|
Log-Analyse und Auswertung: Tabs öffnen sich selbstständig, auch in Spielen.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.12.2013, 18:50 | #1 |
| Tabs öffnen sich selbstständig, auch in Spielen. Hi, also wie die Überschrift schon sagt, es kommt öfters vor, dass sich Tabs selbstständig öffnen. Wenn ich im Spiel bin, fliege ich auf den Desktop (egal welches Spiel). Meine Antiviren Tools finden nichts. Manchmal öffnet sich ein zusätzlicher Tab mit irgendeiner Werbung oder mit der Aussage ich hätte Viren, wenn ich einen neuen Tab mit dem "Plus" in der Tableiste öffnen will. Ich hoffe ich hab alles beisammen was Ihr braucht um zu helfen. Lg Nastagar |
22.12.2013, 19:39 | #2 |
/// the machine /// TB-Ausbilder | Tabs öffnen sich selbstständig, auch in Spielen. Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
22.12.2013, 20:54 | #3 |
| Tabs öffnen sich selbstständig, auch in Spielen.Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-12-2013 02 Ran by Nastagar at 2013-12-22 17:46:05 Running from C:\Users\Nastagar\Desktop\Trojaner kicken Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996} AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED} ==================== Installed Programs ====================== Ad-Aware Antivirus (Version: 11.1.5152.0) Ad-Aware Security Add-on (x32 Version: 3.8.0.0) AdAwareInstaller (Version: 11.1.5152.0) AdAwareUpdater (Version: 11.1.5152.0) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Advanced SystemCare 7 (x32 Version: 7.0.6) AntimalwareEngine (Version: 2.6.0.0) Asmedia ASM106x SATA Host Controller Driver (x32 Version: 1.3.4.000) BatBrowse 1.0.0 (Version: 1.0.0) <==== ATTENTION Battlefield 4™ (x32 Version: 1.0.0.1) Battlelog Web Plugins (x32 Version: 2.3.2) Benutzerhandbuch anzeigen (x32 Version: 3.60.34) Call of Duty: Black Ops II (x32) Common Desktop Agent (Version: 1.62.0) D3DX10 (x32 Version: 15.4.2368.0902) Diablo III (x32 Version: 1.0.8.16416) Empire Earth (x32) Empire: Total War (x32) ESN Sonar (x32 Version: 0.70.4) Flashpoint Resistance uninstall (x32) GeForce Experience NvStream Client Components (Version: 1.6.28) GPGNet (x32 Version: 1.0.0) Intel(R) Management Engine Components (x32 Version: 8.1.10.1300) Intel(R) Network Connections 17.2.154.0 (Version: 17.2.154.0) Intel(R) Rapid Storage Technology enterprise (x32 Version: 3.5.0.1092) Intel® Trusted Connect Service Client (Version: 1.26.242.3) Junk Mail filter update (x32 Version: 15.4.3502.0922) MCI Installation (x32 Version: 1.00.000) Mesh Runtime (x32 Version: 15.4.5722.2) Messenger Companion (x32 Version: 15.4.3502.0922) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8107.0) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Security Client (Version: 4.4.0304.0) Microsoft Security Client DE-DE Language Pack (Version: 2.0.0719.0) Microsoft Security Essentials (Version: 4.4.304.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0) Mozilla Maintenance Service (x32 Version: 26.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) NVIDIA 3D Vision Controller-Treiber 331.65 (Version: 331.65) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65) NVIDIA GeForce Experience 1.7 (Version: 1.7) NVIDIA Grafiktreiber 331.65 (Version: 331.65) NVIDIA HD-Audiotreiber 1.3.26.4 (Version: 1.3.26.4) NVIDIA Install Application (Version: 2.1002.140.952) NVIDIA LED Visualizer 1.0 (Version: 1.0) NVIDIA PhysX (x32 Version: 9.13.0725) NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725) NVIDIA ShadowPlay 9.3.16 (Version: 9.3.16) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165) NVIDIA Systemsteuerung 331.65 (Version: 331.65) NVIDIA Update 9.3.16 (Version: 9.3.16) NVIDIA Update Components (Version: 9.3.21) NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9) OpenOffice 4.0.0 (x32 Version: 4.00.9702) Operation Flashpoint Gold Upgrade uninstall (x32) Operation Flashpoint uninstall (x32) Origin (x32 Version: 9.1.10.2728) OTPService (x32 Version: 1.0.004) PDF Creator PDF Creator Packages (HKCU) PlanetSide 2 (HKCU Version: 1.0.3.181) PunkBuster Services (x32 Version: 0.993) Realtek High Definition Audio Driver (x32 Version: 6.0.1.7083) Red Light Center 3D Client (x32 Version: 1.9.4152) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0) Samsung Easy Document Creator (x32 Version: 1.05.78 (28.06.2013)) Samsung Easy Printer Manager (x32 Version: 1.03.49.00(28.06.2013)) Samsung M2070 Series (x32 Version: 1.01 (11.07.2013)) Samsung Printer Live Update (x32 Version: 1.01.00:04(2013-04-22)) Samsung Scan Process Machine (x32 Version: 1.01.08.00) SHIELD Streaming (Version: 1.6.34) Smart Defrag 2 (x32 Version: 2.9) SNS Upload for Easy Document Creator (x32 Version: 1.0.0) Spybot - Search & Destroy (x32 Version: 2.2.25) Steam (x32 Version: 1.0.0.0) Super-Charger (x32 Version: 1.2.016) Supreme Commander - Forged Alliance (HKCU Version: 1.00.0000) Supreme Commander (HKCU Version: 1.00.0000) Surfing Protection (x32 Version: 1.0) TmNationsForever (x32) Total War: ROME II (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Update for PDF Creator (HKCU) <==== ATTENTION UseNeXT by Tangysoft (x32) VLC media player 2.0.6 (Version: 2.0.6) Wachdienst in der Bundeswehr (x32 Version: 1.00.2004) Warhammer Online: Age of Reckoning (x32 Version: ) Warhammer Online: Age of Reckoning (x32) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3508.1109) Windows Live Family Safety (Version: 15.4.3502.0922) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3508.1109) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 19-12-2013 19:07:59 Windows Update 22-12-2013 13:31:21 AA11 ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {02D6FB8D-A7D3-444E-995E-BBEFD79BF001} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {390288C2-9E14-4D36-9200-CAAAC49CF794} - System32\Tasks\ASC7_SkipUac_Nastagar => C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe [2013-11-14] (IObit) Task: {4844730F-EDDA-4317-A3B8-23DB966A117E} - System32\Tasks\ASC7_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe [2013-11-11] (IObit) Task: {57C0C00A-01B1-4B85-9EF0-937DD7C29FDE} - System32\Tasks\DigitalSite => C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {74F5307B-2E4C-4C20-A8CC-A321CDB5DB1E} - System32\Tasks\{E6E37F8B-75D8-448C-AEEC-4F35915AF4C9} => E:\Downloads\Bw Wachdienst\Wachdienst\TB85RUN.EXE [2002-03-04] (Click2learn, Inc.) Task: {765ABFED-F0F7-4068-B6A1-88E99A620964} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {8E30D8CE-7CF9-4436-AC45-8809D44E35F4} - System32\Tasks\{3ABA0F6D-93F2-47D6-8926-997EB59E09B5} => E:\Downloads\Bw Wachdienst\Wachdienst\TB85RUN.EXE [2002-03-04] (Click2learn, Inc.) Task: {C3166DBC-59D1-4BB7-BBF8-BC44C6CB7B5C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated) Task: {C80534F6-AB06-4611-BF8A-5DFE81558F0F} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {D35A0791-5CDD-484F-BBEB-4FCDB2A1FC78} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {F288441E-DFCB-4165-AA0D-DA3EEF8AA575} - System32\Tasks\{4F809451-0DD4-4218-9C86-45426F41053F} => E:\Downloads\Bw Wachdienst\Wachdienst\TB85RUN.EXE [2002-03-04] (Click2learn, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Nastagar\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE ==================== Loaded Modules (whitelisted) ============= 2012-03-09 09:58 - 2012-03-09 09:58 - 00057208 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00158032 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\pugixml.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 02747720 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\RCF.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00123264 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_filesystem-vc100-mt-1_53.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00023928 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_system-vc100-mt-1_53.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00055168 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_date_time-vc100-mt-1_53.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00102264 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_thread-vc100-mt-1_53.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00499576 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\boost_locale-vc100-mt-1_53.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00361824 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\HtmlFramework.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00149840 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\libssh2.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00106824 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\zlib.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00277328 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\Logger.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00064856 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\DllStorage.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00780656 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTrayDefaultSkin.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00142168 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\Localization.dll 2013-12-11 18:23 - 2013-12-11 18:23 - 00685904 _____ () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\SQLite.dll 2013-11-24 10:31 - 2013-06-28 12:39 - 01402368 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\ssm4mdu.dll 2013-11-20 15:51 - 2013-10-25 12:08 - 00517408 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\sqlite3.dll 2013-10-30 21:16 - 2013-10-30 21:16 - 00337920 _____ () C:\Program Files (x86)\BatBrowse\bin\sqlite3.DLL 2013-11-20 22:04 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-11-20 22:04 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-11-20 15:51 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madExcept_.bpl 2013-11-20 15:51 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madBasic_.bpl 2013-11-20 15:51 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\madDisAsm_.bpl 2013-11-20 15:51 - 2013-01-15 18:47 - 00893248 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\webres.dll 2013-08-15 20:31 - 2013-08-15 20:31 - 00016896 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\PSIClient\bf365ffa617f42ab5f3b2835286e62a0\PSIClient.ni.dll 2013-11-20 15:51 - 2013-10-25 12:07 - 01233696 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare 7\Scan.dll 2013-11-20 22:04 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-12-22 13:32 - 2013-12-22 13:32 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-12-10 20:10 - 2013-12-10 20:10 - 16242056 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll 2013-04-23 17:30 - 2013-11-06 22:48 - 00691200 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2013-05-03 14:35 - 2013-12-11 20:40 - 01135016 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2013-03-26 15:16 - 2013-11-06 22:48 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2012-12-11 08:51 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll 2012-12-11 08:51 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll 2012-12-11 08:51 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/22/2013 00:34:45 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/20/2013 09:47:27 AM) (Source: ESENT) (User: ) Description: taskhost (3740) WebCacheLocal: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\Users\Nastagar\AppData\Local\Microsoft\Windows\WebCache\V01.log. Error: (12/20/2013 09:47:14 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/19/2013 07:57:33 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/17/2013 10:14:31 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/16/2013 09:38:34 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/16/2013 00:16:51 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/15/2013 07:00:15 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde nicht erfolgreich abgeschlossen, da eine Schattenkopie nicht erstellt werden konnte. Löschen Sie auf dem zu sichernden Laufwerk nicht benötigte Dateien, um Speicherplatz freizugeben, und wiederholen Sie den Vorgang. Error: (12/15/2013 04:59:05 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/14/2013 05:16:45 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "imaging1". Fehler in Manifest- oder Richtliniendatei "imaging2" in Zeile imaging3. Das imaging-Element wird als untergeordnetes Element des urn:schemas-microsoft-com:asm.v1^assembly-Elements angezeigt, das von dieser Windows-Version nicht unterstützt wird. System errors: ============= Error: (12/22/2013 00:35:49 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/22/2013 00:35:48 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (12/22/2013 