Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 03.12.2013, 12:59   #1
aule
 
ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E - Standard

ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E



Hallo,

ich kriege es nicht hin ein Virus zu entfernen. Avira sagt mir dass ich wohl einen Virus habe: C:\ProgramDate\BitGuard\2.7.1832.68\..\loader.dll . Wenn ich auf entfernen klicke sucht er mir alles durch. Dann sagt er mir dass er Sachen in Quarantäne schieben möchte und dann stürzt der PC ab bzw. fährt aus Sicherheitsgründen runter. Hab in anderen Foren gelesen dass ich Farbar Recovery Scan Tool FRST64 runterladen soll und scan machen. Das habe ich nun getan und ich hoffe ihr könnt mir helfen.
Vielen Dank im Voraus.
Hier der Log Bericht von FRST64

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2013
Ran by Marc at 2013-12-03 12:45:36
Running from C:\Users\Marc\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

7-Zip 9.20 (x32)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Reader X (10.1.2) - Deutsch (x32 Version: 10.1.2)
ANNO 1404 (x32 Version: 1.00.0000)
Anno 1404 (x32 Version: 1.00.0000)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.2.43)
Atheros Driver Installation Program (x32 Version: 9.0)
Audiobook Cutter Free Edition (x32 Version: 1.8.3)
Avira Free Antivirus (x32 Version: 14.0.1.759)
BitGuard (x32)
Broadcom 802.11 Network Adapter (Version: 5.100.82.63)
Cisco EAP-FAST Module (x32 Version: 2.2.14)
Cisco LEAP Module (x32 Version: 1.0.19)
Cisco PEAP Module (x32 Version: 1.1.6)
DAEMON Tools Lite (x32 Version: 4.47.1.0333)
EASEUS Partition Master 9.1.0 Home Edition (x32)
EPSON WF-2530 Series Printer Uninstall
Google Chrome (HKCU Version: 31.0.1650.57)
Intel PROSet Wireless
Intel PROSet Wireless (x32)
Intel(R) Management Engine Components (x32 Version: 6.0.0.1179)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2372)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.01.1000)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Launch Manager (x32 Version: 5.1.7)
MATLAB Family of Products Release 14 (x32)
MATLAB R2013a (Version: 8.1)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
NVIDIA PhysX (x32 Version: 9.10.0514)
PDFCreator (x32 Version: 1.3.0)
R for Windows 3.0.2 (Version: 3.0.2)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6392)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127)
REALTEK Wireless LAN Driver (x32 Version: 1.00.10.0909)
Skype™ 6.7 (x32 Version: 6.7.102)
SopCast 3.5.0 (x32 Version: 3.5.0)
Synaptics Pointing Device Driver (Version: 15.2.17.5)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Verbindungsassistent (x32 Version: 2.1)
VLC media player 2.0.1 (Version: 2.0.1)
Winamp (x32 Version: 5.623 )
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1)
WinRAR 4.11 (64-Bit) (Version: 4.11.0)

==================== Restore Points  =========================

17-11-2013 23:43:23 Windows Update
25-11-2013 16:56:54 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {3B26EE78-8B76-4008-91E6-2D054893FA86} - System32\Tasks\EPUpdater => C:\Users\Marc\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] ()
Task: {4BC41C6E-FF6E-44CE-A3CD-4AEC80163564} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe
Task: {531AB624-41EF-4B5D-9AF8-A0E59E80FE62} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: {7EA05544-939D-4375-ACFA-DB52A445DD35} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect
Task: {A4E19F1B-CBB5-45F1-93D7-6CDC690AD187} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000Core => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-27] (Google Inc.)
Task: {D586D1E7-DC9B-4FDC-BAD2-BD99A3192102} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe
Task: {F2DD4709-EDA1-4DC0-9FAD-19C0514F02B6} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-27] (Google Inc.)
Task: {F7CFE739-7CD7-4C1B-86B8-ADCB78FC3319} - System32\Tasks\BitGuard => Sc.exe start BitGuard
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000Core1cec45b6f82e49b.job => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA.job => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-11-22 13:03 - 2013-11-18 15:32 - 01958880 _____ () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll
2012-05-30 16:45 - 2012-02-17 19:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll
2012-03-10 20:27 - 2011-04-15 03:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-05-02 13:41 - 2011-05-02 13:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2013-03-26 19:16 - 2013-03-26 19:07 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-11-15 14:51 - 2013-11-14 12:28 - 00702416 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-15 14:51 - 2013-11-14 12:28 - 00099792 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-15 14:51 - 2013-11-14 12:29 - 04055504 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-15 14:51 - 2013-11-14 12:29 - 00399312 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-15 14:51 - 2013-11-14 12:28 - 01619408 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-15 14:51 - 2013-11-14 12:29 - 13582800 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/29/2013 10:53:46 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (11/27/2013 05:08:14 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (11/25/2013 06:54:07 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (11/25/2013 05:53:26 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (11/23/2013 00:34:37 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig.

