|
Plagegeister aller Art und deren Bekämpfung: ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.EWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.12.2013, 12:59 | #1 |
| ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E Hallo, ich kriege es nicht hin ein Virus zu entfernen. Avira sagt mir dass ich wohl einen Virus habe: C:\ProgramDate\BitGuard\2.7.1832.68\..\loader.dll . Wenn ich auf entfernen klicke sucht er mir alles durch. Dann sagt er mir dass er Sachen in Quarantäne schieben möchte und dann stürzt der PC ab bzw. fährt aus Sicherheitsgründen runter. Hab in anderen Foren gelesen dass ich Farbar Recovery Scan Tool FRST64 runterladen soll und scan machen. Das habe ich nun getan und ich hoffe ihr könnt mir helfen. Vielen Dank im Voraus. Hier der Log Bericht von FRST64 Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-12-2013 Ran by Marc at 2013-12-03 12:45:36 Running from C:\Users\Marc\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x32) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Reader X (10.1.2) - Deutsch (x32 Version: 10.1.2) ANNO 1404 (x32 Version: 1.00.0000) Anno 1404 (x32 Version: 1.00.0000) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.2.43) Atheros Driver Installation Program (x32 Version: 9.0) Audiobook Cutter Free Edition (x32 Version: 1.8.3) Avira Free Antivirus (x32 Version: 14.0.1.759) BitGuard (x32) Broadcom 802.11 Network Adapter (Version: 5.100.82.63) Cisco EAP-FAST Module (x32 Version: 2.2.14) Cisco LEAP Module (x32 Version: 1.0.19) Cisco PEAP Module (x32 Version: 1.1.6) DAEMON Tools Lite (x32 Version: 4.47.1.0333) EASEUS Partition Master 9.1.0 Home Edition (x32) EPSON WF-2530 Series Printer Uninstall Google Chrome (HKCU Version: 31.0.1650.57) Intel PROSet Wireless Intel PROSet Wireless (x32) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Processor Graphics (x32 Version: 8.15.10.2372) Intel(R) PROSet/Wireless WiFi-Software (Version: 14.01.1000) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Launch Manager (x32 Version: 5.1.7) MATLAB Family of Products Release 14 (x32) MATLAB R2013a (Version: 8.1) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Enterprise 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) NVIDIA PhysX (x32 Version: 9.10.0514) PDFCreator (x32 Version: 1.3.0) R for Windows 3.0.2 (Version: 3.0.2) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6392) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127) REALTEK Wireless LAN Driver (x32 Version: 1.00.10.0909) Skype™ 6.7 (x32 Version: 6.7.102) SopCast 3.5.0 (x32 Version: 3.5.0) Synaptics Pointing Device Driver (Version: 15.2.17.5) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Verbindungsassistent (x32 Version: 2.1) VLC media player 2.0.1 (Version: 2.0.1) Winamp (x32 Version: 5.623 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) WinRAR 4.11 (64-Bit) (Version: 4.11.0) ==================== Restore Points ========================= 17-11-2013 23:43:23 Windows Update 25-11-2013 16:56:54 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {3B26EE78-8B76-4008-91E6-2D054893FA86} - System32\Tasks\EPUpdater => C:\Users\Marc\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () Task: {4BC41C6E-FF6E-44CE-A3CD-4AEC80163564} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe Task: {531AB624-41EF-4B5D-9AF8-A0E59E80FE62} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: {7EA05544-939D-4375-ACFA-DB52A445DD35} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect Task: {A4E19F1B-CBB5-45F1-93D7-6CDC690AD187} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000Core => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-27] (Google Inc.) Task: {D586D1E7-DC9B-4FDC-BAD2-BD99A3192102} - System32\Tasks\AdobeFlashPlayerUpdate => C:\Windows\SysWOW64\FlashPlayerUpdateService.exe Task: {F2DD4709-EDA1-4DC0-9FAD-19C0514F02B6} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-27] (Google Inc.) Task: {F7CFE739-7CD7-4C1B-86B8-ADCB78FC3319} - System32\Tasks\BitGuard => Sc.exe start BitGuard Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000Core1cec45b6f82e49b.job => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA.job => C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-11-22 13:03 - 2013-11-18 15:32 - 01958880 _____ () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll 2012-05-30 16:45 - 2012-02-17 19:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2012-03-10 20:27 - 2011-04-15 03:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-05-02 13:41 - 2011-05-02 13:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2013-03-26 19:16 - 2013-03-26 19:07 - 00397704 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2013-11-15 14:51 - 2013-11-14 12:28 - 00702416 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\libglesv2.dll 2013-11-15 14:51 - 2013-11-14 12:28 - 00099792 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\libegl.dll 2013-11-15 14:51 - 2013-11-14 12:29 - 04055504 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll 2013-11-15 14:51 - 2013-11-14 12:29 - 00399312 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll 2013-11-15 14:51 - 2013-11-14 12:28 - 01619408 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll 2013-11-15 14:51 - 2013-11-14 12:29 - 13582800 _____ () C:\Users\Marc\AppData\Local\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/29/2013 10:53:46 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (11/27/2013 05:08:14 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (11/25/2013 06:54:07 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (11/25/2013 05:53:26 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (11/23/2013 00:34:37 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (10/27/2013 02:12:17 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: matlab.exe, Version: 1.0.0.1, Zeitstempel: 0x511f0e56 Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0017966f ID des fehlerhaften Prozesses: 0xcbc Startzeit der fehlerhaften Anwendung: 0xmatlab.exe0 Pfad der fehlerhaften Anwendung: matlab.exe1 Pfad des fehlerhaften Moduls: matlab.exe2 Berichtskennung: matlab.exe3 Error: (10/25/2013 10:57:03 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: matlab.exe, Version: 1.0.0.1, Zeitstempel: 0x511f0e56 Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0017966f ID des fehlerhaften Prozesses: 0xc20 Startzeit der fehlerhaften Anwendung: 0xmatlab.exe0 Pfad der fehlerhaften Anwendung: matlab.exe1 Pfad des fehlerhaften Moduls: matlab.exe2 Berichtskennung: matlab.exe3 Error: (10/24/2013 08:40:38 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: AcroRd32.exe, Version: 10.1.2.45, Zeitstempel: 0x4f02e382 Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0017966f ID des fehlerhaften Prozesses: 0x804 Startzeit der fehlerhaften Anwendung: 0xAcroRd32.exe0 Pfad der fehlerhaften Anwendung: AcroRd32.exe1 Pfad des fehlerhaften Moduls: AcroRd32.exe2 Berichtskennung: AcroRd32.exe3 Error: (10/24/2013 08:22:44 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: matlab.exe, Version: 1.0.0.1, Zeitstempel: 0x511f0e56 Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0017966f ID des fehlerhaften Prozesses: 0x660 Startzeit der fehlerhaften Anwendung: 0xmatlab.exe0 Pfad der fehlerhaften Anwendung: matlab.exe1 Pfad des fehlerhaften Moduls: matlab.exe2 Berichtskennung: matlab.exe3 Error: (10/24/2013 08:22:43 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: WerFault.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc2d9 Name des fehlerhaften Moduls: bitguard.dll, Version: 2.6.1694.246, Zeitstempel: 0x52402c3e Ausnahmecode: 0xc0000005 Fehleroffset: 0x0017966f ID des fehlerhaften Prozesses: 0x12ec Startzeit der fehlerhaften Anwendung: 0xWerFault.exe0 Pfad der fehlerhaften Anwendung: WerFault.exe1 Pfad des fehlerhaften Moduls: WerFault.exe2 Berichtskennung: WerFault.exe3 System errors: ============= Error: (12/03/2013 00:34:36 PM) (Source: BugCheck) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa8007009040, 0xfffffa8007009320, 0xfffff800033c87b0)C:\Windows\MEMORY.DMP120313-20358-01 Error: (12/03/2013 00:34:23 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 03.12.2013 um 