suite MFC-J5910DW (x32 Version: 1.0.5.0) ChiconyCam (x32 Version: 1.0.36.913) dm-Fotowelt (x32 Version: 5.0.4) Dropbox (HKCU Version: 2.0.22) EASEUS Partition Master 9.1.1 Home Edition (x32) Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.27.0) Foxit Reader (x32 Version: 6.0.2.413) Free Studio version 2013 (x32 Version: 6.1.12.925) FreeRIP MP3 Converter 4.4.1 (x32 Version: 4.4.1) GeForce Experience NvStream Client Components (Version: 1.6.28) Hard Disk Low Level Format Tool 4.12 (x32) Hotkey 3.3023 (x32 Version: 3.3023) ICQ 8.0 (build 6003, für aktuellen Benutzer) (HKCU Version: 8.0.6003.0) ICQ7.6 (x32 Version: 7.6) Intel(R) Management Engine Components (x32 Version: 9.5.3.1520) Intel(R) Processor Graphics (x32 Version: 9.17.10.3347) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016) Intel® PROSet/Wireless Software (x32 Version: 16.1.1) Intel® Trusted Connect Service Client (Version: 1.27.798.1) Intel® Watchdog Timer Driver (Intel® WDT) (x32) IObit Uninstaller (x32 Version: 3.0.4.922) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.33.3) JMicron Flash Media Controller Driver (x32 Version: 1.0.54.1) Logitech Gaming Software (Version: 8.45.88) Logitech Gaming Software 8.50 (Version: 8.50.281) MAGIX Music Maker MX Premium (x32 Version: 18.0.0.42) MAGIX Music Maker MX Premium Update (Version: 18.0.4.1) MAGIX Music Maker MX Premium Update (x32 Version: 18.0.3.0) MAGIX Screenshare (x32 Version: 4.3.6.1987) MAGIX Speed burnR (MSI) (x32 Version: 7.0.2.6) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938) Microsoft Mouse and Keyboard Center (Version: 2.2.173.0) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1) Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) Mozilla Thunderbird 24.0.1 (x86 de) (x32 Version: 24.0.1) Mp3tag v2.58 (x32 Version: v2.58) MSVC80_x64_v2 (Version: 1.0.3.0) MSVC80_x86_v2 (x32 Version: 1.0.3.0) MSVC90_x64 (Version: 1.0.1.2) MSVC90_x86 (x32 Version: 1.0.1.2) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) Netzmanager (Version: 1.071) Netzmanager (x32 Version: 1.071) NirSoft BlueScreenView (x32) Nokia Connectivity Cable Driver (x32 Version: 7.1.172.0) Nokia Suite (x32 Version: 3.8.48.0) NVIDIA GeForce Experience 1.7 (Version: 1.7) NVIDIA Grafiktreiber 331.65 (Version: 331.65) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA Optimus 9.3.16 (Version: 9.3.16) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16) NVIDIA Systemsteuerung 331.65 (Version: 331.65) NVIDIA Update 9.3.16 (Version: 9.3.16) NVIDIA Update Components (Version: 9.3.16) NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9) Paint.NET v3.5.10 (Version: 3.60.0) Pando Media Booster (x32 Version: 2.6.0.7) PC Connectivity Solution (x32 Version: 12.0.109.0) PDFCreator (x32 Version: 1.6.2) Realtek High Definition Audio Driver (x32 Version: 6.0.1.7071) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.39.0) SHIELD Streaming (Version: 1.6.34) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.11 (x32 Version: 6.11.102) Synaptics Pointing Device Driver (Version: 15.0.8.0) System Requirements Lab (x32) System Requirements Lab for Intel (x32 Version: 4.5.15.0) TeamSpeak 3 Client (x32 Version: 3.0.6) TeamViewer 8 (x32 Version: 8.0.18051) Text-To-Speech-Runtime (x32 Version: 1.0.0.0) THX TruStudio Pro (x32 Version: TAMB-CVS1D-1-LB R07) TomTom HOME (x32 Version: 2.9.6) TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2) TuneUp Utilities 2012 (x32 Version: 12.0.3600.129) TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.129) Unity Web Player (HKCU Version: ) Unlocker 1.9.1-x64 (Version: 1.9.1) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2598290) 32-Bit Edition (x32) Update for Zip Opener (HKCU) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VLC media player 2.0.6 (Version: 2.0.6) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0) Yahoo! Messenger (x32) Z-defragRAM (x32 Version: 2.7) ==================== Restore Points ========================= 29-11-2013 02:53:59 vor HiJackThis 30-11-2013 22:14:37 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {2BE2F70C-CAA9-4190-A92A-741DE2A42335} - System32\Tasks\{ACA804A1-2A77-4D17-92B7-00364125955F} => D:\Downloads\Xpadder(1).exe Task: {2E3D543F-702F-423F-BBCF-D6CB46F2CDC6} - \Software Updater Ui No Task File Task: {395C6845-0179-4DBC-BD04-30D41060575B} - System32\Tasks\{FAA5FB71-F4F6-4F0C-B7CE-3685ECEAF6B4} => P:\Xpadder(1).exe [2012-07-21] () Task: {4DBBBA45-A2C7-41AC-A944-5D2FCD94042B} - System32\Tasks\{9ED9E1ED-59C4-4213-A776-15A008EF7CE6} => Firefox.exe hxxp://ui.skype.com/ui/0/5.5.0.124.259/de/abandoninstall?source=lightinstaller&page=tsProblems&LastError=12002&installinfo=google-toolbar:notoffered;notincluded,google-chrome:notoffered;disabled Task: {735B74B9-1E5B-4BFF-956A-B75B3A3F262C} - System32\Tasks\{3EEF37EF-7900-4BDE-B59A-C2923D3AE59D} => Firefox.