00:35:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/22/2013 00:35:15 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht. Error: (12/22/2013 00:34:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/22/2013 00:34:14 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (12/22/2013 00:33:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (12/22/2013 00:33:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1326 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (12/22/2013 00:33:33 PM) (Source: volmgr) (User: ) Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen. Error: (12/20/2013 00:42:06 PM) (Source: DCOM) (User: Nastagar-PC) Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}Nastagar-PCGastS-1-5-21-569393183-3011460949-2441938767-501LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= Error: (12/22/2013 00:34:45 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/20/2013 09:47:27 AM) (Source: ESENT)(User: ) Description: taskhost3740WebCacheLocal: C:\Users\Nastagar\AppData\Local\Microsoft\Windows\WebCache\V01.log-1811 (0xfffff8ed) Error: (12/20/2013 09:47:14 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/19/2013 07:57:33 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/17/2013 10:14:31 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/16/2013 09:38:34 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/16/2013 00:16:51 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/15/2013 07:00:15 PM) (Source: Windows Backup)(User: ) Description: Es konnte keine Schattenkopie erstellt werden. Weitere Informationen finden Sie in den Anwendungsereignisprotokollen "VSS" und "SPP". (0x81000019) Error: (12/15/2013 04:59:05 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/14/2013 05:16:45 PM) (Source: SideBySide)(User: ) Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10 ==================== Memory info =========================== Percentage of memory in use: 15% Total physical RAM: 32681.89 MB Available physical RAM: 27604.31 MB Total Pagefile: 32680.07 MB Available Pagefile: 28090.31 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:279.36 GB) (Free:68.9 GB) NTFS Drive d: (SupCom1EG) (CDROM) (Total:5.44 GB) (Free:0 GB) UDF Drive e: (Volume) (Fixed) (Total:1863.01 GB) (Free:1734.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 279 GB) (Disk ID: 6ABA6FCB) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=279 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: D0493362) Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 15:00 on 22/12/2013 (********) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-12-2013 02 Ran by Nastagar (administrator) on NASTAGAR-PC on 22-12-2013 17:45:34 Running from C:\Users\Nastagar\Desktop\Trojaner kicken Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe () C:\Program Files (x86)\MSI\OTPService\OTPService.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe () C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\splwow64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7204568 2013-11-20] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [] - [x] HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe [3987288 2013-12-11] () HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2283808 2013-11-11] (IObit) HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.) HKCU\...\Runonce: [adawarebp] - reg.exe delete "HKCU\Software\AppDataLow\Software\adawarebp" /f HKCU\...\Runonce: [adawarebp_XP] - reg.exe delete "HKCU\Software\adawarebp" /f MountPoints2: {4c9d0149-b1a8-11e2-a937-806e6f6e6963} - D:\autorun.exe HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKU\Gast\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Gast\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x218546485A4FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1383069832&from=cor&uid=WDCXWD3000BLHX-01V7BV0_WD-WXD1E91JWVF2JWVF2 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - DefaultScope {CA085DE2-EDBE-4E69-AD55-4D8317F6E6B0} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} SearchScopes: HKCU - {CA085DE2-EDBE-4E69-AD55-4D8317F6E6B0} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} BHO: No Name - {10921475-03CE-4E04-90CE-E2E7EF20C814} - No File BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll () BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll () BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: BatBrowse - {b67b3dbb-c1c9-49d2-b016-2748b0b5017e} - C:\Program Files (x86)\BatBrowse\BatBrowseBHO.dll (BatBrowse) BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit) Toolbar: HKLM - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll () Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll () Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default FF user.js: detected! => C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\user.js FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\Extensions\ascsurfingprotection@iobit.com FF Extension: Ad-Aware Security Add-on - C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} FF Extension: BatBrowse - C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\Extensions\firefox@batbrowse.com.xpi FF Extension: Address Bar Search - C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}.xpi ==================== Services (Whitelisted) ================= R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [878368 2013-10-25] (IObit) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-09] (Intel Corporation) R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe [513736 2013-12-11] () R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-10-25] (IObit) R2 MSI_OTPService; C:\Program Files (x86)\MSI\OTPService\OTPService.exe [252432 2012-04-12] () R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [144008 2012-12-21] (MSI) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-31] () S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 Update BatBrowse; C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe [66336 2013-11-07] () R2 Util BatBrowse; C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe [66336 2013-11-07] () ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49048 2013-10-30] (Asmedia Technology) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-06-10] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [26072 2012-08-07] (Intel Corporation) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-06-10] () R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [28928 2013-10-30] (Razer USA Ltd.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 NTIOLib_1_0_T; C:\Program Files (x86)\MSI\OTPService\NTIOLib_X64.sys [14136 2009-10-05] (MSI) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [329800 2013-07-17] (BitDefender S.R.L.) S3 MSICDSetup; \??\D:\CDriver64.sys [x] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-22 17:45 - 2013-12-22 17:45 - 00000000 ____D C:\FRST 2013-12-22 15:02 - 2013-12-22 15:02 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\LavasoftStatistics 2013-12-22 15:00 - 2013-12-22 15:00 - 00000000 _____ C:\Users\Nastagar\defogger_reenable 2013-12-22 14:35 - 2013-12-22 14:35 - 00000000 ____D C:\Program Files\Lavasoft 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Users\Nastagar\AppData\Local\adawarebp 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\ProgramData\blekko toolbars 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Program Files (x86)\Toolbar Cleaner 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2013-12-22 14:33 - 2013-12-22 14:33 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Lavasoft 2013-12-22 14:32 - 2013-12-22 14:32 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-12-22 14:31 - 2013-12-22 14:31 - 00000000 ____D C:\ProgramData\Lavasoft 2013-12-22 14:17 - 2013-12-22 17:45 - 00000000 ____D C:\Users\Nastagar\Desktop\Trojaner kicken 2013-12-22 13:32 - 2013-12-22 13:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 12:42 - 2013-12-20 12:42 - 00000000 ____D C:\Users\Gast\Documents\Fax 2013-12-13 09:09 - 2013-12-13 09:09 - 00000000 _____ C:\asc_rdflag 2013-12-11 09:48 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 09:48 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 09:48 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 09:48 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 09:46 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 09:46 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 09:46 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 09:46 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 09:46 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 09:46 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 09:46 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 09:46 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 09:46 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 09:46 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 09:46 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 09:46 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 09:46 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 09:46 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 09:46 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 09:46 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 09:46 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 09:46 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 09:46 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 09:46 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 09:46 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 09:46 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 09:46 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 09:46 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 09:46 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 09:46 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 09:46 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 09:46 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 09:46 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 09:46 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 09:46 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 09:18 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 09:18 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 09:18 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 09:18 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 09:18 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 09:18 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 09:18 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 09:18 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 09:18 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 09:18 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 09:18 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 09:18 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 09:18 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 09:18 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 09:18 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 09:18 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 09:18 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 09:18 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 09:18 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-06 12:03 - 2013-12-06 12:03 - 00002976 _____ C:\Windows\System32\Tasks\{E6E37F8B-75D8-448C-AEEC-4F35915AF4C9} 2013-12-05 10:00 - 2013-12-05 10:00 - 00002976 _____ C:\Windows\System32\Tasks\{4F809451-0DD4-4218-9C86-45426F41053F} 2013-12-05 09:59 - 2013-12-05 09:59 - 00002976 _____ C:\Windows\System32\Tasks\{3ABA0F6D-93F2-47D6-8926-997EB59E09B5} 2013-12-05 09:57 - 2013-12-05 09:57 - 00000961 _____ C:\Users\Public\Desktop\Wachdienst in der Bundeswehr.lnk 2013-12-05 09:51 - 2002-05-01 18:51 - 00011776 ____N (Microsoft Corporation) C:\Windows\system\MCIQTZ.DRV 2013-12-05 09:29 - 2013-12-13 09:09 - 60731392 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2013-12-05 09:29 - 2013-12-13 09:09 - 00897024 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2013-12-05 09:29 - 2013-12-13 09:09 - 00069632 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2013-12-05 09:29 - 2013-12-13 09:09 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2013-12-01 13:42 - 2013-12-01 13:42 - 00000000 ____D C:\ProgramData\Razer 2013-11-28 11:29 - 2013-12-20 12:54 - 00000000 ____D C:\Users\Gast\Documents\Scan 2013-11-26 13:30 - 2013-11-26 13:32 - 32206488 _____ (DVDVideoSoft Ltd. ) C:\Users\Gast\Downloads\FreeYouTubeToMP3Converter_3.12.16.1030.exe 2013-11-25 10:32 - 2013-11-25 11:00 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Samsung 