|
Plagegeister aller Art und deren Bekämpfung: TR/Dropper.Gen-Avira-Windows 7 32 BitWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.01.2014, 13:06 | #1 |
| TR/Dropper.Gen-Avira-Windows 7 32 Bit Hallo an die Communitiy! Mein Virenschutzprogramm (Avira) macht mich seit kurzer Zeit auf ein Virus/unerwünschtes Programm namens "TR/Dropper.Gen" aufmerksam. Ich hab über Google einige Beiträge über dieses Thema in diesem Forum gefunden und bitte nun um Hilfe. Ich benutze Windows 7 32 Bit Home Premium. Grüße Niggel333 |
21.01.2014, 13:18 | #2 |
/// the machine /// TB-Ausbilder | TR/Dropper.Gen-Avira-Windows 7 32 Bit hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
21.01.2014, 13:59 | #3 |
| TR/Dropper.Gen-Avira-Windows 7 32 Bit Danke für die schnelle Antwort!
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-01-2014 Ran by Fabian (administrator) on FABIAN-PC on 21-01-2014 13:56:33 Running from C:\Users\Fabian\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple, Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Connect\BackService.exe (Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe (Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Samsung) C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Valve Corporation) C:\Program Files\Steam\Steam.exe (Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Splashtop Inc.) C:\Program Files\Splashtop\Splashtop Connect IE\STCHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [STCAgent] - C:\Program Files\Splashtop\Splashtop Connect IE\STCAgent.exe [776064 2011-03-04] (Splashtop Inc.) HKLM\...\Run: [ZyngaGamesAgent] - C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe [841544 2010-11-15] (Splashtop Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-06-07] (Realtek Semiconductor) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [348664 2012-07-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - C:\Program Files\Ask.com\Updater\Updater.exe [1568976 2012-06-20] (Ask) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2008-03-28] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [267048 2008-03-30] (Apple Inc.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [185896 2013-10-28] (Geek Software GmbH) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844168 2013-05-18] (Samsung) HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1815464 2014-01-07] (Valve Corporation) AppInit_DLLs: C:\Windows\system32\nvinit.dll => C:\Windows\system32\nvinit.dll [201576 2013-02-25] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x41F793AE84ECCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) URLSearchHook: HKCU - Splashtop Connect SearchHook - {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files\Splashtop\Splashtop Connect IE\AddressBarSearch.dll (Splashtop Inc.) SearchScopes: HKCU - DefaultScope {6B02B0A8-8809-447d-85BE-B42C9CDA89B5} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPB648502E-BB23-4730-A089-25D4E464FEB5&q={searchTerms}&SSPV= SearchScopes: HKCU - {53BF67CF-B31A-43E3-8AB4-EFA6F2296173} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=80f22c25-0382-413d-afbe-787a928982ed&apn_sauid=C9F1F666-C303-4A38-A6EE-34A26979E43F SearchScopes: HKCU - {6B02B0A8-8809-447d-85BE-B42C9CDA89B5} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {9EB71124-A817-4c0f-B4C9-CE1F524393E6} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {EBB94A4B-A86F-4ad1-A484-9D929B783CC1} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH BHO: Splashtop Connect VisualBookmark - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files\Splashtop\Splashtop Connect IE\STC.dll (Splashtop Inc.) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKCU - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Tcpip\..\Interfaces\{747B7B48-3CFC-48EA-85EB-D67E18D1F350}: [NameServer]62.152.168.253 62.152.177.87 FireFox: ======== FF ProfilePath: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: about:home FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=80f22c25-0382-413d-afbe-787a928982ed&apn_ptnrs=%5EABT&apn_sauid=C9F1F666-C303-4A38-A6EE-34A26979E43F&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF SearchPlugin: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\searchplugins\conduit-search.xml FF Extension: Ask Toolbar - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\Extensions\toolbar@ask.com [2012-09-06] FF Extension: Adblock Plus - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-16] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-21] FF HKLM\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} FF Extension: Splashtop Connect Companion - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} [2012-09-02] FF HKLM\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} FF Extension: Splashtop Connect - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} [2012-09-02] FF HKLM\...