12:33:12 unerwartet heruntergefahren. Error: (12/03/2013 00:29:31 PM) (Source: BugCheck) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa80070967f0, 0xfffffa8007096ad0, 0xfffff800033cf7b0)C:\Windows\MEMORY.DMP120313-21902-01 Error: (12/03/2013 00:29:19 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 03.12.2013 um 12:21:33 unerwartet heruntergefahren. Error: (12/03/2013 00:18:52 PM) (Source: BugCheck) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa8006fa6b30, 0xfffffa8006fa6e10, 0xfffff8000337a7b0)C:\Windows\MEMORY.DMP120313-29967-01 Error: (12/03/2013 00:18:38 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 03.12.2013 um 12:17:28 unerwartet heruntergefahren. Error: (12/03/2013 00:13:51 PM) (Source: BugCheck) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa8006d7fb30, 0xfffffa8006d7fe10, 0xfffff800033847b0)C:\Windows\MEMORY.DMP120313-21060-01 Error: (12/03/2013 00:13:36 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 03.12.2013 um 12:12:11 unerwartet heruntergefahren. Error: (11/23/2013 06:30:08 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ARCOR", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{976DFCD2-2CD9-4266-A518-1D17600A413F}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/23/2013 11:22:13 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 23.11.2013 um 01:46:55 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3764.86 MB Available physical RAM: 2108.12 MB Total Pagefile: 7527.9 MB Available Pagefile: 5308.73 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:234.77 GB) (Free:173.3 GB) NTFS Drive e: () (Fixed) (Total:230.89 GB) (Free:133.01 GB) NTFS Drive g: (Matlab 8.01 (R20) (CDROM) (Total:5.63 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: EA121F62) Partition 1: (Not Active) - (Size=235 GB) - (Type=07 NTFS) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=231 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2013 Ran by Marc (administrator) on MARC-PC on 03-12-2013 12:44:20 Running from C:\Users\Marc\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Marc\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2723624 2011-03-28] (Synaptics Incorporated) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Userinit] - C:\Users\Marc\AppData\Roaming\appConf32.exe HKCU\...\Run: [Google Update] - C:\Users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-08-27] (Google Inc.) HKCU\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_YATIIVE.EXE [283232 2012-02-27] (SEIKO EPSON CORPORATION) HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd) MountPoints2: {2b671cdd-69c1-11e1-8f2e-806e6f6e6963} - F:\DistinguishOS.exe MountPoints2: {9fbd2edf-22fe-11e3-824b-386077e5a823} - D:\HTC_Sync_Manager_PC.exe MountPoints2: {ca5daf6b-de2f-11e1-9468-386077e5a823} - D:\.\Autorun.exe AUTORUN=1 MountPoints2: {dc8e2a3d-be1f-11e2-865c-386077e5a823} - G:\setup.exe HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1103440 2011-07-01] (Dritek System Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-27] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\loader.dll [1958880 2013-11-18] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?affID=121562&tt=gc_&babsrc=HP_ss_din2g&mntrId=B2C716DE2B93552A HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5EE12861C7FFCC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 SearchScopes: HKCU - {09743295-742C-4EE0-BC49-A2F064AF5616} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://isearch.babylon.com/?q={searchTerms}&affID=121562&tt=gc_&babsrc=SP_ssbtis1&mntrId=B2C716DE2B93552A SearchScopes: HKCU - {34235501-5F82-42FA-82CF-150ED17D6321} URL = hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} SearchScopes: HKCU - {3F19D13F-9CAF-4CFA-A8A8-331E2D273EB9} URL = hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {8FDE0F91-580E-4A73-A571-2EA945271CB1} URL = hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms} BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKCU - No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Chrome: ======= CHR Extension: (Google