2013-11-24 16:49 - 2013-11-24 16:50 - 00000000 ____D C:\Users\Nastagar\Documents\Scan 2013-11-24 10:35 - 2013-11-25 11:13 - 00000099 _____ C:\Users\Public\LMDebug.log 2013-11-24 10:33 - 2013-11-24 10:33 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Samsung 2013-11-24 10:33 - 2013-11-24 10:33 - 00000000 ____D C:\Program Files\Common Files\Common Desktop Agent 2013-11-24 10:32 - 2013-11-24 10:35 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdate 2013-11-24 10:32 - 2013-11-24 10:33 - 00000000 ____D C:\ProgramData\Samsung 2013-11-24 10:32 - 2013-07-05 11:51 - 00152920 ____R C:\Windows\Wiainst64.exe 2013-11-24 10:32 - 2013-02-22 13:29 - 00365568 _____ C:\Windows\system32\SaMinDrv.dll 2013-11-24 10:32 - 2013-02-22 13:29 - 00112128 _____ C:\Windows\system32\SaImgFlt.dll 2013-11-24 10:32 - 2013-02-22 13:29 - 00055296 _____ C:\Windows\system32\SaErHdlr.dll 2013-11-24 10:31 - 2013-11-24 10:33 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-11-24 10:31 - 2013-06-28 15:36 - 00094208 _____ C:\Windows\SysWOW64\Ssdevm.dll 2013-11-24 10:31 - 2013-06-28 15:36 - 00091136 _____ C:\Windows\system32\Ssdevm64.dll 2013-11-24 10:31 - 2013-06-02 03:38 - 00053248 _____ C:\Windows\SysWOW64\Ssusbpn.dll 2013-11-24 10:31 - 2013-06-02 03:38 - 00049152 _____ C:\Windows\system32\Ssusbp64.dll 2013-11-24 10:31 - 2013-05-29 13:01 - 00219136 _____ C:\Windows\system32\SBuySupplies.exe 2013-11-24 10:31 - 2013-05-29 13:01 - 00034304 _____ () C:\Windows\system32\ssm4mlm.dll 2013-11-24 10:31 - 2013-05-29 13:01 - 00000359 _____ C:\Windows\system32\ssm4mlm.smt 2013-11-24 10:31 - 2013-05-29 13:00 - 00158040 _____ (SS) C:\Windows\system32\ssm4mci.exe 2013-11-24 10:31 - 2013-05-29 13:00 - 00089600 _____ (SS) C:\Windows\system32\ssm4mci.dll 2013-11-22 19:08 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-22 19:02 - 2013-11-22 19:02 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-22 19:02 - 2013-11-22 19:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-22 19:02 - 2013-11-22 19:02 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-22 19:02 - 2013-11-22 19:02 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-22 19:02 - 2013-11-22 19:02 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-22 19:02 - 2013-11-22 19:02 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-22 19:02 - 2013-11-22 19:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe ==================== One Month Modified Files and Folders ======= 2013-12-22 17:45 - 2013-12-22 17:45 - 00000000 ____D C:\FRST 2013-12-22 17:45 - 2013-12-22 14:17 - 00000000 ____D C:\Users\Nastagar\Desktop\Trojaner kicken 2013-12-22 17:16 - 2013-05-12 23:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-22 17:03 - 2013-10-29 19:03 - 00000304 _____ C:\Windows\Tasks\DigitalSite.job 2013-12-22 16:36 - 2013-04-30 15:36 - 01144473 _____ C:\Windows\WindowsUpdate.log 2013-12-22 15:06 - 2013-05-13 17:58 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-22 15:02 - 2013-12-22 15:02 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\LavasoftStatistics 2013-12-22 15:00 - 2013-12-22 15:00 - 00000000 _____ C:\Users\Nastagar\defogger_reenable 2013-12-22 15:00 - 2013-05-12 22:24 - 00000000 ____D C:\Users\Nastagar 2013-12-22 14:37 - 2013-05-14 20:33 - 00000000 ____D C:\Users\Nastagar\Desktop\Sicherheitszeug und Tools 2013-12-22 14:36 - 2013-05-12 23:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-22 14:35 - 2013-12-22 14:35 - 00000000 ____D C:\Program Files\Lavasoft 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Users\Nastagar\AppData\Local\adawarebp 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\ProgramData\blekko toolbars 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Program Files (x86)\Toolbar Cleaner 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2013-12-22 14:33 - 2013-12-22 14:33 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Lavasoft 2013-12-22 14:32 - 2013-12-22 14:32 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-12-22 14:31 - 2013-12-22 14:31 - 00000000 ____D C:\ProgramData\Lavasoft 2013-12-22 14:03 - 2013-10-29 20:03 - 00000107 _____ C:\Users\Nastagar\AppData\Roaming\WB.CFG 2013-12-22 14:03 - 2013-10-29 20:03 - 00000006 _____ C:\Users\Nastagar\AppData\Roaming\WBPU-TTL.DAT 2013-12-22 13:32 - 2013-12-22 13:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-22 12:42 - 2009-07-14 05:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-22 12:42 - 2009-07-14 05:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-22 12:40 - 2011-04-12 08:43 - 00698110 _____ C:\Windows\system32\perfh007.dat 2013-12-22 12:40 - 2011-04-12 08:43 - 00148646 _____ C:\Windows\system32\perfc007.dat 2013-12-22 12:40 - 2009-07-14 06:13 - 01617458 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-22 12:33 - 2013-04-30 16:10 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-22 12:33 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-20 13:09 - 2013-09-20 15:15 - 00000000 ____D C:\Users\Gast\Desktop\Neuer Ordner 2013-12-20 12:54 - 2013-11-28 11:29 - 00000000 ____D C:\Users\Gast\Documents\Scan 2013-12-20 12:42 - 2013-12-20 12:42 - 00000000 ____D C:\Users\Gast\Documents\Fax 2013-12-20 02:25 - 2013-05-12 23:10 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\UseNeXT 2013-12-16 09:42 - 2013-11-20 15:51 - 00000000 ____D C:\ProgramData\ProductData 2013-12-14 18:46 - 2013-08-01 21:56 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 18:46 - 2013-05-22 19:09 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-14 18:46 - 2013-05-12 22:19 - 00001912 _____ C:\Windows\epplauncher.mif 2013-12-14 18:44 - 2013-05-12 22:18 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-12-14 18:44 - 2013-05-12 22:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-12-13 09:09 - 2013-12-13 09:09 - 00000000 _____ C:\asc_rdflag 2013-12-13 09:09 - 2013-12-05 09:29 - 60731392 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2013-12-13 09:09 - 2013-12-05 09:29 - 00897024 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2013-12-13 09:09 - 2013-12-05 09:29 - 00069632 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2013-12-13 09:09 - 2013-12-05 09:29 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2013-12-12 19:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-12 17:58 - 2013-05-14 21:14 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\vlc 2013-12-11 23:17 - 2013-08-01 18:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-11 18:04 - 2013-08-01 18:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-12-11 10:55 - 2013-05-28 19:33 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-11 10:30 - 2009-07-14 05:45 - 00294712 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-10 20:10 - 2013-05-12 23:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 20:10 - 2013-05-12 23:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 20:10 - 2013-05-12 23:33 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-08 16:40 - 2013-08-28 21:26 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\WinRAR 2013-12-07 12:31 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-06 12:03 - 2013-12-06 12:03 - 00002976 _____ C:\Windows\System32\Tasks\{E6E37F8B-75D8-448C-AEEC-4F35915AF4C9} 2013-12-06 11:59 - 2013-04-30 15:45 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-05 10:00 - 2013-12-05 10:00 - 00002976 _____ C:\Windows\System32\Tasks\{4F809451-0DD4-4218-9C86-45426F41053F} 2013-12-05 09:59 - 2013-12-05 09:59 - 00002976 _____ C:\Windows\System32\Tasks\{3ABA0F6D-93F2-47D6-8926-997EB59E09B5} 2013-12-05 09:57 - 2013-12-05 09:57 - 00000961 _____ C:\Users\Public\Desktop\Wachdienst in der Bundeswehr.lnk 2013-12-05 09:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system 2013-12-05 09:47 - 2013-05-12 22:24 - 00000000 ____D C:\Users\Nastagar\AppData\Local\VirtualStore 2013-12-04 23:58 - 2013-05-12 23:19 - 00000000 ____D C:\Users\Nastagar\Desktop\Bilder 2013-12-04 13:08 - 2013-10-31 22:40 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-12-01 13:43 - 2013-05-14 20:43 - 00000000 ____D C:\Program Files (x86)\IObit 2013-12-01 13:42 - 2013-12-01 13:42 - 00000000 ____D C:\ProgramData\Razer 2013-12-01 13:42 - 2013-05-14 20:43 - 00000000 ____D C:\ProgramData\IObit 2013-11-30 20:29 - 2013-07-02 18:57 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\dvdcss 2013-11-26 13:32 - 2013-11-26 13:30 - 32206488 _____ (DVDVideoSoft Ltd. ) C:\Users\Gast\Downloads\FreeYouTubeToMP3Converter_3.12.16.1030.exe 2013-11-26 12:54 - 2013-12-11 09:46 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-26 11:19 - 2013-12-11 09:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-26 11:18 - 2013-12-11 09:46 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-26 11:11 - 2013-12-11 09:46 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-26 10:48 - 2013-12-11 09:46 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-26 10:46 - 2013-12-11 09:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-26 10:41 - 2013-12-11 09:46 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-26 10:29 - 2013-12-11 09:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-26 10:27 - 2013-12-11 09:46 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-26 10:23 - 2013-12-11 09:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-26 10:21 - 2013-12-11 09:46 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-26 10:18 - 2013-12-11 09:46 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-26 10:18 - 2013-12-11 09:46 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-26 10:16 - 2013-12-11 09:46 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-26 09:57 - 2013-12-11 09:46 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-26 09:38 - 2013-12-11 09:46 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-26 09:38 - 2013-12-11 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-26 09:35 - 2013-12-11 09:46 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-26 09:32 - 2013-12-11 09:46 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-26 09:28 - 2013-12-11 09:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-26 09:16 - 2013-12-11 09:46 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-26 09:02 - 2013-12-11 09:46 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-26 08:48 - 2013-12-11 09:46 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-26 08:32 - 2013-12-11 09:46 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-26 08:26 - 2013-12-11 09:46 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-26 08:07 - 2013-12-11 09:46 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-26 07:40 - 2013-12-11 09:46 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-26 07:34 - 2013-12-11 09:46 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-26 07:34 - 2013-12-11 09:46 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-26 07:33 - 2013-12-11 09:46 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-26 07:27 - 2013-12-11 09:46 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-25 11:13 - 2013-11-24 10:35 - 00000099 _____ C:\Users\Public\LMDebug.log 2013-11-25 11:01 - 2013-07-23 20:36 - 00000000 ____D C:\Users\Gast\AppData\Local\VirtualStore 2013-11-25 11:00 - 2013-11-25 10:32 - 00000000 ____D C:\Users\Gast\AppData\Roaming\Samsung 2013-11-24 23:46 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports 2013-11-24 16:50 - 2013-11-24 16:49 - 00000000 ____D C:\Users\Nastagar\Documents\Scan 2013-11-24 10:35 - 2013-11-24 10:32 - 00000000 ____D C:\Program Files (x86)\SamsungPrinterLiveUpdate 2013-11-24 10:33 - 2013-11-24 10:33 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Samsung 2013-11-24 10:33 - 2013-11-24 10:33 - 00000000 ____D C:\Program Files\Common Files\Common Desktop Agent 2013-11-24 10:33 - 2013-11-24 10:32 - 00000000 ____D C:\ProgramData\Samsung 2013-11-24 10:33 - 2013-11-24 10:31 - 00000000 ____D C:\Program Files (x86)\Samsung 2013-11-23 19:26 - 2013-12-11 09:18 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-11-23 18:47 - 2013-12-11 09:18 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-11-23 14:40 - 2013-04-30 16:26 - 00000000 ____D C:\Windows\Panther 2013-11-23 14:33 - 2013-07-23 20:36 - 00000000 ____D C:\Users\Gast 2013-11-23 14:30 - 2013-11-21 00:05 - 00000326 _____ C:\Windows\wininit.ini 2013-11-23 14:30 - 2013-05-12 22:24 - 00001421 _____ C:\Users\Nastagar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-23 14:15 - 2013-07-23 20:36 - 00001421 _____ C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-23 14:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-22 19:02 - 2013-11-22 19:02 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-22 19:02 - 2013-11-22 19:02 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-22 19:02 - 2013-11-22 19:02 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-22 19:02 - 2013-11-22 19:02 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-22 19:02 - 2013-11-22 19:02 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-22 19:02 - 2013-11-22 19:02 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-22 19:02 - 2013-11-22 19:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-22 19:02 - 2013-11-22 19:02 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-22 19:02 - 2013-11-22 19:02 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-22 16:50 - 2013-05-12 23:22 - 00000000 ____D C:\Users\Nastagar\Desktop\bundeswehr Some content of TEMP: ==================== C:\Users\Nastagar\AppData\Local\Temp\c641e5db-11e1-4048-b4ca-f371e87670de.