Error: (10/27/2013 02:12:17 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: matlab.exe, Version: 1.0.0.1, Zeitstempel: 0x511f0e56
Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0017966f
ID des fehlerhaften Prozesses: 0xcbc
Startzeit der fehlerhaften Anwendung: 0xmatlab.exe0
Pfad der fehlerhaften Anwendung: matlab.exe1
Pfad des fehlerhaften Moduls: matlab.exe2
Berichtskennung: matlab.exe3

Error: (10/25/2013 10:57:03 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: matlab.exe, Version: 1.0.0.1, Zeitstempel: 0x511f0e56
Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0017966f
ID des fehlerhaften Prozesses: 0xc20
Startzeit der fehlerhaften Anwendung: 0xmatlab.exe0
Pfad der fehlerhaften Anwendung: matlab.exe1
Pfad des fehlerhaften Moduls: matlab.exe2
Berichtskennung: matlab.exe3

Error: (10/24/2013 08:40:38 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 10.1.2.45, Zeitstempel: 0x4f02e382
Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0017966f
ID des fehlerhaften Prozesses: 0x804
Startzeit der fehlerhaften Anwendung: 0xAcroRd32.exe0
Pfad der fehlerhaften Anwendung: AcroRd32.exe1
Pfad des fehlerhaften Moduls: AcroRd32.exe2
Berichtskennung: AcroRd32.exe3

Error: (10/24/2013 08:22:44 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: matlab.exe, Version: 1.0.0.1, Zeitstempel: 0x511f0e56
Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0017966f
ID des fehlerhaften Prozesses: 0x660
Startzeit der fehlerhaften Anwendung: 0xmatlab.exe0
Pfad der fehlerhaften Anwendung: matlab.exe1
Pfad des fehlerhaften Moduls: matlab.exe2
Berichtskennung: matlab.exe3

Error: (10/24/2013 08:22:43 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: WerFault.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc2d9
Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0017966f
ID des fehlerhaften Prozesses: 0x12ec
Startzeit der fehlerhaften Anwendung: 0xWerFault.exe0
Pfad der fehlerhaften Anwendung: WerFault.exe1
Pfad des fehlerhaften Moduls: WerFault.exe2
Berichtskennung: WerFault.exe3


System errors:
=============
Error: (12/03/2013 00:34:36 PM) (Source: BugCheck) (User: )
Description: 0x000000f4 (0x0000000000000003, 0xfffffa8007009040, 0xfffffa8007009320, 0xfffff800033c87b0)C:\Windows\MEMORY.DMP120313-20358-01

Error: (12/03/2013 00:34:23 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎03.‎12.‎2013 um 12:33:12 unerwartet heruntergefahren.

Error: (12/03/2013 00:29:31 PM) (Source: BugCheck) (User: )
Description: 0x000000f4 (0x0000000000000003, 0xfffffa80070967f0, 0xfffffa8007096ad0, 0xfffff800033cf7b0)C:\Windows\MEMORY.DMP120313-21902-01

Error: (12/03/2013 00:29:19 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎03.‎12.‎2013 um 12:21:33 unerwartet heruntergefahren.

Error: (12/03/2013 00:18:52 PM) (Source: BugCheck) (User: )
Description: 0x000000f4 (0x0000000000000003, 0xfffffa8006fa6b30, 0xfffffa8006fa6e10, 0xfffff8000337a7b0)C:\Windows\MEMORY.DMP120313-29967-01

Error: (12/03/2013 00:18:38 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎03.‎12.‎2013 um 12:17:28 unerwartet heruntergefahren.