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.5.0.124.259&LastError=12002 Task: {79BA2AFD-2C4B-4291-9A5D-94FAB064E7D9} - System32\Tasks\Google Updater and Installer => C:\Users\OLYNT\AppData\Local\Google\Update\GoogleUpdate.exe Task: {7BD27B3E-366F-45F1-B98D-43C5FB44C056} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => P:\TuneUp Utilities 2012\OneClick.exe [2013-10-17] (TuneUp Software) Task: {7CF6FBA5-5AB4-40AD-BCC3-DFC57C5D2D14} - \Software Updater No Task File Task: {83247E88-7F60-49C3-83AE-3A1CD92528F3} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation) Task: {A6E8F11A-10EA-427C-8958-FDB797D1B37C} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe Task: {B407F380-8338-4977-AF88-370E15B7A5C7} - System32\Tasks\{D57A2F05-F991-450D-9271-6F4610AE8183} => P:\ultrachord\ultraChord.exe [2013-02-10] () Task: {B4F623F5-5992-4412-8116-0A3AAEE6A532} - \FreeDriverScout No Task File Task: {B9EB0A9B-93D1-4245-9D31-D29AF77362DA} - System32\Tasks\{CADB9278-FBBE-4491-97CA-63BC5A2B197E} => P:\ultrachord\ultraChord.exe [2013-02-10] () Task: {BE84A311-DE3E-4B5C-AD7E-4166365A6AEA} - System32\Tasks\{645622BC-C9CA-466C-86C9-1886CC8446CA} => Firefox.exe hxxp://ui.skype.com/ui/0/6.3.0.107/de/abandoninstall?page=tsProgressBar Task: {C25C2C5A-D317-45E1-8DCC-3808ED8A1C42} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation) Task: {CA10141D-9792-4562-84D8-6213187C010D} - System32\Tasks\{5D405EF0-9E62-4A93-B7F5-05491543ACC3} => P:\ultrachord\ultraChord.exe [2013-02-10] () Task: {FA392611-764C-4FD4-AC61-E7819DD7EACE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-14] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2011-09-02 03:57 - 2010-11-28 13:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-07-15 05:44 - 2010-07-15 05:44 - 00020032 _____ () P:\Unlocker\UnlockerCOM.dll 2013-02-06 03:12 - 2013-02-06 03:05 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2011-09-02 04:20 - 2010-11-01 16:34 - 00159744 ____N () C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\de-DE\THXAudio.resources.dll 2013-10-10 04:01 - 2013-05-09 03:23 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= Error: (07/08/2012 09:37:20 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1485 seconds with 660 seconds of active time. This session ended with a crash. Error: (03/04/2012 04:01:10 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 190 seconds with 180 seconds of active time. This session ended with a crash. Error: (02/17/2012 10:24:47 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6652.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 178 seconds with 120 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 24% Total physical RAM: 8106.17 MB Available physical RAM: 6088.06 MB Total Pagefile: 20263.35 MB Available Pagefile: 18150.53 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:60 GB) (Free:16.91 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Daten) (Fixed) (Total:538.64 GB) (Free:337.95 GB) NTFS Drive p: (Programme) (Fixed) (Total:100 GB) (Free:78.1 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 76C8CFBD) Partition 1: (Active) - (Size=60 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=639 GB) - (Type=05) ==================== End Of Log ============================ Zustand ist jedenfalls unverändert! Immer noch diese leeren Static-Seiten, manchmal diese Seiten mit dem leeren Rahmen (und "Skip"-Button) und der E-Mail-Schutz von Avira geht auch immer noch nicht! Ich warte einfach 'mal ab, was Du als nächstes vorschlägst! Danke für die Hilfe! LG olynt |
02.12.2013, 11:46 | #6 |
/// the machine /// TB-Ausbilder | Problem: http://static.icmapp.com/blank.html# etc. Avira neu installieren. In welchem Browser hast du die Probleme?