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-10 00:26 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-12-22 18:30:30 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000006d ATA_____ rev.5G04 279,46GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Nastagar\AppData\Local\Temp\uwldikow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2024] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2024] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 00000000751e1a22 2 bytes [1E, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 00000000751e1ad0 2 bytes [1E, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 00000000751e1b08 2 bytes [1E, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 00000000751e1bba 2 bytes [1E, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 00000000751e1bda 2 bytes [1E, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2136] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe[2948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe[2948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe[3028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe[3028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[1604] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[1604] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[3704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[3972] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[3972] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe[5736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe[5736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[4276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000768d1465 2 bytes [8D, 76] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[4276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768d14bb 2 bytes [8D, 76] .text ... * 2 ---- EOF - GMER 2.1 ---- Code:
ATTFilter Search results from Spybot - Search & Destroy 22.12.2013 14:56:26 Scan took 00:28:47. 53 items found. DownloadSponsor: [SBI $CC437C6B] Settings (Registry Change, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\OCS\lastPID DownloadSponsor: [SBI $980DE8E4] Settings (Registry Change, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\OCS\PID Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\cdn.flashtalking.com\ftLocalComms.sol Properties.size=61 Properties.md5=548A59F7B165D23D1FFCC95519BFAD69 Properties.filedate=1386703607 Properties.filedatetext=2013-12-10 20:26:47 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\cdn.flashtalking.com\FT_cookie.sol Properties.size=43 Properties.md5=5BD98BB813EEDA3C606E3671EE84AA76 Properties.filedate=1386503987 Properties.filedatetext=2013-12-08 12:59:46 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\cdn.movad.net\movad.sol Properties.size=67 Properties.md5=14FFED13587B6F42A7D19FC80A81E010 Properties.filedate=1386235019 Properties.filedatetext=2013-12-05 10:16:58 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\cdn1b.thumbnails.4tube.com\com.jeroenwijering.sol Properties.size=54 Properties.md5=0F76B3755D10B759CCB9581F5C4B51A8 Properties.filedate=1386176407 Properties.filedatetext=2013-12-04 18:00:06 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\de-uim.cdn.videoplaza.tv\com.videoplaza.adplayer.sol Properties.size=283 Properties.md5=DFFD825E5654686385CAF83AB2EC51BF Properties.filedate=1387126706 Properties.filedatetext=2013-12-15 17:58:26 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\de-uim.cdn.videoplaza.tv\com.videoplaza.bootloader.sol Properties.size=121 Properties.md5=DDFA044C31FE6CB79A0FA91D43A96D72 Properties.filedate=1387126759 Properties.filedatetext=2013-12-15 17:59:18 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\diz.madmovs.com\com.jeroenwijering.sol Properties.size=54 Properties.md5=6B4E1AB84277844EE6114A1DCA0C7474 Properties.filedate=1386754932 Properties.filedatetext=2013-12-11 10:42:11 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\embed.porntube.com\com.jeroenwijering.sol Properties.size=50 Properties.md5=568E8E9B9C9FD7B473D201BD0638FBFB Properties.filedate=1386682362 Properties.filedatetext=2013-12-10 14:32:42 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\secureinclude.ebaystatic.com\ebayLSO.sol Properties.size=131 Properties.md5=4DD868D0CE48C5800AF3171E5A9B5844 Properties.filedate=1387481384 Properties.filedatetext=2013-12-19 20:29:44 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\secureinclude.ebaystatic.com\ebayT.sol Properties.size=39 Properties.md5=B43F43445AA3414DDC22EC80FBB22871 Properties.filedate=1387481384 Properties.filedatetext=2013-12-19 20:29:44 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\staticloads.com\com.jeroenwijering.sol Properties.size=64 Properties.md5=4ECD7CDA3A144040A627D28C47DAD65E Properties.filedate=1386703593 Properties.filedatetext=2013-12-10 20:26:33 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\sunstatic.fuckandcdn.com\com.jeroenwijering.sol Properties.size=64 Properties.md5=9241494D2F549252F46E8A7ADB9C4531 Properties.filedate=1387717169 Properties.filedatetext=2013-12-22 13:59:29 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\wac.edgecastcdn.net\dropdowndeals.sol Properties.size=440 Properties.md5=BDF02CA8B5C048D8A9B7EA2CC94D9553 Properties.filedate=1387720446 Properties.filedatetext=2013-12-22 14:54:05 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.sklavenzentrale.com\localstore.sol Properties.size=86 Properties.md5=8EDABB5310E8602A1E3513599598600D Properties.filedate=1385307309 Properties.filedatetext=2013-11-24 16:35:09 Macromedia.FlashPlayer.Cookies: [SBI $6AA61750] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.tripadvisor.de\TA.sol Properties.size=62 Properties.md5=79376BCB45AFBB298862D9999CBF24CD Properties.filedate=1387272442 Properties.filedatetext=2013-12-17 10:27:21 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\eu-st.xhamster.com\videoplayerC.swf\dats.sol Properties.size=43 Properties.md5=30EAA19737A236ABE3E7405FC4E6D9D2 Properties.filedate=1387502843 Properties.filedatetext=2013-12-20 02:27:23 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\eu-st.xhamster.com\xembed7.swf\dats.sol Properties.size=36 Properties.md5=BBDE37F8F89F86729649AB505486E942 Properties.filedate=1386682003 Properties.filedatetext=2013-12-10 14:26:43 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\freepornvs.com\#kernelteam\preferences.sol Properties.size=70 Properties.md5=E90566F37E09014F927E8E17A91E2122 Properties.filedate=1387480230 Properties.filedatetext=2013-12-19 20:10:30 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\hdporntube.xxx\#kernelteam\preferences.sol Properties.size=70 Properties.md5=E90566F37E09014F927E8E17A91E2122 Properties.filedate=1386503390 Properties.filedatetext=2013-12-08 12:49:49 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\hellporno.com\#kernelteam\preferences.sol Properties.size=61 Properties.md5=C58803187774833DFC9451A7E42B4002 Properties.filedate=1387502771 Properties.filedatetext=2013-12-20 02:26:10 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.bravotube.net\#kernelteam\preferences.sol Properties.size=61 Properties.md5=C58803187774833DFC9451A7E42B4002 Properties.filedate=1385839958 Properties.filedatetext=2013-11-30 20:32:37 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.tubewolf.com\#kernelteam\preferences.sol Properties.size=61 Properties.md5=C58803187774833DFC9451A7E42B4002 Properties.filedate=1386754981 Properties.filedatetext=2013-12-11 10:43:01 Macromedia.FlashPlayer.Cookies: [SBI $1EF45977] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.wankoz.com\#kernelteam\preferences.sol Properties.size=61 Properties.md5=C58803187774833DFC9451A7E42B4002 Properties.filedate=1386175743 Properties.filedatetext=2013-12-04 17:49:03 Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\cdn1b.thumbnails.4tube.com\swf-4tube\related_v3.swf\4tube-postroll-advertising-rotation.sol Properties.size=71 Properties.md5=594DF77F81155C6BCD96A477C11AC27F Properties.filedate=1386176152 Properties.filedatetext=2013-12-04 17:55:52 Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\play.snacktv.de\player\videoplayer.swf\SnackTV.sol Properties.size=79 Properties.md5=C4E28739FEC5A16BD61DBFA01250992D Properties.filedate=1386503999 Properties.filedatetext=2013-12-08 12:59:59 Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\video.unrulymedia.com\leo-marmalade\flowplayer-3.1.5.1-scale.swf\org.flowplayer.sol Properties.size=60 Properties.md5=180B425B659ECE264684E4F035E572BF Properties.filedate=1387716989 Properties.filedatetext=2013-12-22 13:56:28 Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.nuvid.com\player\videoplayer.swf\dat.sol Properties.size=41 Properties.md5=2F80A0F3987B1A2D0D34D7743F341373 Properties.filedate=1386503638 Properties.filedatetext=2013-12-08 12:53:58 Macromedia.FlashPlayer.Cookies: [SBI $5555F3D7] Text file (File, nothing done) C:\Users\Nastagar\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\YQUHY8FT\www.pornme.com\swf\flowplayer-3.2.16.swf\org.flowplayer.sol Properties.size=60 Properties.md5=A03AC7AC210C3FB73596484DA2BB74FD Properties.filedate=1385839447 Properties.filedatetext=2013-11-30 20:24:07 MediaPlex: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) SexList: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) SexTracker: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) SexTracker: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) CasaleMedia: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) CasaleMedia: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) CasaleMedia: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) CasaleMedia: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) CasaleMedia: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) Statcounter: [SBI $19447DDC] Tracking cookie (Firefox: Nastagar (default)) (Browser: Cookie, nothing done) MS Media Player: [SBI $5C51E349] Client ID (Registry Change, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\MediaPlayer\Player\Settings\Client ID MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\Direct3D\MostRecentApplication\Name MS Direct3D: [SBI $C2A44980] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\Direct3D\MostRecentApplication\Name MS DirectInput: [SBI $9A063C91] Most recent application (Registry Change, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\DirectInput\MostRecentApplication\Name MS DirectInput: [SBI $7B184199] Most recent application ID (Registry Change, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\DirectInput\MostRecentApplication\Id Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList Windows.OpenWith: [SBI $A1C94E79] Open with list - .BMP extension (Registry Key, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry Key, nothing done) HKEY_USERS\S-1-5-21-569393183-3011460949-2441938767-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs Cookie: [SBI $49804B54] Browser: Cookie (2) (Browser: Cookie, nothing done) Cache: [SBI $49804B54] Browser: Cache (3) (Browser: Cache, nothing done) Verlauf: [SBI $49804B54] Browser: History (1) (Browser: History, nothing done) Cookie: [SBI $49804B54] Browser: Cookie (2002) (Browser: Cookie, nothing done) --- Spybot - Search & Destroy version: 2.1.18.131 DLL (build: 20130516) --- 2013-09-20 blindman.exe (2.2.18.151) 2013-09-20 explorer.exe (2.2.18.177) 2013-09-20 SDBootCD.exe (2.2.18.109) 2013-09-20 SDCleaner.exe (2.2.18.110) 2013-09-20 SDDelFile.exe (2.2.18.94) 2013-06-18 SDDisableProxy.exe 2013-09-20 SDFiles.exe (2.2.18.135) 2013-09-20 SDFileScanHelper.exe (2.2.16.1) 2013-10-15 SDFSSvc.exe (2.2.25.211) 2013-10-10 SDHookHelper.exe (2.3.30.2) 2013-10-10 SDHookInst32.exe (2.3.30.2) 2013-10-10 SDHookInst64.exe (2.3.30.2) 2013-09-20 SDImmunize.exe (2.2.18.130) 2013-05-16 SDLogReport.exe (2.1.18.107) 2013-10-14 