\Firefox\Extensions: [{d9284e50-81fc-11da-a72b-0800200c9a66}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} FF Extension: Yoono - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} [2012-09-02] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [86224 2012-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [110032 2012-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [465360 2012-07-18] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [110592 2008-02-18] (Apple, Inc.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 SCBackService; C:\Program Files\Splashtop\Splashtop Connect\BackService.exe [477000 2010-11-15] (Splashtop Inc.) R2 WCUService_STC_FF; C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [493384 2011-03-24] (Splashtop Inc.) R2 WCUService_STC_IE; C:\Program Files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [497480 2011-03-22] (Splashtop Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [18544 2011-01-10] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-07-18] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-07-18] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2012-07-18] (Avira GmbH) R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [41600 2011-05-25] (Etron Technology Inc) R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [61824 2011-05-25] (Etron Technology Inc) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-09-21] (Intel Corporation) S3 Ser2plx86; C:\Windows\System32\DRIVERS\ser2pl.sys [139776 2013-10-17] (Prolific Technology Inc.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH) S3 gdrv; \??\C:\Windows\gdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-21 13:56 - 2014-01-21 13:56 - 00014255 _____ C:\Users\Fabian\Desktop\FRST.txt 2014-01-21 13:56 - 2014-01-21 13:56 - 00000000 ____D C:\FRST 2014-01-21 13:55 - 2014-01-21 13:55 - 01222144 _____ (Farbar) C:\Users\Fabian\Desktop\FRST.exe 2014-01-21 12:49 - 2014-01-21 12:49 - 00110700 _____ C:\Users\Fabian\Downloads\OTL.Txt 2014-01-21 12:49 - 2014-01-21 12:49 - 00048124 _____ C:\Users\Fabian\Downloads\Extras.Txt 2014-01-21 12:38 - 2014-01-21 12:38 - 00602112 _____ (OldTimer Tools) C:\Users\Fabian\Downloads\OTL.exe 2014-01-15 12:16 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 12:16 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-13 00:42 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-13 00:42 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-13 00:42 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-13 00:42 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-13 00:42 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-13 00:42 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-13 00:42 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-13 00:42 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-13 00:42 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-13 00:42 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-13 00:42 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-13 00:42 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-13 00:42 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-13 00:42 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-13 00:42 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-13 00:42 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-13 00:42 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-13 00:42 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-13 00:42 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-12 13:57 - 2014-01-12 13:57 - 00001107 _____ C:\Users\Fabian\Desktop\Steam - Verknüpfung.lnk 2014-01-11 23:58 - 2014-01-11 23:58 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-11 23:58 - 2014-01-11 23:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00367104 _____ C:\Windows\system32\dxtmsft.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-11 23:58 - 2014-01-11 23:58 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00194048 _____ C:\Windows\system32\elshyph.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-11 23:58 - 2014-01-11 23:58 - 00061952 _____ C:\Windows\system32\MshtmlDac.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-11 20:09 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-11 20:09 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-11 20:09 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-11 20:09 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-11 20:09 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-11 20:09 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-11 20:09 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-11 20:09 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-11 20:09 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-11 20:09 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-11 20:09 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-11 20:09 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-11 20:09 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-11 20:09 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-11 20:09 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-11 20:09 