__________________ --> Problem: http://static.icmapp.com/blank.html# etc. |
03.12.2013, 00:08 | #7 |
| Problem: http://static.icmapp.com/blank.html# etc. Okay! Werde ich neu installieren! Ich habe die Probleme bei Firefox! Das ist mein Standard-Browser! Beim IE scheinen die Probleme nicht zu bestehen... Edit: So! ...habe ich neu nstalliert! Scheint wieder problemlos zu laufen... Dazu musste ichh allerdings Malwarebytes deinstallieren! Ist das normal? Jetzt muss ich erst 'mal zur Arbeit! Ich schaue dann heute Abend wieder rein... ich hoffe, dass ich diesen Mist mit dem Browser auch wieder los werde... Hi Schrauber! PROBLEM VERSCHWUNDEN!!! ...ich kapier's zwar nicht so ganz.... Aber mit der Neuinstallation von Avira ist auch das Browser-Problem nun Vergangenheit! Heißt das, dass sich der "Schädling" in irgendeiner Avira-Datei eingenistet hatte??? :O :O Weißt Du, ob ich Malwarebytes wieder installieren kann? Oder beißt sich das generell mit Avira? Obwohl ich keine Ahnung habe, was genau von Deinen Tipps mir nun letztendlich geholfen hat (ich tippe auf JRT und Neuinstallation von Avira): HERZLICHEN DANK!!! :-X Liebe Grüße olynt Geändert von olynt (02.12.2013 um 13:15 Uhr) |
03.12.2013, 12:36 | #8 |
/// the machine /// TB-Ausbilder | Problem: http://static.icmapp.com/blank.html# etc. Kannste nochmal installieren. Ich denke eher das verbogene Antivir hat da was geblockt. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.12.2013, 02:26 | #9 | ||
| Problem: http://static.icmapp.com/blank.html# etc. Hi Schrauber! Das ist ja ein ganz schön langer Schlauch, was Du da alles vorschlägst!!! Zitat:
Delfix: Code:
ATTFilter # DelFix v10.6 - Datei am 03/12/2013 um 23:26:15 erstellt # Aktualisiert am 11/11/2013 von Xplode # Benutzer : OLYNT - OLYNT-PC # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) ~ Aktiviere die Benutzerkontensteuerung ... OK ~ Entferne die Bereinigungsprogramme ... Gelöscht : C:\FRST Gelöscht : C:\AdwCleaner Gelöscht : D:\Desktop\Addition.txt Gelöscht : D:\Desktop\AdwCleaner[S0].txt Gelöscht : D:\Desktop\FRST.txt Gelöscht : D:\Desktop\FRST64.exe Gelöscht : D:\Desktop\JRT.exe Gelöscht : D:\Desktop\JRT.txt Gelöscht : D:\Desktop\hijackthis.log Gelöscht : HKLM\SOFTWARE\AdwCleaner Gelöscht : HKLM\SOFTWARE\TrendMicro\Hijackthis ~ Erstelle ein Backup der Registrierungsdatenbank ... OK ~ Lösche die Wiederherstellungspunkte ... Ein neuer Wiederherstellungspunkt wurde erstellt ! ~ Stelle die Systemeinstellungen wieder her ... OK ########## - EOF - ########## Zitat:
Nochmals vielen Dank! Liebe Grüße olynt |
04.12.2013, 12:02 | #10 | |
/// the machine /// TB-Ausbilder | Problem: http://static.icmapp.com/blank.html# etc.Zitat:
In dem Fall aber Fehlfunktion. TFC ruhig einmal die Woche. Registry Cleaner und Tuning Programme werden grundsätzlich von abgeraten. Richten mehr Schaden an als das sie gutes tun. Der angebliche Performancegewinn ist ein Witz.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Problem: http://static.icmapp.com/blank.html# etc. |
administrator, adobe, adware, antivir, avg, avira, bho, desktop, email, explorer, fehlermeldung, firefox, firewall, flash player, freemium, google, hijack, hijackthis, home, http://static.icmapp.com/, internet, internet explorer, leere fenster, malware, mozilla, nvidia, object, ohne befund, problem, recover, registrierungsdatenbank, security, software |