SDOnAccess.exe (2.2.25.4) 2013-09-20 SDPESetup.exe (2.2.18.3) 2013-09-20 SDPEStart.exe (2.2.18.86) 2013-09-20 SDPhoneScan.exe (2.2.18.28) 2013-09-20 SDPRE.exe (2.2.18.22) 2013-09-20 SDPrepPos.exe (2.2.18.10) 2013-09-20 SDQuarantine.exe (2.2.18.103) 2013-09-20 SDRootAlyzer.exe (2.2.18.116) 2013-09-20 SDSBIEdit.exe (2.2.18.39) 2013-09-20 SDScan.exe (2.2.18.177) 2013-09-20 SDScript.exe (2.2.18.53) 2013-10-15 SDSettings.exe (2.2.25.138) 2013-09-20 SDShell.exe (2.2.18.2) 2013-09-20 SDShred.exe (2.2.18.107) 2013-09-20 SDSysRepair.exe (2.2.18.101) 2013-09-20 SDTools.exe (2.2.18.150) 2013-07-25 SDTray.exe (2.1.21.129) 2013-09-20 SDUpdate.exe (2.2.18.91) 2013-09-20 SDUpdSvc.exe (2.2.18.76) 2013-09-20 SDWelcome.exe (2.2.21.129) 2013-09-13 SDWSCSvc.exe (2.2.22.2) 2013-06-19 spybotsd2-translation-frx.exe 2013-11-20 unins000.exe (51.1052.0.0) 1999-12-02 xcacls.exe 2012-08-23 borlndmm.dll (10.0.2288.42451) 2012-09-05 DelZip190.dll (1.9.0.107) 2012-09-10 libeay32.dll (1.0.0.4) 2012-09-10 libssl32.dll (1.0.0.4) 2013-05-16 SDAdvancedCheckLibrary.dll (2.1.18.98) 2013-05-16 SDAV.dll 2013-05-16 SDECon32.dll (2.1.18.113) 2013-05-16 SDECon64.dll (2.1.18.113) 2013-04-05 SDEvents.dll (2.1.16.2) 2013-10-14 SDFileScanLibrary.dll (2.2.25.14) 2013-10-10 SDHook32.dll (2.3.30.2) 2013-10-10 SDHook64.dll (2.3.30.2) 2013-05-16 SDImmunizeLibrary.dll (2.1.18.2) 2013-05-16 SDLicense.dll (2.1.18.0) 2013-05-16 SDLists.dll (2.1.18.4) 2013-05-16 SDResources.dll (2.1.18.7) 2013-05-16 SDScanLibrary.dll (2.1.18.131) 2013-05-16 SDTasks.dll (2.1.18.15) 2013-05-16 SDWinLogon.dll (2.1.18.0) 2012-08-23 sqlite3.dll 2012-09-10 ssleay32.dll (1.0.0.4) 2013-05-16 Tools.dll (2.1.18.36) 2013-11-12 Includes\Adware.sbi (*) 2013-12-17 Includes\AdwareC.sbi (*) 2010-08-13 Includes\Cookies.sbi (*) 2012-11-14 Includes\Dialer.sbi (*) 2012-11-14 Includes\DialerC.sbi (*) 2012-11-14 Includes\HeavyDuty.sbi (*) 2012-11-14 Includes\Hijackers.sbi (*) 2012-11-14 Includes\HijackersC.sbi (*) 2013-10-16 Includes\iPhone.sbi (*) 2013-06-25 Includes\Keyloggers.sbi (*) 2013-10-29 Includes\KeyloggersC.sbi (*) 2013-05-29 Includes\Malware.sbi (*) 2013-12-17 Includes\MalwareC.sbi (*) 2012-11-14 Includes\PUPS.sbi (*) 2013-12-10 Includes\PUPSC.sbi (*) 2012-11-14 Includes\Security.sbi (*) 2013-10-29 Includes\SecurityC.sbi (*) 2013-05-22 Includes\Spyware.sbi (*) 2013-08-06 Includes\SpywareC.sbi (*) 2011-06-07 Includes\Tracks.sbi (*) 2012-11-19 Includes\Tracks.uti (*) 2013-01-16 Includes\Trojans.sbi (*) 2013-05-13 Includes\TrojansC-02.sbi (*) 2013-12-03 Includes\TrojansC-03.sbi (*) 2013-12-17 Includes\TrojansC-04.sbi (*) 2013-12-10 Includes\TrojansC-05.sbi (*) 2013-08-06 Includes\TrojansC.sbi (*) |
23.12.2013, 19:38 | #4 | |
/// the machine /// TB-Ausbilder | Tabs öffnen sich selbstständig, auch in Spielen.Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.12.2013, 22:36 | #5 |
| Tabs öffnen sich selbstständig, auch in Spielen.Code:
ATTFilter ComboFix 13-12-23.01 - Nastagar 23.12.2013 22:17:40.1.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.32682.29429 [GMT 1:00] ausgeführt von:: c:\users\Nastagar\Desktop\Trojaner kicken\Combofix.exe AV: Ad-Aware Antivirus *Disabled/Outdated* {D87B6541-12A1-DAEA-0033-9B8057AAB996} AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} FW: Ad-Aware Firewall *Disabled* {E040E464-58CE-DBB2-2B6C-32B5A979FEED} SP: Ad-Aware Antivirus *Disabled/Outdated* {631A84A5-349B-D564-3A83-A0F22C2DF32B} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Nastagar\AppData\Roaming\.# c:\users\Nastagar\AppData\Roaming\.#\MBX@E28@CC2938.### c:\users\Nastagar\AppData\Roaming\.#\MBX@E28@CC2968.### c:\users\Nastagar\AppData\Roaming\.#\MBX@E28@CC2998.### . . ((((((((((((((((((((((( Dateien erstellt von 2013-11-23 bis 2013-12-23 )))))))))))))))))))))))))))))) . . 2013-12-23 21:23 . 2013-12-23 21:23 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2013-12-23 20:51 . 2013-12-23 20:51 -------- d-----w- c:\users\Nastagar\AppData\Local\Max Secure Software 2013-12-23 20:50 . 2013-12-23 20:51 -------- d-----w- c:\users\Nastagar\AppData\Roaming\GetRightToGo 2013-12-23 15:05 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DA373ECA-2D99-4E54-A436-DA9D0D254870}\mpengine.dll 2013-12-23 10:15 . 2013-12-23 10:15 -------- d-----w- c:\users\Gast\AppData\Local\adawarebp 2013-12-22 16:45 . 2013-12-22 16:45 -------- d-----w- C:\FRST 2013-12-22 13:35 . 2013-12-22 13:35 -------- d-----w- c:\program files\Lavasoft 2013-12-22 13:34 . 2013-12-22 13:34 -------- d-----w- c:\users\Nastagar\AppData\Local\adawarebp 2013-12-22 13:34 . 2013-12-22 13:34 -------- d-----w- c:\programdata\blekko toolbars 2013-12-22 13:34 . 2013-12-22 13:34 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection 2013-12-22 13:34 . 2013-12-22 13:34 -------- d-----w- c:\program files (x86)\Toolbar Cleaner 2013-12-22 13:34 . 2013-12-22 13:34 -------- d-----w- c:\program files (x86)\Lavasoft 2013-12-22 13:33 . 2013-12-22 13:33 -------- d-----w- c:\users\Nastagar\AppData\Roaming\Lavasoft 2013-12-22 13:32 . 2013-12-22 13:32 -------- d-----w- c:\program files\Common Files\Lavasoft 2013-12-22 13:31 . 2013-12-22 13:31 -------- d-----w- c:\programdata\Lavasoft 2013-12-22 11:44 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-12-15 19:41 . 2013-05-12 22:36 972264 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2013-12-15 19:41 . 2013-12-15 19:41 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D9C6311A-BB7D-429E-91FF-80C0F4FCD524}\gapaengine.dll 2013-12-11 08:48 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe 2013-12-11 08:48 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe 2013-12-11 08:48 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL 2013-12-11 08:48 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL 2013-12-11 08:48 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll 2013-12-11 08:18 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll 2013-12-05 08:51 . 2002-05-01 17:51 11776 ------w- c:\windows\system\MCIQTZ.DRV 2013-12-05 08:48 . 2002-12-05 13:10 155648 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll 2013-12-05 08:48 . 2002-12-02 14:22 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe 2013-12-05 08:48 . 2002-12-02 12:33 57344 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll 2013-12-05 08:48 . 2002-12-02 12:33 237568 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll 2013-12-05 08:48 . 2002-12-05 13:12 692224 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll 2013-12-05 08:47 . 2013-12-05 08:47 282756 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll 2013-12-05 08:47 . 2013-12-05 08:47 163972 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll 2013-12-01 12:42 . 2013-12-01 12:42 -------- d-----w- c:\programdata\Razer 2013-11-25 09:32 . 2013-11-25 10:00 -------- d-----w- c:\users\Gast\AppData\Roaming\Samsung 2013-11-24 09:33 . 2013-11-24 09:34 -------- d-----w- c:\program files (x86)\Common Files\Scan Process Machine 2013-11-24 09:33 . 2013-11-24 09:33 -------- d-----w- c:\program files\Common Files\Common Desktop Agent 2013-11-24 09:33 . 2013-11-24 09:33 -------- d-----w- c:\program files (x86)\Common Files\Common Desktop Agent 2013-11-24 09:33 . 2013-11-24 09:33 -------- d-----w- c:\users\Nastagar\AppData\Roaming\Samsung 2013-11-24 09:32 . 2013-07-05 10:51 152920 ----a-r- c:\windows\Wiainst64.exe 2013-11-24 09:32 . 2013-02-22 12:29 365568 ----a-w- c:\windows\system32\SaMinDrv.dll 2013-11-24 09:32 . 2013-02-22 12:29 112128 ----a-w- c:\windows\system32\SaImgFlt.dll 2013-11-24 09:32 . 2013-02-22 12:29 55296 ----a-w- c:\windows\system32\SaErHdlr.dll 2013-11-24 09:32 . 2013-11-24 09:33 -------- d-----w- c:\programdata\Samsung 2013-11-24 09:32 . 2013-06-28 11:39 41984 ----a-w- c:\windows\system32\Spool\prtprocs\x64\ssm4mpc.dll 2013-11-24 09:31 . 2013-05-29 12:01 34304 ----a-w- c:\windows\system32\ssm4mlm.dll 2013-11-24 09:31 . 2013-05-29 12:01 219136 ----a-w- c:\windows\system32\SBuySupplies.exe 2013-11-24 09:31 . 2013-05-29 12:00 158040 ----a-w- c:\windows\system32\ssm4mci.exe 2013-11-24 09:31 . 2013-05-29 12:00 89600 ----a-w- c:\windows\system32\ssm4mci.dll 2013-11-24 09:31 . 2013-06-28 14:36 91136 ----a-w- c:\windows\system32\Ssdevm64.dll 2013-11-24 09:31 . 2013-06-28 14:36 94208 ----a-w- c:\windows\SysWow64\Ssdevm.dll 2013-11-24 09:31 . 2013-06-02 02:38 53248 ----a-w- c:\windows\SysWow64\Ssusbpn.dll 2013-11-24 09:31 . 2013-06-02 02:38 49152 ----a-w- c:\windows\system32\Ssusbp64.dll 2013-11-24 09:31 . 2013-11-24 09:33 -------- d-----w- c:\program files (x86)\Samsung . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-14 17:46 . 2013-05-22 18:09 90708896 ----a-w- c:\windows\system32\MRT.exe 2013-12-11 22:17 . 2013-08-01 17:34 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-12-11 17:04 . 2013-08-01 17:34 214392 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 2013-12-10 19:10 . 2013-05-12 22:33 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-12-10 19:10 . 2013-05-12 22:33 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-11-22 18:02 . 2013-11-22 18:02 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-22 18:02 . 2013-11-22 18:02 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-22 18:02 . 2013-11-22 18:02 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-11-22 18:02 . 2013-11-22 18:02 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-11-22 18:02 . 2013-11-22 18:02 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-22 18:02 . 2013-11-22 18:02 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-22 18:02 . 2013-11-22 18:02 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-22 18:02 . 2013-11-22 18:02 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-11-22 18:02 . 2013-11-22 18:02 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-22 18:02 . 2013-11-22 18:02 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-22 18:02 . 2013-11-22 18:02 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2013-11-22 18:02 . 2013-11-22 18:02 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2013-11-22 18:02 . 2013-11-22 18:02 454656 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-11-22 18:02 . 2013-11-22 18:02 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-22 18:02 . 2013-11-22 18:02 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-22 18:02 . 2013-11-22 18:02 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-22 18:02 . 2013-11-22 18:02 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-22 18:02 . 2013-11-22 18:02 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-22 18:02 . 2013-11-22 18:02 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-11-22 18:02 . 2013-11-22 18:02 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-22 18:02 . 2013-11-22 18:02 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-22 18:02 . 2013-11-22 18:02 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-22 18:02 . 2013-11-22 18:02 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-22 18:02 . 2013-11-22 18:02 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-22 18:02 . 2013-11-22 18:02 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-22 18:02 . 2013-11-22 18:02 247808 ----a-w- c:\windows\system32\msls31.dll 2013-11-22 18:02 . 2013-11-22 18:02 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-22 18:02 . 2013-11-22 18:02 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-22 18:02 . 2013-11-22 18:02 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-22 18:02 . 2013-11-22 18:02 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-22 18:02 . 2013-11-22 18:02 195584 ----a-w- c:\windows\system32\msrating.dll 2013-11-22 18:02 . 2013-11-22 18:02 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-22 18:02 . 2013-11-22 18:02 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-22 18:02 . 2013-11-22 18:02 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-22 18:02 . 2013-11-22 18:02 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-22 18:02 . 2013-11-22 18:02 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-22 18:02 . 2013-11-22 18:02 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-22 18:02 . 2013-11-22 18:02 626176 ----a-w- c:\windows\system32\msfeeds.dll 2013-11-22 18:02 . 2013-11-22 18:02 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-22 18:02 . 2013-11-22 18:02 548352 ----a-w- c:\windows\system32\vbscript.dll 2013-11-22 18:02 . 2013-11-22 18:02 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-22 18:02 . 2013-11-22 18:02 413696 ----a-w- c:\windows\system32\html.iec 2013-11-22 18:02 . 2013-11-22 18:02 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-22 18:02 . 2013-11-22 18:02 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-22 18:02 . 