Error: (12/03/2013 00:13:51 PM) (Source: BugCheck) (User: )
Description: 0x000000f4 (0x0000000000000003, 0xfffffa8006d7fb30, 0xfffffa8006d7fe10, 0xfffff800033847b0)C:\Windows\MEMORY.DMP120313-21060-01

Error: (12/03/2013 00:13:36 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎03.‎12.‎2013 um 12:12:11 unerwartet heruntergefahren.

Error: (11/23/2013 06:30:08 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ARCOR",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{976DFCD2-2CD9-4266-A518-1D17600A413F}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (11/23/2013 11:22:13 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am ‎23.‎11.‎2013 um 01:46:55 unerwartet heruntergefahren.


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Percentage of memory in use: 44%
Total physical RAM: 3764.86 MB
Available physical RAM: 2108.12 MB
Total Pagefile: 7527.9 MB
Available Pagefile: 5308.73 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:234.77 GB) (Free:173.3 GB) NTFS
Drive e: () (Fixed) (Total:230.89 GB) (Free:133.01 GB) NTFS
Drive g: (Matlab 8.01 (R20) (CDROM) (Total:5.63 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: EA121F62)
Partition 1: (Not Active) - (Size=235 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=231 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
und der zweite log

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013
Ran by Marc (administrator) on MARC-PC on 03-12-2013 12:44:20
Running from C:\Users\Marc\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-28] (Synaptics Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Userinit] - C:\Users\Marc\AppData\Roaming\appConf32.exe
HKCU\...\Run: [Google Update] - C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-08-27] (Google Inc.)
HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
MountPoints2: {2b671cdd-69c1-11e1-8f2e-806e6f6e6963} - F:\DistinguishOS.exe
MountPoints2: {9fbd2edf-22fe-11e3-824b-386077e5a823} - D:\HTC_Sync_Manager_PC.exe
MountPoints2: {ca5daf6b-de2f-11e1-9468-386077e5a823} - D:\.\Autorun.exe AUTORUN=1
MountPoints2: {dc8e2a3d-be1f-11e2-865c-386077e5a823} - G:\setup.exe
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-27] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll [1958880 2013-11-18] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?affID=121562&tt=gc_&babsrc=HP_ss_din2g&mntrId=B2C716DE2B93552A
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5EE12861C7FFCC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = 
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000
SearchScopes: HKCU - {09743295-742C-4EE0-BC49-A2F064AF5616} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://isearch.babylon.com/?q={searchTerms}&affID=121562&tt=gc_&babsrc=SP_ssbtis1&mntrId=B2C716DE2B93552A
SearchScopes: HKCU - {34235501-5F82-42FA-82CF-150ED17D6321} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}
SearchScopes: HKCU - {3F19D13F-9CAF-4CFA-A8A8-331E2D273EB9} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKCU - {8FDE0F91-580E-4A73-A571-2EA945271CB1} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

Chrome: 
=======
CHR Extension: (Google Wallet) - C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Marc\AppData\Roaming\BabSolution\CR\delta1.crx

==================== Services (Whitelisted) =================

R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-27] (Avira Operations GmbH & Co. KG)
R2 BitGuard; C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3780064 2013-11-18] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [329168 2010-02-23] ()
S4 matlabserver; C:\MATLAB7\webserver\bin\win32\matlabserver.exe [x]

==================== Drivers (Whitelisted) ====================

R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-09-04] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [107416 2013-12-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-27] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-16] (DT Soft Ltd)
S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] ()
S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] ()
S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] ()
S3 ewsercd; C:\Windows\System32\DRIVERS\ewsercd.sys [112896 2012-08-10] (Huawei Technologies Co., Ltd.)
S3 ewsercd; C:\Windows\SysWow64\DRIVERS\ewsercd.sys [112896 2012-08-10] (Huawei Technologies Co., Ltd.)
S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [116864 2008-12-13] (Huawei Technologies Co., Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-09-04] ()