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-11 20:09 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-11 20:09 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-11 20:09 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-11 20:09 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-11 20:09 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-11 20:09 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-11 20:09 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-11 20:09 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-11 20:09 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-11 20:09 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-11 20:09 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-11 20:09 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-11 20:09 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-11 20:09 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-11 20:09 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-11 20:09 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-11 20:09 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-11 20:09 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-11 20:09 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-11 20:09 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-11 20:09 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-11 20:09 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-11 20:09 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-11 20:09 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-11 20:09 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-11 20:09 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-01-11 20:09 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-01-11 20:09 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-01-11 20:09 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-01-11 20:09 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-01-11 20:09 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-01-11 20:09 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-01-11 20:09 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-01-11 20:09 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-01-11 20:09 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-01-11 20:09 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-01-11 20:09 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-01-11 19:13 - 2014-01-21 12:06 - 00000000 ____D C:\Program Files\Steam 2014-01-11 19:13 - 2014-01-11 19:13 - 00000875 _____ C:\Users\Public\Desktop\Steam.lnk 2014-01-11 19:11 - 2014-01-11 19:12 - 08531968 _____ C:\Users\Fabian\Downloads\SteamInstall_German.msi 2014-01-11 13:11 - 2013-10-17 19:02 - 00139776 _____ (Prolific Technology Inc.) C:\Windows\system32\Drivers\ser2pl.sys 2014-01-11 13:11 - 2005-08-03 16:05 - 00035892 _____ (Prolific Technology Inc.) C:\Windows\system32\SER9PL.sys 2014-01-11 13:11 - 2005-08-03 16:04 - 00026719 _____ C:\Windows\system32\SERSPL.VXD 2014-01-11 13:05 - 2014-01-11 13:20 - 00000000 ____D C:\Users\Fabian\Documents\gpsPhotoTagger_Workspace 2014-01-11 13:02 - 2014-01-11 13:02 - 00002370 _____ C:\Windows\DPINST.LOG 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D C:\Program Files\STMicroelectronics 2014-01-11 13:01 - 2014-01-11 13:01 - 00000804 _____ C:\Users\Public\Desktop\GPS Photo Tagger.lnk 2014-01-11 13:01 - 2014-01-11 13:01 - 00000000 ____D C:\Windows\Downloaded Installations 2013-12-22 15:10 - 2013-12-22 15:10 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-12-22 15:10 - 2013-12-22 15:10 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-22 15:10 - 2013-12-22 15:10 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-22 15:10 - 2013-12-22 15:10 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-12-22 15:10 - 2013-12-22 15:10 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-12-22 15:09 - 2014-01-12 00:00 - 00183927 _____ C:\Windows\IE11_main.log 2013-12-22 15:09 - 2013-12-22 15:09 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-22 15:09 - 2013-12-22 15:09 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-12-22 15:09 - 2013-12-22 15:09 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll ==================== One Month Modified Files and Folders ======= 2014-01-21 13:56 - 2014-01-21 13:56 - 00014255 _____ C:\Users\Fabian\Desktop\FRST.txt 2014-01-21 13:56 - 2014-01-21 13:56 - 00000000 ____D C:\FRST 2014-01-21 13:55 - 2014-01-21 13:55 - 01222144 _____ (Farbar) C:\Users\Fabian\Desktop\FRST.exe 2014-01-21 13:55 - 2012-09-02 20:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-21 13:33 - 2012-09-09 12:02 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Skype 2014-01-21 13:05 - 2009-07-14 05:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-21 13:05 - 2009-07-14 05:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-21 12:49 - 2014-01-21 12:49 - 00110700 _____ C:\Users\Fabian\Downloads\OTL.Txt 2014-01-21 12:49 - 2014-01-21 12:49 - 00048124 _____ C:\Users\Fabian\Downloads\Extras.Txt 2014-01-21 12:38 - 2014-01-21 12:38 - 00602112 _____ (OldTimer Tools) C:\Users\Fabian\Downloads\OTL.exe 2014-01-21 12:09 - 2012-09-02 18:27 - 01344797 _____ C:\Windows\WindowsUpdate.log 2014-01-21 12:06 - 2014-01-11 19:13 - 00000000 ____D C:\Program Files\Steam 2014-01-21 12:05 - 2012-11-19 01:33 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-21 12:05 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-21 12:05 - 2009-07-14 05:39 - 00088534 _____ C:\Windows\setupact.log 2014-01-17 16:53 - 2013-05-11 02:25 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\TS3Client 2014-01-16 12:13 - 2009-07-14 05:33 - 00278840 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-16 02:08 - 2013-10-06 19:34 - 00000000 ____D C:\Windows\system32\MRT 2014-01-16 02:07 - 2013-10-06 19:34 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-12 13:57 - 2014-01-12 13:57 - 00001107 _____ C:\Users\Fabian\Desktop\Steam - Verknüpfung.lnk 2014-01-12 13:52 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2014-01-12 12:53 - 2012-09-07 00:09 - 00000000 ____D C:\Program Files\Common Files\Steam 2014-01-12 12:53 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2014-01-12 00:00 - 2013-12-22 15:09 - 00183927 _____ C:\Windows\IE11_main.log 2014-01-11 23:58 - 2014-01-11 23:58 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-11 23:58 - 2014-01-11 23:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00367104 _____ C:\Windows\system32\dxtmsft.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-11 23:58 - 2014-01-11 23:58 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00194048 _____ C:\Windows\system32\elshyph.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-11 23:58 - 2014-01-11 23:58 - 00061952 _____ C:\Windows\system32\MshtmlDac.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-11 23:57 - 2013-05-10 19:43 - 00888237 _____ C:\Windows\IE10_main.log 2014-01-11 19:13 - 2014-01-11 19:13 - 00000875 _____ C:\Users\Public\Desktop\Steam.lnk 2014-01-11 19:13 - 2012-09-02 19:11 - 00000000 ____D C:\Users\Fabian 2014-01-11 19:12 - 2014-01-11 19:11 - 08531968 _____ C:\Users\Fabian\Downloads\SteamInstall_German.msi 2014-01-11 13:39 - 2012-09-02 19:14 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 13:20 - 2014-01-11 13:05 - 00000000 ____D C:\Users\Fabian\Documents\gpsPhotoTagger_Workspace 2014-01-11 13:11 - 2012-09-02 19:22 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2014-01-11 13:02 - 2014-01-11 13:02 - 00002370 _____ C:\Windows\DPINST.LOG 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D C:\Program Files\STMicroelectronics 2014-01-11 13:01 - 2014-01-11 13:01 - 00000804 _____ C:\Users\Public\Desktop\GPS Photo Tagger.lnk 2014-01-11 13:01 - 2014-01-11 13:01 - 00000000 ____D C:\Windows\Downloaded Installations 2014-01-11 13:01 - 2012-09-02 19:22 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2014-01-10 15:49 - 2011-06-19 23:29 - 00000000 ____D C:\patch 2014-01-10 15:09 - 2008-04-22 16:18 - 00000000 ___RD C:\Programme 2013-12-23 09:43 - 2012-09-02 19:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-12-22 15:10 - 2013-12-22 15:10 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-12-22 15:10 - 2013-12-22 15:10 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-22 15:10 - 2013-12-22 15:10 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-22 15:10 - 2013-12-22 15:10 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-12-22 15:10 - 2013-12-22 15:10 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-12-22 15:09 - 2013-12-22 15:09 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-22 15:09 - 2013-12-22 15:09 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-12-22 15:09 - 2013-12-22 15:09 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-12-22 15:06 - 2012-09-09 12:02 - 00000000 ___RD C:\Program Files\Skype 2013-12-22 15:06 - 2012-09-09 12:02 - 00000000 ____D C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Fabian\AppData\Local\Temp\AskSLib.dll C:\Users\Fabian\AppData\Local\Temp\Foxit Updater.exe C:\Users\Fabian\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Fabian\AppData\Local\Temp\nsd3FC3.exe C:\Users\Fabian\AppData\Local\Temp\nsd414A.exe C:\Users\Fabian\AppData\Local\Temp\nsi6733.exe C:\Users\Fabian\AppData\Local\Temp\nstF1C3.exe C:\Users\Fabian\AppData\Local\Temp\nsx65BB.exe C:\Users\Fabian\AppData\Local\Temp\setup.exe C:\Users\Fabian\AppData\Local\Temp\SkypeSetup.exe C:\Users\Fabian\AppData\Local\Temp\_isFEF7.