2013-11-22 18:02 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-11-22 18:02 . 2013-11-22 18:02 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-11-22 18:02 . 2013-11-22 18:02 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-11-22 18:02 . 2013-11-22 18:02 235520 ----a-w- c:\windows\system32\url.dll 2013-11-22 18:02 . 2013-11-22 18:02 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-11-22 18:02 . 2013-11-22 18:02 143872 ----a-w- c:\windows\system32\wextract.exe 2013-11-22 18:02 . 2013-11-22 18:02 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-22 18:02 . 2013-11-22 18:02 101376 ----a-w- c:\windows\system32\inseng.dll 2013-11-22 18:02 . 2013-11-22 18:02 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-11-22 18:02 . 2013-11-22 18:02 774144 ----a-w- c:\windows\system32\jscript.dll 2013-11-22 18:02 . 2013-11-22 18:02 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-11-22 18:02 . 2013-11-22 18:02 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-11-22 18:02 . 2013-11-22 18:02 147968 ----a-w- c:\windows\system32\occache.dll 2013-11-22 18:02 . 2013-11-22 18:02 13824 ----a-w- c:\windows\system32\mshta.exe 2013-11-22 18:02 . 2013-11-22 18:02 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-20 14:31 . 2013-11-20 14:31 2103040 ----a-w- c:\windows\system32\WavesGUILib64.dll 2013-11-20 14:31 . 2013-11-20 14:31 2810072 ----a-w- c:\windows\system32\RtPgEx64.dll 2013-11-20 14:31 . 2013-11-20 14:31 1662024 ----a-w- c:\windows\system32\RTSnMg64.cpl 2013-11-20 14:31 . 2013-11-20 14:31 3707864 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys 2013-11-20 14:31 . 2013-11-20 14:31 2587864 ----a-w- c:\windows\system32\RtkAPO64.dll 2013-11-20 14:31 . 2013-11-20 14:31 617176 ----a-w- c:\windows\system32\RtDataProc64.dll 2013-11-20 14:31 . 2013-11-20 14:31 153304 ----a-w- c:\windows\system32\RCoInstII64.dll 2013-11-20 14:31 . 2013-11-20 14:31 1286360 ----a-w- c:\windows\system32\RTCOM64.dll 2013-11-20 14:31 . 2013-11-20 14:31 1021656 ----a-w- c:\windows\system32\RtkApi64.dll 2013-11-20 14:31 . 2013-11-20 14:31 628504 ----a-w- c:\windows\system32\MBTHX64.dll 2013-11-20 14:31 . 2013-11-20 14:31 563992 ----a-w- c:\windows\SysWow64\MBTHX32.dll 2013-11-20 14:31 . 2013-11-20 14:31 397080 ----a-w- c:\windows\system32\MBWrp64.dll 2013-11-20 14:31 . 2013-11-20 14:31 2036992 ----a-w- c:\windows\system32\MaxxAudioEQ64.dll 2013-11-20 14:31 . 2013-11-20 14:31 1012992 ----a-w- c:\windows\system32\MaxxAudioAPOShell64.dll 2013-11-20 14:31 . 2013-11-20 14:31 2743328 ----a-w- c:\windows\system32\FMAPO64.dll 2013-11-20 14:31 . 2013-11-20 14:31 113576 ----a-w- c:\windows\system32\CONEQMSAPOGUILibrary.dll 2013-11-20 14:30 . 2013-11-20 14:30 209096 ----a-w- c:\windows\system32\AERTAC64.dll 2013-11-19 10:21 . 2010-11-21 03:27 267936 ------w- c:\windows\system32\MpSigStub.exe 2013-10-31 21:40 . 2013-08-01 17:34 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe 2013-10-30 19:56 . 2013-10-30 19:56 49048 ----a-w- c:\windows\system32\drivers\asahci64.sys 2013-10-30 19:56 . 2013-10-30 19:56 28928 ----a-w- c:\windows\system32\drivers\Lycosa.sys 2013-10-23 10:30 . 2013-11-01 15:35 9524088 ----a-w- c:\windows\SysWow64\nvcuda.dll 2013-10-23 10:30 . 2013-11-01 15:35 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll 2013-10-23 10:30 . 2013-11-01 15:35 696096 ----a-w- c:\windows\system32\NvFBC64.dll 2013-10-23 10:30 . 2013-11-01 15:35 655136 ----a-w- c:\windows\system32\NvIFR64.dll 2013-10-23 10:30 . 2013-11-01 15:35 599840 ----a-w- c:\windows\SysWow64\NvFBC.dll 2013-10-23 10:30 . 2013-11-01 15:35 560416 ----a-w- c:\windows\SysWow64\NvIFR.dll 2013-10-23 10:30 . 2013-11-01 15:35 479520 ----a-w- c:\windows\system32\nvEncodeAPI64.dll 2013-10-23 10:30 . 2013-11-01 15:35 405280 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll 2013-10-23 10:30 . 2013-11-01 15:35 317472 ----a-w- c:\windows\system32\nvoglshim64.dll 2013-10-23 10:30 . 2013-11-01 15:35 3131680 ----a-w- c:\windows\system32\nvcuvid.dll 2013-10-23 10:30 . 2013-11-01 15:35 3124512 ----a-w- c:\windows\system32\nvcuvenc.dll 2013-10-23 10:30 . 2013-11-01 15:35 30344480 ----a-w- c:\windows\system32\nvoglv64.dll 2013-10-23 10:30 . 2013-11-01 15:35 2946848 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2013-10-23 10:30 . 2013-11-01 15:35 2747168 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2013-10-23 10:30 . 2013-11-01 15:35 266984 ----a-w- c:\windows\SysWow64\nvoglshim32.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] 2013-11-27 21:34 116248 ----a-w- c:\program files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{b67b3dbb-c1c9-49d2-b016-2748b0b5017e}] 2013-10-22 19:29 249632 ----a-w- c:\program files (x86)\BatBrowse\BatBrowseBHO.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll" [2013-11-27 116248] . [HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Advanced SystemCare 7"="c:\program files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" [2013-11-11 2283808] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576] "Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-09-27 559696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage-Technologie;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MSICDSetup;MSICDSetup;d:\cdriver64.sys;d:\CDriver64.sys [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 NTIOLib_1_0_C;NTIOLib_1_0_C;d:\ntiolib_x64.sys;d:\NTIOLib_X64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x] S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x] S2 AdvancedSystemCareService7;Advanced SystemCare Service 7;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 LavasoftAdAwareService11;Ad-Aware Service 11;c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe;c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe [x] S2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x] S2 MSI_OTPService;MSI_OTPService;c:\program files (x86)\MSI\OTPService\OTPService.exe;c:\program files (x86)\MSI\OTPService\OTPService.exe [x] S2 MSI_SuperCharger;MSI_SuperCharger;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe;c:\program files (x86)\MSI\Super-Charger\ChargeService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 Update BatBrowse;Update BatBrowse;c:\program files (x86)\BatBrowse\updateBatBrowse.exe;c:\program files (x86)\BatBrowse\updateBatBrowse.exe [x] S2 Util BatBrowse;Util BatBrowse;c:\program files (x86)\BatBrowse\bin\utilBatBrowse.exe;c:\program files (x86)\BatBrowse\bin\utilBatBrowse.exe [x] S3 Lycosa;Lycosa Keyboard;c:\windows\system32\drivers\Lycosa.sys;c:\windows\SYSNATIVE\drivers\Lycosa.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 NTIOLib_1_0_3;NTIOLib_1_0_3;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys;c:\program files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x] S3 NTIOLib_1_0_T;NTIOLib_1_0_T;c:\program files (x86)\MSI\OTPService\NTIOLib_X64.sys;c:\program files (x86)\MSI\OTPService\NTIOLib_X64.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - NTIOLIB_1_0_3 . Inhalt des "geplante Tasks" Ordners . 2013-12-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-12 19:10] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] 2013-11-27 21:34 132264 ----a-w- c:\program files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll" [2013-11-27 132264] . [HKEY_CLASSES_ROOT\CLSID\{6c97a91e-4524-4019-86af-2aa2d567bf5c}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-11-20 7204568] "Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-10-18 1028384] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-10-18 1063200] "CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2012-03-09 462712] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 1266912] "AdAwareTray"="c:\program files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe" [2013-12-11 3987288] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mDefault_Page_URL = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyServer = localhost:8080 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ FF - prefs.js: keyword.URL - hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= FF - ExtSQL: 2013-11-20 16:51; ascsurfingprotection@iobit.com; c:\users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\extensions\ascsurfingprotection@iobit.com FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: browser.turbo.enabled - true FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.chrome.favicons - false FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: content.notify.ontimer - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.switch.threshold - 750000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . SafeBoot-IMFservice HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start BHO-{10921475-03CE-4E04-90CE-E2E7EF20C814} - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.bmp.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DIB\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.bmp.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ICO\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.ico.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JFIF\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.jpg.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPE\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.jpg.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPEG\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.jpg.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPG\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.jpg.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PNG\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.png.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIF\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.tif.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIFF\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.tif.15.4" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WDP\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLive.PhotoGallery.wdp.15.4" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\IObit\Advanced SystemCare 7\Monitor.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-12-23 22:27:40 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-12-23 21:27 . Vor Suchlauf: 15 Verzeichnis(se), 79.763.668.992 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 79.241.478.144 Bytes frei . - - End Of File - - D29AC7B0F985986CAC1C08B73E565709 |
24.12.2013, 10:57 | #6 |
/// the machine /// TB-Ausbilder | Tabs öffnen sich selbstständig, auch in Spielen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Tabs öffnen sich selbstständig, auch in Spielen. |
24.12.2013, 14:21 | #7 |
| Tabs öffnen sich selbstständig, auch in Spielen.Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.12.24.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Nastagar :: NASTAGAR-PC [Administrator] Schutz: Aktiviert 24.12.2013 12:42:21 MBAM-log-2013-12-24 (12-46-10).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 261624 Laufzeit: 3 Minute(n), 20 Sekunde(n) Infizierte Speicherprozesse: 2 C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe (PUP.Optional.BatBrowse.A) -> 2876 -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe (PUP.Optional.BatBrowse.A) -> 3036 -> Keine Aktion durchgeführt. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 8 HKCR\CLSID\{b67b3dbb-c1c9-49d2-b016-2748b0b5017e} (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B67B3DBB-C1C9-49D2-B016-2748B0B5017E} (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DigitalSite (PUP.Optional.DigitalSites.A) -> Keine Aktion durchgeführt. HKLM\SYSTEM\CurrentControlSet\Services\Update BatBrowse (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. HKLM\SYSTEM\CurrentControlSet\Services\Util BatBrowse (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\BatBrowse (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\BatBrowse (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 1 HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0X2O1C0R2R1R -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 4 C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\plugins (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 18 C:\Program Files (x86)\BatBrowse\BatBrowseBHO.dll (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc\UpdateTask.exe (PUP.Optional.DigitalSites.A) -> Keine Aktion durchgeführt. C:\Users\Gast\Downloads\FreeYouTubeToMP3Converter31212.exe (PUP.Optional.OpenCandy) -> Keine Aktion durchgeführt. C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc\config.dat (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt. C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc\prod.dat (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt. C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc\STTL.DAT (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt. C:\Users\Nastagar\AppData\Roaming\DigitalSite\UpdateProc\TTL.DAT (PUP.Optional.DigitalSite.