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-03 12:44 - 2013-12-03 12:44 - 00011850 _____ C:\Users\Marc\Downloads\FRST.txt
2013-12-03 12:44 - 2013-12-03 12:44 - 00000000 ____D C:\FRST
2013-12-03 12:43 - 2013-12-03 12:43 - 01959434 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe
2013-12-03 12:34 - 2013-12-03 12:34 - 00262144 _____ C:\Windows\Minidump\120313-20358-01.dmp
2013-12-03 12:34 - 2013-12-03 12:34 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard
2013-12-03 12:29 - 2013-12-03 12:29 - 00262144 _____ C:\Windows\Minidump\120313-21902-01.dmp
2013-12-03 12:18 - 2013-12-03 12:18 - 00262144 _____ C:\Windows\Minidump\120313-29967-01.dmp
2013-12-03 12:13 - 2013-12-03 12:13 - 00262144 _____ C:\Windows\Minidump\120313-21060-01.dmp
2013-11-29 10:55 - 2013-11-29 10:56 - 141602366 _____ C:\Users\Marc\Downloads\30-11-80 - Sido.zip
2013-11-26 21:39 - 2013-11-27 19:17 - 00000087 _____ C:\Users\Marc\Desktop\leibnitz.m
2013-11-25 15:54 - 2013-11-25 15:25 - 00000000 ____D C:\Users\Marc\Desktop\VortraegeWS2013-14
2013-11-25 15:53 - 2013-11-25 15:54 - 23856602 _____ C:\Users\Marc\Downloads\VortraegeWS2013-14_25-11-13_15.27.zip
2013-11-22 19:29 - 2013-11-22 19:29 - 105757824 _____ C:\Windows\SysWOW64\悶癗L
2013-11-22 13:03 - 2013-11-22 13:03 - 00000000 ____D C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-11-22 12:37 - 2013-11-22 12:37 - 00052736 _____ C:\Users\Marc\Downloads\Aufg4_5_22-11-13_8.39.xls
2013-11-21 21:55 - 2013-11-21 21:55 - 105611834 _____ C:\Windows\SysWOW64\䄼꠴Œ
2013-11-20 12:44 - 2013-11-20 12:56 - 00000111 _____ C:\Users\Marc\Desktop\test1.m
2013-11-18 07:39 - 2013-11-18 07:39 - 104837737 _____ C:\Windows\SysWOW64\ṕ젅–
2013-11-18 00:47 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-18 00:47 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-18 00:47 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-18 00:47 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-18 00:47 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-11-18 00:47 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-11-18 00:47 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-11-18 00:47 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-18 00:47 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-11-18 00:47 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-18 00:47 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-11-18 00:46 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-18 00:46 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-18 00:46 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-18 00:46 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-11-18 00:46 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-11-13 16:30 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-13 16:30 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-13 16:30 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-13 16:30 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2013-11-13 16:30 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2013-11-13 16:30 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-13 16:30 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-11-13 16:30 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 16:30 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2013-11-13 16:30 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2013-11-13 16:30 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
2013-11-13 16:30 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-11-13 16:30 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll
2013-11-13 16:30 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-13 16:30 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-11-13 16:30 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-13 16:30 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 16:30 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 16:30 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-13 16:30 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-13 16:30 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-13 16:30 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-13 16:30 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-13 16:30 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-13 16:30 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-11-13 16:30 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-11-13 16:30 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-11-13 16:30 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2013-11-13 16:30 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-13 16:30 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2013-11-10 16:21 - 2013-11-10 16:21 - 00005953 _____ C:\Users\Marc\Downloads\353654985_Umsatzliste (1).csv
2013-11-10 14:42 - 2013-11-26 21:41 - 00000070 _____ C:\Users\Marc\Desktop\geo.m
2013-11-06 17:32 - 2013-11-12 22:45 - 103974937 _____ C:\Windows\SysWOW64\ⲛW