Wallet) - C:\Users\Marc\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Marc\AppData\Roaming\BabSolution\CR\delta1.crx ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-11-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-27] (Avira Operations GmbH & Co. KG) R2 BitGuard; C:\ProgramData\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [3780064 2013-11-18] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [329168 2010-02-23] () S4 matlabserver; C:\MATLAB7\webserver\bin\win32\matlabserver.exe [x] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-09-04] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [107416 2013-12-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132600 2013-11-27] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-27] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-16] (DT Soft Ltd) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [16776 2011-07-29] () S3 epmntdrv; C:\Windows\SysWow64\epmntdrv.sys [14216 2011-07-29] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [9096 2011-07-29] () S3 EuGdiDrv; C:\Windows\SysWow64\EuGdiDrv.sys [8456 2011-07-29] () S3 ewsercd; C:\Windows\System32\DRIVERS\ewsercd.sys [112896 2012-08-10] (Huawei Technologies Co., Ltd.) S3 ewsercd; C:\Windows\SysWow64\DRIVERS\ewsercd.sys [112896 2012-08-10] (Huawei Technologies Co., Ltd.) S3 hwdatacard; C:\Windows\SysWow64\DRIVERS\ewusbmdm.sys [116864 2008-12-13] (Huawei Technologies Co., Ltd.) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-09-04] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-03 12:44 - 2013-12-03 12:44 - 00011850 _____ C:\Users\Marc\Downloads\FRST.txt 2013-12-03 12:44 - 2013-12-03 12:44 - 00000000 ____D C:\FRST 2013-12-03 12:43 - 2013-12-03 12:43 - 01959434 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe 2013-12-03 12:34 - 2013-12-03 12:34 - 00262144 _____ C:\Windows\Minidump\120313-20358-01.dmp 2013-12-03 12:34 - 2013-12-03 12:34 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2013-12-03 12:29 - 2013-12-03 12:29 - 00262144 _____ C:\Windows\Minidump\120313-21902-01.dmp 2013-12-03 12:18 - 2013-12-03 12:18 - 00262144 _____ C:\Windows\Minidump\120313-29967-01.dmp 2013-12-03 12:13 - 2013-12-03 12:13 - 00262144 _____ C:\Windows\Minidump\120313-21060-01.dmp 2013-11-29 10:55 - 2013-11-29 10:56 - 141602366 _____ C:\Users\Marc\Downloads\30-11-80 - Sido.zip 2013-11-26 21:39 - 2013-11-27 19:17 - 00000087 _____ C:\Users\Marc\Desktop\leibnitz.m 2013-11-25 15:54 - 2013-11-25 15:25 - 00000000 ____D C:\Users\Marc\Desktop\VortraegeWS2013-14 2013-11-25 15:53 - 2013-11-25 15:54 - 23856602 _____ C:\Users\Marc\Downloads\VortraegeWS2013-14_25-11-13_15.27.zip 2013-11-22 19:29 - 2013-11-22 19:29 - 105757824 _____ C:\Windows\SysWOW64\悶癗L 2013-11-22 13:03 - 2013-11-22 13:03 - 00000000 ____D C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-11-22 12:37 - 2013-11-22 12:37 - 00052736 _____ C:\Users\Marc\Downloads\Aufg4_5_22-11-13_8.39.xls 2013-11-21 21:55 - 2013-11-21 21:55 - 105611834 _____ C:\Windows\SysWOW64\䄼꠴ 2013-11-20 12:44 - 2013-11-20 12:56 - 00000111 _____ C:\Users\Marc\Desktop\test1.m 2013-11-18 07:39 - 2013-11-18 07:39 - 104837737 _____ C:\Windows\SysWOW64\ṕ젅 2013-11-18 00:47 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-18 00:47 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-18 00:47 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-18 00:47 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-18 00:47 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-18 00:47 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-18 00:47 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-18 00:47 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-18 00:47 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-18 00:47 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-18 00:47 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-18 00:46 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-18 00:46 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-18 00:46 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-18 00:46 