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\BatBrowse.ico (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\BatBrowseUninstall.exe (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\updateBatBrowse.InstallState (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\sqlite3.dll (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.InstallState (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\plugins\BatBrowse.CompatibilityChecker.dll (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\plugins\BatBrowse.FFUpdate.dll (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\plugins\BatBrowse.GCUpdate.dll (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. C:\Program Files (x86)\BatBrowse\bin\plugins\BatBrowse.IEUpdate.dll (PUP.Optional.BatBrowse.A) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter # AdwCleaner v3.016 - Bericht erstellt am 24/12/2013 um 12:52:23 # Aktualisiert 23/12/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Nastagar - NASTAGAR-PC # Gestartet von : C:\Users\Nastagar\Desktop\Trojaner kicken\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\blekko toolbars Ordner Gelöscht : C:\Program Files (x86)\BatBrowse Ordner Gelöscht : C:\Program Files (x86)\Toolbar Cleaner Ordner Gelöscht : C:\Users\Nastagar\AppData\Local\Max Secure Software Ordner Gelöscht : C:\Users\Nastagar\AppData\LocalLow\adawaretb Ordner Gelöscht : C:\Users\Nastagar\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z Ordner Gelöscht : C:\Users\Nastagar\AppData\Roaming\digitalsite Ordner Gelöscht : C:\Users\Nastagar\AppData\Roaming\Systweak Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\Search Settings Ordner Gelöscht : C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\adawaretb Ordner Gelöscht : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vhhf85px.default\adawaretb Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp Schlüssel Gelöscht : HKCU\Software\Classes\pokki Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateBatBrowse_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateBatBrowse_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88CCA982-C030-4B27-8FBC-201189970FDE} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88CCA982-C030-4B27-8FBC-201189970FDE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}] Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Search Settings Schlüssel Gelöscht : HKLM\Software\adawaretb Schlüssel Gelöscht : HKLM\Software\eSafeSecControl Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BatBrowse ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\prefs.js ] [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vhhf85px.default\prefs.js ] ************************* AdwCleaner[R0].txt - [4761 octets] - [24/12/2013 12:50:03] AdwCleaner[R1].txt - [4821 octets] - [24/12/2013 12:51:39] AdwCleaner[S0].txt - [4638 octets] - [24/12/2013 12:52:23] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4698 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by Nastagar on 24.12.2013 at 12:56:14,40 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Nastagar\appdata\local\adawarebp" ~~~ FireFox Successfully deleted: [Folder] C:\Users\Nastagar\AppData\Roaming\mozilla\firefox\profiles\ghk796ar.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} Successfully deleted the following from C:\Users\Nastagar\AppData\Roaming\mozilla\firefox\profiles\ghk796ar.default\prefs.js user_pref("keyword.URL", "hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q="); Emptied folder: C:\Users\Nastagar\AppData\Roaming\mozilla\firefox\profiles\ghk796ar.default\minidumps [12 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 24.12.2013 at 13:03:24,26 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
25.12.2013, 14:29 | #8 |
/// the machine /// TB-Ausbilder | Tabs öffnen sich selbstständig, auch in Spielen.ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.12.2013, 18:16 | #9 |
| Tabs öffnen sich selbstständig, auch in Spielen.Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=58baac17c925ed4693cce7b126032317 # engine=16436 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-12-29 03:23:54 # local_time=2013-12-29 04:23:54 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 13900369 139960484 0 0 # scanned=189204 # found=0 # cleaned=0 # scan_time=12728 Code:
ATTFilter Results of screen317's Security Check version 0.99.77 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Ad-Aware Antivirus Antivirus out of date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.9.900.170 Adobe Reader XI Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.1.5152.0\AdAwareService.exe Lavasoft Ad-Aware Antivirus Ad-Aware Antivirus 11.1.5152.0\AdAwareTray.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 Ran by Nastagar (administrator) on NASTAGAR-PC on 29-12-2013 18:11:23 Running from C:\Users\Nastagar\Desktop\Trojaner kicken Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Program Files (x86)\MSI\OTPService\OTPService.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Windows\System32\UI0Detect.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASC.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7204568 2013-11-20] (Realtek Semiconductor) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-10-18] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [CDAServer] - C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [462712 2012-03-09] () HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [1266912 2013-10-23] (Microsoft Corporation) HKLM\...\Run: [AdAwareTray] - C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareTray.exe [3987288 2013-12-11] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft) HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2283808 2013-11-11] (IObit) HKU\Gast\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Gast\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () ==================== Internet (Whitelisted) ==================== ProxyServer: localhost:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x218546485A4FCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - DefaultScope {CA085DE2-EDBE-4E69-AD55-4D8317F6E6B0} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} SearchScopes: HKCU - {CA085DE2-EDBE-4E69-AD55-4D8317F6E6B0} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=198484&p={searchTerms} BHO: No Name - {10921475-03CE-4E04-90CE-E2E7EF20C814} - No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.1 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\Extensions\ascsurfingprotection@iobit.com FF Extension: Address Bar Search - C:\Users\Nastagar\AppData\Roaming\Mozilla\Firefox\Profiles\ghk796ar.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9}.xpi ==================== Services (Whitelisted) ================= R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [878368 2013-10-25] (IObit) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-08-09] (Intel Corporation) R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5152.0\AdAwareService.exe [513736 2013-12-11] () R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-10-25] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSI_OTPService; C:\Program Files (x86)\MSI\OTPService\OTPService.exe [252432 2012-04-12] () R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [144008 2012-12-21] (MSI) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2013-10-23] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [348376 2013-10-23] (Microsoft Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-31] () ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49048 2013-10-30] (Asmedia Technology) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [88480 2013-06-10] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [26072 2012-08-07] (Intel Corporation) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [46400 2013-06-10] () R3 Lycosa; C:\Windows\System32\drivers\Lycosa.sys [28928 2013-10-30] (Razer USA Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [248240 2013-09-27] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [134944 2013-09-27] (Microsoft Corporation) R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI) R3 NTIOLib_1_0_T; C:\Program Files (x86)\MSI\OTPService\NTIOLib_X64.sys [14136 2009-10-05] (MSI) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-28] (NVIDIA Corporation) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [329800 2013-07-17] (BitDefender S.R.L.) S3 catchme; \??\C:\Combofix\catchme.sys [x] S3 MSICDSetup; \??\D:\CDriver64.sys [x] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-29 12:38 - 2013-12-29 12:38 - 00000000 ____D C:\Program Files (x86)\ESET 2013-12-28 11:38 - 2013-12-28 11:38 - 00000355 _____ C:\Users\Gast\Desktop\Computer - Verknüpfung.lnk 2013-12-27 11:21 - 2013-12-28 11:05 - 00020525 _____ C:\Users\Gast\Desktop\OpenDocument Text (neu).odt 2013-12-25 20:39 - 2013-12-29 12:31 - 00001973 _____ C:\Windows\setupact.log 2013-12-25 20:39 - 2013-12-25 20:39 - 00000602 _____ C:\Windows\PFRO.log 2013-12-25 20:39 - 2013-12-25 20:39 - 00000000 _____ C:\Windows\setuperr.log 2013-12-24 23:07 - 2013-12-24 23:32 - 00000000 ____D C:\Users\Nastagar\AppData\Local\adawarebp 2013-12-24 12:56 - 2013-12-24 12:56 - 00000000 ____D C:\Windows\ERUNT 2013-12-24 12:49 - 2013-12-24 12:52 - 00000000 ____D C:\AdwCleaner 2013-12-24 12:35 - 2013-12-24 12:35 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Malwarebytes 2013-12-24 12:35 - 2013-12-24 12:35 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-24 12:35 - 2013-12-24 12:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-12-24 12:35 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-12-23 22:27 - 2013-12-23 22:27 - 00030315 _____ C:\ComboFix.txt 2013-12-23 21:58 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-12-23 21:58 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-12-23 21:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-12-23 21:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-12-23 21:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-12-23 21:58 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-12-23 21:58 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-12-23 21:58 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-12-23 21:54 - 2013-12-23 22:27 - 00000000 ____D C:\Qoobox 2013-12-23 21:54 - 2013-12-23 22:25 - 00000000 ____D C:\Windows\erdnt 2013-12-23 21:50 - 2013-12-23 21:51 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\GetRightToGo 2013-12-23 11:15 - 2013-12-23 11:15 - 00000000 ____D C:\Users\Gast\AppData\Local\adawarebp 2013-12-22 17:45 - 2013-12-29 18:11 - 00000000 ____D C:\FRST 2013-12-22 15:02 - 2013-12-22 15:02 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\LavasoftStatistics 2013-12-22 15:00 - 2013-12-22 15:00 - 00000000 _____ C:\Users\Nastagar\defogger_reenable 2013-12-22 14:35 - 2013-12-22 14:35 - 00000000 ____D C:\Program Files\Lavasoft 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2013-12-22 14:33 - 2013-12-22 14:33 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Lavasoft 2013-12-22 14:32 - 2013-12-22 14:32 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-12-22 14:31 - 2013-12-22 14:31 - 00000000 ____D C:\ProgramData\Lavasoft 2013-12-22 14:17 - 2013-12-29 18:11 - 00000000 ____D C:\Users\Nastagar\Desktop\Trojaner kicken 2013-12-22 13:32 - 2013-12-22 13:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 12:42 - 2013-12-20 12:42 - 00000000 ____D C:\Users\Gast\Documents\Fax 2013-12-13 09:09 - 2013-12-13 09:09 - 00000000 _____ C:\asc_rdflag 2013-12-11 09:48 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-11 09:48 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-11 09:48 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2013-12-11 09:48 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2013-12-11 09:46 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 09:46 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 09:46 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-11 09:46 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-11 09:46 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-11 09:46 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-11 09:46 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 09:46 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 09:46 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-11 