==================== One Month Modified Files and Folders =======

2013-12-03 12:44 - 2013-12-03 12:44 - 00011850 _____ C:\Users\Marc\Downloads\FRST.txt
2013-12-03 12:44 - 2013-12-03 12:44 - 00000000 ____D C:\FRST
2013-12-03 12:43 - 2013-12-03 12:43 - 01959434 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe
2013-12-03 12:42 - 2009-07-14 05:45 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-03 12:42 - 2009-07-14 05:45 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-03 12:39 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat
2013-12-03 12:39 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat
2013-12-03 12:39 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-03 12:38 - 2012-03-09 09:26 - 01414675 _____ C:\Windows\WindowsUpdate.log
2013-12-03 12:34 - 2013-12-03 12:34 - 00262144 _____ C:\Windows\Minidump\120313-20358-01.dmp
2013-12-03 12:34 - 2013-12-03 12:34 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard
2013-12-03 12:34 - 2012-08-04 13:24 - 434162977 _____ C:\Windows\MEMORY.DMP
2013-12-03 12:34 - 2012-08-04 13:24 - 00000000 ____D C:\Windows\Minidump
2013-12-03 12:34 - 2012-07-31 17:23 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-12-03 12:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-03 12:34 - 2009-07-14 05:51 - 00093462 _____ C:\Windows\setupact.log
2013-12-03 12:33 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-03 12:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing
2013-12-03 12:29 - 2013-12-03 12:29 - 00262144 _____ C:\Windows\Minidump\120313-21902-01.dmp
2013-12-03 12:21 - 2012-04-04 09:35 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-03 12:18 - 2013-12-03 12:18 - 00262144 _____ C:\Windows\Minidump\120313-29967-01.dmp
2013-12-03 12:16 - 2012-08-27 13:15 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA.job
2013-12-03 12:13 - 2013-12-03 12:13 - 00262144 _____ C:\Windows\Minidump\120313-21060-01.dmp
2013-12-03 12:08 - 2013-04-03 13:33 - 00107416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-29 10:56 - 2013-11-29 10:55 - 141602366 _____ C:\Users\Marc\Downloads\30-11-80 - Sido.zip
2013-11-27 19:17 - 2013-11-26 21:39 - 00000087 _____ C:\Users\Marc\Desktop\leibnitz.m
2013-11-27 18:44 - 2013-04-09 22:08 - 00000000 ____D C:\Users\Marc\Documents\MATLAB
2013-11-27 15:05 - 2013-10-14 14:09 - 00000000 ____D C:\Users\Marc\Desktop\Monte Carlo
2013-11-27 09:16 - 2013-05-08 16:37 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-27 09:16 - 2013-04-03 13:33 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-27 09:16 - 2013-04-03 13:33 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-26 21:41 - 2013-11-10 14:42 - 00000070 _____ C:\Users\Marc\Desktop\geo.m
2013-11-25 15:54 - 2013-11-25 15:53 - 23856602 _____ C:\Users\Marc\Downloads\VortraegeWS2013-14_25-11-13_15.27.zip
2013-11-25 15:25 - 2013-11-25 15:54 - 00000000 ____D C:\Users\Marc\Desktop\VortraegeWS2013-14
2013-11-23 14:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-11-23 11:21 - 2013-09-16 09:51 - 00000000 ____D C:\ProgramData\BitGuard
2013-11-23 11:21 - 2012-03-14 07:12 - 00139584 _____ C:\Windows\PFRO.log
2013-11-22 19:29 - 2013-11-22 19:29 - 105757824 _____ C:\Windows\SysWOW64\悶癗L
2013-11-22 13:03 - 2013-11-22 13:03 - 00000000 ____D C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2013-11-22 12:37 - 2013-11-22 12:37 - 00052736 _____ C:\Users\Marc\Downloads\Aufg4_5_22-11-13_8.39.xls
2013-11-21 21:55 - 2013-11-21 21:55 - 105611834 _____ C:\Windows\SysWOW64\䄼꠴Œ
2013-11-20 12:56 - 2013-11-20 12:44 - 00000111 _____ C:\Users\Marc\Desktop\test1.m
2013-11-18 07:39 - 2013-11-18 07:39 - 104837737 _____ C:\Windows\SysWOW64\ṕ젅–
2013-11-18 00:46 - 2013-07-16 11:38 - 00000000 ____D C:\Windows\system32\MRT
2013-11-18 00:44 - 2013-05-20 19:29 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-11-12 22:45 - 2013-11-06 17:32 - 103974937 _____ C:\Windows\SysWOW64\ⲛW
2013-11-11 14:54 - 2012-04-22 20:08 - 00000000 ____D C:\Users\Marc\AppData\Roaming\Winamp
2013-11-10 16:21 - 2013-11-10 16:21 - 00005953 _____ C:\Users\Marc\Downloads\353654985_Umsatzliste (1).csv
2013-11-08 16:03 - 2013-10-14 14:05 - 00000000 ____D C:\Users\Marc\Desktop\Ökonometrie

Some content of TEMP:
====================
C:\Users\Marc\AppData\Local\Temp\AskSLib.dll
C:\Users\Marc\AppData\Local\Temp\avgnt.exe
C:\Users\Marc\AppData\Local\Temp\IPx64_1031.exe
C:\Users\Marc\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
C:\Users\Marc\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe
C:\Users\Marc\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Marc\AppData\Local\Temp\ose00000.exe
C:\Users\Marc\AppData\Local\Temp\ubiA515.tmp.exe
C:\Users\Marc\AppData\Local\Temp\uninst1.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-30 07:58