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-18 00:46 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-13 16:30 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 16:30 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 16:30 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 16:30 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 16:30 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 16:30 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 16:30 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 16:30 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 16:30 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 16:30 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 16:30 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 16:30 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 16:30 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 16:30 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 16:30 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 16:30 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 16:30 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 16:30 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 16:30 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 16:30 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 16:30 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 16:30 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 16:30 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 16:30 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 16:30 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 16:30 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 16:30 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 16:30 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 16:30 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 16:30 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-10 16:21 - 2013-11-10 16:21 - 00005953 _____ C:\Users\Marc\Downloads\353654985_Umsatzliste (1).csv 2013-11-10 14:42 - 2013-11-26 21:41 - 00000070 _____ C:\Users\Marc\Desktop\geo.m 2013-11-06 17:32 - 2013-11-12 22:45 - 103974937 _____ C:\Windows\SysWOW64\ⲛW ==================== One Month Modified Files and Folders ======= 2013-12-03 12:44 - 2013-12-03 12:44 - 00011850 _____ C:\Users\Marc\Downloads\FRST.txt 2013-12-03 12:44 - 2013-12-03 12:44 - 00000000 ____D C:\FRST 2013-12-03 12:43 - 2013-12-03 12:43 - 01959434 _____ (Farbar) C:\Users\Marc\Downloads\FRST64.exe 2013-12-03 12:42 - 2009-07-14 05:45 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-03 12:42 - 2009-07-14 05:45 - 00014960 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-03 12:39 - 2009-07-14 18:58 - 00654400 _____ C:\Windows\system32\perfh007.dat 2013-12-03 12:39 - 2009-07-14 18:58 - 00130240 _____ C:\Windows\system32\perfc007.dat 2013-12-03 12:39 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-03 12:38 - 2012-03-09 09:26 - 01414675 _____ C:\Windows\WindowsUpdate.log 2013-12-03 12:34 - 2013-12-03 12:34 - 00262144 _____ C:\Windows\Minidump\120313-20358-01.dmp 2013-12-03 12:34 - 2013-12-03 12:34 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2013-12-03 12:34 - 2012-08-04 13:24 - 434162977 _____ C:\Windows\MEMORY.DMP 2013-12-03 12:34 - 2012-08-04 13:24 - 00000000 ____D C:\Windows\Minidump 2013-12-03 12:34 - 2012-07-31 17:23 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2013-12-03 12:34 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-03 12:34 - 2009-07-14 05:51 - 00093462 _____ C:\Windows\setupact.log 2013-12-03 12:33 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-03 12:30 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-12-03 12:29 - 2013-12-03 12:29 - 00262144 _____ C:\Windows\Minidump\120313-21902-01.dmp 2013-12-03 12:21 - 2012-04-04 09:35 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-03 12:18 - 2013-12-03 12:18 - 00262144 _____ C:\Windows\Minidump\120313-29967-01.dmp 2013-12-03 12:16 - 2012-08-27 13:15 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA.job 2013-12-03 12:13 - 2013-12-03 12:13 - 00262144 _____ C:\Windows\Minidump\120313-21060-01.dmp 2013-12-03 12:08 - 2013-04-03 13:33 - 00107416 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-11-29 10:56 - 2013-11-29 10:55 - 141602366 _____ C:\Users\Marc\Downloads\30-11-80 - Sido.zip 2013-11-27 19:17 - 2013-11-26 21:39 - 00000087 _____ C:\Users\Marc\Desktop\leibnitz.m 2013-11-27 18:44 - 2013-04-09 22:08 - 00000000 ____D C:\Users\Marc\Documents\MATLAB 2013-11-27 15:05 - 2013-10-14 14:09 - 00000000 ____D C:\Users\Marc\Desktop\Monte Carlo 2013-11-27 09:16 - 2013-05-08 16:37 - 00083160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-11-27 09:16 - 2013-04-03 13:33 - 00132600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-11-27 09:16 - 2013-04-03 13:33 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-11-26 21:41 - 2013-11-10 14:42 - 00000070 _____ C:\Users\Marc\Desktop\geo.m 2013-11-25 15:54 - 2013-11-25 15:53 - 23856602 _____ C:\Users\Marc\Downloads\VortraegeWS2013-14_25-11-13_15.27.zip 2013-11-25 15:25 - 2013-11-25 15:54 - 00000000 ____D C:\Users\Marc\Desktop\VortraegeWS2013-14 2013-11-23 14:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-23 11:21 - 2013-09-16 09:51 - 00000000 ____D C:\ProgramData\BitGuard 2013-11-23 11:21 - 2012-03-14 07:12 - 00139584 _____ C:\Windows\PFRO.log 2013-11-22 19:29 - 2013-11-22 19:29 - 105757824 _____ C:\Windows\SysWOW64\悶癗L 2013-11-22 13:03 - 2013-11-22 13:03 - 00000000 ____D C:\Users\Marc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2013-11-22 12:37 - 2013-11-22 12:37 - 00052736 _____ C:\Users\Marc\Downloads\Aufg4_5_22-11-13_8.39.xls 2013-11-21 21:55 - 2013-11-21 21:55 - 105611834 _____ C:\Windows\SysWOW64\䄼꠴ 2013-11-20 12:56 - 2013-11-20 12:44 - 00000111 _____ C:\Users\Marc\Desktop\test1.m 2013-11-18 07:39 - 2013-11-18 07:39 - 104837737 _____ C:\Windows\SysWOW64\ṕ젅 2013-11-18 00:46 - 2013-07-16 11:38 - 00000000 ____D C:\Windows\system32\MRT 2013-11-18 00:44 - 2013-05-20 19:29 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-12 22:45 - 2013-11-06 17:32 - 103974937 _____ C:\Windows\SysWOW64\ⲛW 2013-11-11 14:54 - 2012-04-22 20:08 - 00000000 ____D C:\Users\Marc\AppData\Roaming\Winamp 2013-11-10 16:21 - 2013-11-10 16:21 - 00005953 _____ C:\Users\Marc\Downloads\353654985_Umsatzliste (1).csv 2013-11-08 16:03 - 2013-10-14 14:05 - 00000000 ____D C:\Users\Marc\Desktop\Ökonometrie Some content of TEMP: ==================== C:\Users\Marc\AppData\Local\Temp\AskSLib.dll C:\Users\Marc\AppData\Local\Temp\avgnt.exe C:\Users\Marc\AppData\Local\Temp\IPx64_1031.exe C:\Users\Marc\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe C:\Users\Marc\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Marc\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Marc\AppData\Local\Temp\ose00000.exe C:\Users\Marc\AppData\Local\Temp\ubiA515.tmp.exe C:\Users\Marc\AppData\Local\Temp\uninst1.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-30 07:58 ==================== End Of Log ============================ |
03.12.2013, 13:06 | #2 |
/// the machine /// TB-Ausbilder | ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E hi,
__________________Scan mit Combofix
__________________ |
03.12.2013, 16:46 | #3 |
| ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E Hallo,
__________________danke für Deine schnelle Antwort. Hab das Programm durchlaufen lassen und hier den LOG-Text: (gab aber meldung dass mein avira programm noch laufen würde, nur als info) Code:
ATTFilter ComboFix 13-12-01.01 - Marc 03.12.2013 13:18:14.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3765.2376 [GMT 1:00] ausgeführt von:: c:\users\Marc\Downloads\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\users\Marc\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data c:\users\Marc\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences c:\users\Marc\AppData\Roaming\AcroIEHelpe.txt c:\windows\SysWow64\FlashPlayerApp.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-11-03 bis 2013-12-03 )))))))))))))))))))))))))))))) . . 2013-12-03 12:26 . 2013-12-03 12:26 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-12-03 11:44 . 