09:46 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-11 09:46 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 09:46 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 09:46 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-11 09:46 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-11 09:46 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-11 09:46 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-11 09:46 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-11 09:46 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 09:46 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-11 09:46 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-11 09:46 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-11 09:46 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 09:46 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 09:46 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-11 09:46 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-11 09:46 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 09:46 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 09:46 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-11 09:46 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-11 09:46 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-11 09:46 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 09:18 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2013-12-11 09:18 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-11 09:18 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-11 09:18 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-12-11 09:18 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-11 09:18 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2013-12-11 09:18 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 09:18 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 09:18 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll 2013-12-11 09:18 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 09:18 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 09:18 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx 2013-12-11 09:18 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll 2013-12-11 09:18 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 09:18 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-11 09:18 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe 2013-12-11 09:18 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe 2013-12-11 09:18 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 09:18 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-06 12:03 - 2013-12-06 12:03 - 00002976 _____ C:\Windows\System32\Tasks\{E6E37F8B-75D8-448C-AEEC-4F35915AF4C9} 2013-12-05 10:00 - 2013-12-05 10:00 - 00002976 _____ C:\Windows\System32\Tasks\{4F809451-0DD4-4218-9C86-45426F41053F} 2013-12-05 09:59 - 2013-12-05 09:59 - 00002976 _____ C:\Windows\System32\Tasks\{3ABA0F6D-93F2-47D6-8926-997EB59E09B5} 2013-12-05 09:57 - 2013-12-05 09:57 - 00000961 _____ C:\Users\Public\Desktop\Wachdienst in der Bundeswehr.lnk 2013-12-05 09:51 - 2002-05-01 18:51 - 00011776 ____N (Microsoft Corporation) C:\Windows\system\MCIQTZ.DRV 2013-12-05 09:29 - 2013-12-13 09:09 - 60731392 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2013-12-05 09:29 - 2013-12-13 09:09 - 00897024 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2013-12-05 09:29 - 2013-12-13 09:09 - 00069632 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2013-12-05 09:29 - 2013-12-13 09:09 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2013-12-01 13:42 - 2013-12-01 13:42 - 00000000 ____D C:\ProgramData\Razer ==================== One Month Modified Files and Folders ======= 2013-12-29 18:11 - 2013-12-22 17:45 - 00000000 ____D C:\FRST 2013-12-29 18:11 - 2013-12-22 14:17 - 00000000 ____D C:\Users\Nastagar\Desktop\Trojaner kicken 2013-12-29 17:52 - 2013-04-30 15:36 - 01701467 _____ C:\Windows\WindowsUpdate.log 2013-12-29 17:16 - 2013-05-12 23:33 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-29 12:42 - 2011-04-12 08:43 - 00698110 _____ C:\Windows\system32\perfh007.dat 2013-12-29 12:42 - 2011-04-12 08:43 - 00148646 _____ C:\Windows\system32\perfc007.dat 2013-12-29 12:42 - 2009-07-14 06:13 - 01617458 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-29 12:40 - 2013-05-12 23:10 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\UseNeXT 2013-12-29 12:38 - 2013-12-29 12:38 - 00000000 ____D C:\Program Files (x86)\ESET 2013-12-29 12:38 - 2009-07-14 05:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-29 12:38 - 2009-07-14 05:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-29 12:34 - 2013-05-13 17:58 - 00000000 ____D C:\Program Files (x86)\Steam 2013-12-29 12:31 - 2013-12-25 20:39 - 00001973 _____ C:\Windows\setupact.log 2013-12-29 12:31 - 2013-04-30 16:10 - 00000000 ____D C:\ProgramData\NVIDIA 2013-12-29 12:31 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-28 11:38 - 2013-12-28 11:38 - 00000355 _____ C:\Users\Gast\Desktop\Computer - Verknüpfung.lnk 2013-12-28 11:10 - 2013-09-20 15:15 - 00000000 ____D C:\Users\Gast\Desktop\Neuer Ordner 2013-12-28 11:05 - 2013-12-27 11:21 - 00020525 _____ C:\Users\Gast\Desktop\OpenDocument Text (neu).odt 2013-12-28 10:55 - 2013-11-24 10:35 - 00000099 _____ C:\Users\Public\LMDebug.log 2013-12-25 20:39 - 2013-12-25 20:39 - 00000602 _____ C:\Windows\PFRO.log 2013-12-25 20:39 - 2013-12-25 20:39 - 00000000 _____ C:\Windows\setuperr.log 2013-12-24 23:32 - 2013-12-24 23:07 - 00000000 ____D C:\Users\Nastagar\AppData\Local\adawarebp 2013-12-24 12:56 - 2013-12-24 12:56 - 00000000 ____D C:\Windows\ERUNT 2013-12-24 12:52 - 2013-12-24 12:49 - 00000000 ____D C:\AdwCleaner 2013-12-24 12:49 - 2013-05-14 20:33 - 00000000 ____D C:\Users\Nastagar\Desktop\Sicherheitszeug und Tools 2013-12-24 12:35 - 2013-12-24 12:35 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Malwarebytes 2013-12-24 12:35 - 2013-12-24 12:35 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-24 12:35 - 2013-12-24 12:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-12-24 09:25 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-23 22:27 - 2013-12-23 22:27 - 00030315 _____ C:\ComboFix.txt 2013-12-23 22:27 - 2013-12-23 21:54 - 00000000 ____D C:\Qoobox 2013-12-23 22:25 - 2013-12-23 21:54 - 00000000 ____D C:\Windows\erdnt 2013-12-23 22:24 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-12-23 22:14 - 2013-11-20 22:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-12-23 22:13 - 2013-11-21 00:05 - 00000376 _____ C:\Windows\wininit.ini 2013-12-23 22:13 - 2013-11-20 22:04 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-12-23 21:51 - 2013-12-23 21:50 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\GetRightToGo 2013-12-23 18:04 - 2013-05-14 21:14 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\vlc 2013-12-23 11:15 - 2013-12-23 11:15 - 00000000 ____D C:\Users\Gast\AppData\Local\adawarebp 2013-12-23 11:15 - 2013-11-20 15:51 - 00000000 ____D C:\ProgramData\ProductData 2013-12-23 00:03 - 2013-10-29 20:03 - 00000107 _____ C:\Users\Nastagar\AppData\Roaming\WB.CFG 2013-12-23 00:03 - 2013-10-29 20:03 - 00000006 _____ C:\Users\Nastagar\AppData\Roaming\WBPU-TTL.DAT 2013-12-22 18:31 - 2013-05-12 23:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-12-22 15:02 - 2013-12-22 15:02 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\LavasoftStatistics 2013-12-22 15:00 - 2013-12-22 15:00 - 00000000 _____ C:\Users\Nastagar\defogger_reenable 2013-12-22 15:00 - 2013-05-12 22:24 - 00000000 ____D C:\Users\Nastagar 2013-12-22 14:35 - 2013-12-22 14:35 - 00000000 ____D C:\Program Files\Lavasoft 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\ProgramData\Ad-Aware Browsing Protection 2013-12-22 14:34 - 2013-12-22 14:34 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2013-12-22 14:33 - 2013-12-22 14:33 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\Lavasoft 2013-12-22 14:32 - 2013-12-22 14:32 - 00000000 ____D C:\Program Files\Common Files\Lavasoft 2013-12-22 14:31 - 2013-12-22 14:31 - 00000000 ____D C:\ProgramData\Lavasoft 2013-12-22 13:32 - 2013-12-22 13:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-20 12:54 - 2013-11-28 11:29 - 00000000 ____D C:\Users\Gast\Documents\Scan 2013-12-20 12:42 - 2013-12-20 12:42 - 00000000 ____D C:\Users\Gast\Documents\Fax 2013-12-14 18:46 - 2013-08-01 21:56 - 00000000 ____D C:\Windows\system32\MRT 2013-12-14 18:46 - 2013-05-22 19:09 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-14 18:46 - 2013-05-12 22:19 - 00001912 _____ C:\Windows\epplauncher.mif 2013-12-14 18:44 - 2013-05-12 22:18 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-12-14 18:44 - 2013-05-12 22:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2013-12-13 09:09 - 2013-12-13 09:09 - 00000000 _____ C:\asc_rdflag 2013-12-13 09:09 - 2013-12-05 09:29 - 60731392 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2013-12-13 09:09 - 2013-12-05 09:29 - 00897024 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2013-12-13 09:09 - 2013-12-05 09:29 - 00069632 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2013-12-13 09:09 - 2013-12-05 09:29 - 00024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2013-12-12 19:06 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-11 23:17 - 2013-08-01 18:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-12-11 18:04 - 2013-08-01 18:34 - 00214392 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-12-11 10:55 - 2013-05-28 19:33 - 00000000 ____D C:\Program Files (x86)\Origin 2013-12-11 10:30 - 2009-07-14 05:45 - 00294712 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-10 20:10 - 2013-05-12 23:33 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-10 20:10 - 2013-05-12 23:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-10 20:10 - 2013-05-12 23:33 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-08 16:40 - 2013-08-28 21:26 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\WinRAR 2013-12-07 12:31 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-06 12:03 - 2013-12-06 12:03 - 00002976 _____ C:\Windows\System32\Tasks\{E6E37F8B-75D8-448C-AEEC-4F35915AF4C9} 2013-12-06 11:59 - 2013-04-30 15:45 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-12-05 10:00 - 2013-12-05 10:00 - 00002976 _____ C:\Windows\System32\Tasks\{4F809451-0DD4-4218-9C86-45426F41053F} 2013-12-05 09:59 - 2013-12-05 09:59 - 00002976 _____ C:\Windows\System32\Tasks\{3ABA0F6D-93F2-47D6-8926-997EB59E09B5} 2013-12-05 09:57 - 2013-12-05 09:57 - 00000961 _____ C:\Users\Public\Desktop\Wachdienst in der Bundeswehr.lnk 2013-12-05 09:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system 2013-12-05 09:47 - 2013-05-12 22:24 - 00000000 ____D C:\Users\Nastagar\AppData\Local\VirtualStore 2013-12-04 23:58 - 2013-05-12 23:19 - 00000000 ____D C:\Users\Nastagar\Desktop\Bilder 2013-12-04 13:08 - 2013-10-31 22:40 - 00000000 ____D C:\Program Files (x86)\Battlelog Web Plugins 2013-12-01 13:43 - 2013-05-14 20:43 - 00000000 ____D C:\Program Files (x86)\IObit 2013-12-01 13:42 - 2013-12-01 13:42 - 00000000 ____D C:\ProgramData\Razer 2013-12-01 13:42 - 2013-05-14 20:43 - 00000000 ____D C:\ProgramData\IObit 2013-11-30 20:29 - 2013-07-02 18:57 - 00000000 ____D C:\Users\Nastagar\AppData\Roaming\dvdcss Some content of TEMP: ==================== C:\Users\Nastagar\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-22 18:14 ==================== End Of Log ============================ --- --- --- In den letzten Tagen keine Probleme mehr. Ich nehme an, du kennst meinen Rechner jetzt vermutlich besser als ich selbst. Kannst du mir empfehlen welche Progrmme aktuell ausreichenden Schutz bieten? |
30.12.2013, 11:12 | #10 |
/// the machine /// TB-Ausbilder | Tabs öffnen sich selbstständig, auch in Spielen. Ich empfehle immer Emisoft Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.01.2014, 08:02 | #11 |
| Tabs öffnen sich selbstständig, auch in Spielen. Ok, soweit alles klar, eine letzte Frage noch. Ich hab Advanced System Care 7 und Adaware Antivir, ASC7 bereinigt aber auch die registry...... soll ich das Programm besser loswerden und ersetzen? |
03.01.2014, 12:51 | #12 |
/// the machine /// TB-Ausbilder | Tabs öffnen sich selbstständig, auch in Spielen. Ich würd beides gegen was anständiges ersetzen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Tabs öffnen sich selbstständig, auch in Spielen. |
antiviren, brauch, desktop, fliege, hoffe, neue, neuen, pup.optional.batbrowse.a, pup.optional.digitalsite.a, pup.optional.digitalsites.a, pup.optional.installcore.a, pup.optional.opencandy, selbstständig, spiel, spiele, spielen, tabs öffnen, tools, werbung, zusätzlicher, öffnen, öffnet, öfters |