==================== End Of Log ============================
         
Gruß Marc

 

Themen zu ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E
adapter, administrator, adware/bprotector.e, antivirus, avira, computer, defender, desktop, device driver, excel, explorer, fehler, flash player, home, installation, log, memory.dmp, minidump, monte, opera, registry, richtlinie, scan, security, services.exe, svchost.exe, system, usb, virus, windows, winlogon.exe




Ähnliche Themen: ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E


  1. Viren (APPL/RedCap (Cloud), SPR/Agent.dkb, TR/Drop.Rotbrow.K.1, ADWARE/InstallCore.Gen7 und zweimal ADWARE/BHO.Bprotector.1.4).
    Plagegeister aller Art und deren Bekämpfung - 10.05.2015 (7)
  2. ADWARE/MultiPlug.aob, ADWARE/BProtector.C und Co. entfernen
    Log-Analyse und Auswertung - 26.09.2014 (11)
  3. TR/BProtector.Gen in C:\ProgramData\BitGuard\2.7.1832.68\{61d8b74e-8d89-46ff-afa6-33382 , nach "In Quarantäne verschieben" kommt Blue Screen
    Log-Analyse und Auswertung - 13.04.2014 (11)
  4. Anti Avira-Meldung TR/BProtector.Gen in Datei C:/ProgramData/Bitguard/2.7.1832.68/.../loader.dll
    Log-Analyse und Auswertung - 02.04.2014 (3)
  5. Was kann ich tun bei der Avira Meldung: C:\ProgramData\BitGuard\2.7.1832.68\...\loader.dll
    Plagegeister aller Art und deren Bekämpfung - 31.03.2014 (5)
  6. TR/BProtector.Gen in C:\ProgramData\Bitguard\... entfernen, bräuchte leicht verständliche Hilfe ohne Fachjargon
    Plagegeister aller Art und deren Bekämpfung - 30.03.2014 (4)
  7. C:/ProgramData/BitGuard/2.7.1832.68.../loader.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2014 (5)
  8. C:\ProgrammData/BitGuard\2.7.1832.68\...\loader.dll
    Plagegeister aller Art und deren Bekämpfung - 29.03.2014 (3)
  9. Windows, 8 Avira meldet 5 mal Befall: TR/BProtector.Gen in BitGuard.exe in Programmdata
    Log-Analyse und Auswertung - 31.01.2014 (17)
  10. ProgramDate\BitGuard\2.7.1832.68\..\loader.dll - ADWARE/BProtector.E
    Log-Analyse und Auswertung - 21.12.2013 (23)
  11. Avira springt an c:ProgramData/BitGuard/2.7.1832.68.../loader.dll
    Plagegeister aller Art und deren Bekämpfung - 19.12.2013 (11)
  12. Win7 x64 | Bitguard-Trojaner? - BProtector.F , BProtector.E , BHO.Bprotector.1.4
    Log-Analyse und Auswertung - 15.12.2013 (11)
  13. BitGuard / Adware/Bprotector.E
    Plagegeister aller Art und deren Bekämpfung - 09.12.2013 (12)
  14. ADWARE/BProtector.E
    Plagegeister aller Art und deren Bekämpfung - 08.12.2013 (43)
  15. Windows 7: Infektion mit Bitguard/BHO.Bprotector.1.4, Lizardlink und evtl. anderen Viren
    Log-Analyse und Auswertung - 05.12.2013 (13)
  16. C:\ProgramData\BitGuard\2.7.1832.68\...,ßoader.dll
    Log-Analyse und Auswertung - 03.12.2013 (5)
  17. PUP.Optional.BitGuard in C:\ProgramData\BitGuard\2.6.1673.238
    Log-Analyse und Auswertung - 03.11.2013 (10)

Zum Thema ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E - Hallo, ich kriege es nicht hin ein Virus zu entfernen. Avira sagt mir dass ich wohl einen Virus habe: C:\ProgramDate\BitGuard\2.7.1832.68\..\loader.dll . Wenn ich auf entfernen klicke sucht er mir alles - ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E...
Archiv
Du betrachtest: ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.