2013-12-03 11:44 -------- d-----w- C:\FRST 2013-11-17 23:46 . 2013-10-12 08:45 2241536 ----a-w- c:\windows\system32\wininet.dll 2013-11-17 23:46 . 2013-10-12 08:43 15404544 ----a-w- c:\windows\system32\ieframe.dll 2013-11-17 23:46 . 2013-10-12 08:43 19269632 ----a-w- c:\windows\system32\mshtml.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-03 11:08 . 2013-04-03 12:33 107416 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-11-27 08:16 . 2013-05-08 15:37 83160 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-11-27 08:16 . 2013-04-03 12:33 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-11-27 08:16 . 2013-04-03 12:33 132600 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-11-17 23:44 . 2013-05-20 18:29 82896128 ----a-w- c:\windows\system32\MRT.exe 2013-09-08 02:30 . 2013-10-10 23:30 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-09-08 02:27 . 2013-10-10 23:30 327168 ----a-w- c:\windows\system32\mswsock.dll 2013-09-08 02:03 . 2013-10-10 23:30 231424 ----a-w- c:\windows\SysWow64\mswsock.dll 2013-09-04 20:44 . 2013-09-04 20:44 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2013-09-04 20:44 . 2013-09-04 20:44 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIIVE.EXE" [2012-02-27 283232] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-07-01 1103440] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-12-09 74752] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-11-27 683576] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys;c:\windows\SYSNATIVE\epmntdrv.sys [x] R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys;c:\windows\SYSNATIVE\EuGdiDrv.sys [x] R3 ewsercd;Huawei DataCard USB Serial Port;c:\windows\system32\DRIVERS\ewsercd.sys;c:\windows\SYSNATIVE\DRIVERS\ewsercd.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 BitGuard;BitGuard;c:\programdata\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe;c:\programdata\BitGuard\2.7.1832.68\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 WTGService;WTGService;c:\program files (x86)\Verbindungsassistent\WTGService.exe;c:\program files (x86)\Verbindungsassistent\WTGService.exe [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-10-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000Core1cec45b6f82e49b.job - c:\users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-27 12:15] . 2013-12-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-782170740-2215469858-196107692-1000UA.job - c:\users\Marc\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-27 12:15] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-05-09 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-05-09 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-05-09 416024] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~3\BitGuard\271832~1.68\{C16C1~1\loader.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://search.babylon.com/?affID=121562&tt=gc_&babsrc=HP_ss_din2g&mntrId=B2C716DE2B93552A mLocal Page = c:\windows\SysWOW64\blank.htm uSearchAssistant = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=7243efda-c5bf-4408-bc58-85ad224ec1f0&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=16/05/2013&type=hp1000 IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-MatlabR14 - c:\matlab7\uninstall\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-12-03 13:30:26 ComboFix-quarantined-files.txt 2013-12-03 12:30 . Vor Suchlauf: 11 Verzeichnis(se), 185.950.998.528 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 188.518.862.848 Bytes frei . - - End Of File - - B50584F05F234391F7EC938D7BB86A93 |
04.12.2013, 10:51 | #4 |
/// the machine /// TB-Ausbilder | ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu ProgramDate\BitGuard\2.7.1832.68\..\loader.dll bzw. adware/bprotector.E |
adapter, administrator, adware/bprotector.e, antivirus, avira, computer, defender, desktop, device driver, excel, explorer, fehler, flash player, home, installation, log, memory.dmp, minidump, monte, opera, registry, richtlinie, scan, security, services.exe, svchost.exe, system, usb, virus, windows, winlogon.exe |