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-19 12:52 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-01-2014 Ran by Fabian at 2014-01-21 13:57:05 Running from C:\Users\Fabian\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Apple Mobile Device Support (Version: 1.1.4.7 - Apple Inc.) Apple Software Update (Version: 2.0.2.92 - Apple Inc.) Ask Toolbar (Version: 1.15.26.0 - Ask.com) <==== ATTENTION Avira Free Antivirus (Version: 12.0.0.1167 - Avira) Avira SearchFree Toolbar plus Web Protection Updater (HKCU Version: 1.3.0.23930 - Ask.com) Bonjour (Version: 1.0.104 - Apple Inc.) Command & Conquer Die ersten 10 Jahre (Version: 1.00.0000 - Electronic Arts) Etron USB3.0 Host Controller (Version: 0.101 - Etron Technology) Hidden FileParade Bundle (Version: 1.0.0.0 - FileParade Bundle) Foxit Reader (Version: 5.3.1.606 - Foxit Corporation) Free Video to MP3 Converter version 5.0.25.610 (Version: 5.0.25.610 - DVDVideoSoft Ltd.) Free YouTube Download version 3.2.3.610 (Version: 3.2.3.610 - DVDVideoSoft Ltd.) GPS Photo Tagger V1.2.4 (Version: V1.2.4 - iTravel Tech, Inc.) Intel(R) Control Center (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (Version: 7.0.0.1118 - Intel Corporation) Intel(R) Processor Graphics (Version: 8.15.10.2418 - Intel Corporation) iTunes (Version: 7.6.2.9 - Apple Inc.) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden Microsoft Age of Empires II (Version: - ) Microsoft Age of Empires II: The Conquerors Expansion (Version: - ) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 en-US) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MyFreeCodec (HKCU Version: - ) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.06 (Version: 311.06 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.108.688 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1106 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden NVIDIA Update 1.11.3 (Version: 1.11.3 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden ON_OFF Charge B11.0110.1 (Version: 1.00.0001 - GIGABYTE) PDF24 Creator 6.0.1 (Version: - PDF24.org) PL-2303 USB-to-Serial (Version: 1.9.0 - Prolific Technology INC) QuickTime (Version: 7.4.5.67 - Apple Inc.) Realtek Ethernet Controller Driver (Version: 7.45.516.2011 - Realtek) Realtek High Definition Audio Driver (Version: 6.0.1.6387 - Realtek Semiconductor Corp.) Samsung Kies (Version: 2.5.3.13043_14 - Samsung Electronics Co., Ltd.) Samsung Kies (Version: 2.5.3.13043_14 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.23.0 - SAMSUNG Electronics Co., Ltd.) Skype Click to Call (Version: 5.10.9560 - Skype Technologies S.A.) Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.) Splashtop Connect for Firefox (Version: 1.1.8.4 - Splashtop Inc.) Splashtop Connect IE (Version: 1.1.13.1 - Splashtop Inc.) Spotify (HKCU Version: 0.9.1.57.ge7405149 - Spotify AB) Steam (Version: 1.0.0.0 - Valve Corporation) TeamSpeak 3 Client (Version: 3.0.13.1 - TeamSpeak Systems GmbH) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Virtual COM Port Driver (Version: 1.3.1 - STMicroelectronics) Virtual COM Port Driver (Version: 1.3.1 - STMicroelectronics) Hidden ==================== Restore Points ========================= 12-01-2014 23:41:44 Windows Update 16-01-2014 01:07:00 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {28160ACD-3C44-4B49-BCA9-C2FE7CD97AFE} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe [2013-04-30] () Task: {52BC5478-0F1D-4426-8D86-2D6803FF0C39} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-09-02 19:22 - 2011-06-10 03:36 - 00094208 _____ () C:\Windows\System32\IccLibDll.dll 2013-10-12 10:25 - 2013-10-12 10:25 - 01899520 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\59ee5862c051127ed695e125f1e3cb1a\Kies.UI.ni.dll 2013-08-16 09:39 - 2013-08-16 09:39 - 00079360 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\c0fbbc04960625be85b6275ebeb00cb2\Kies.MVVM.ni.dll 2013-08-16 09:39 - 2013-08-16 09:39 - 00080896 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ZipStore\1dd23f0d663e85fd7471859147b682e7\ZipStore.ni.dll 2013-08-16 09:39 - 2013-08-16 09:39 - 00187904 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\2cb652c9e0d3ece998b8622920a463d3\Kies.Common.DeviceServiceLib.Interface.ni.dll 2013-10-12 10:25 - 2013-10-12 10:25 - 00355840 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\048885ddaa4310795d59f8306203038f\DevicePhoto.ni.dll 2013-10-12 10:25 - 2013-10-12 10:25 - 00300544 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\0a90338c405d94cc87736c9c687a8e0d\DeviceVideo.ni.dll 2013-10-12 10:25 - 2013-10-12 10:25 - 00614912 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\75e03182c72ff271ec666a1520ef1014\DevicePodcast.ni.dll 2013-08-16 09:39 - 2013-08-16 09:39 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\aab2f72c4ff4d4516918d856a101b7c6\DummyStorePlugin.ni.dll 2013-08-16 09:39 - 2013-08-16 09:39 - 17554944 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\3adf7b0ea0d7f23db2f5024776a42166\Kies.Theme.ni.dll 2013-10-12 10:25 - 2013-10-12 10:25 - 00580096 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\0f66aea003566f420cf9e472b60d6116\Kies.Common.DeviceServiceLib.FileService.ni.dll 2013-07-12 14:13 - 2013-07-12 14:13 - 00045568 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\b2b18bdc2d90d3aab43a09b1a188150a\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll 2013-10-12 10:25 - 2013-10-12 10:25 - 00995328 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\1b30a74c76d2f03f46c4311225d2fb89\DeviceCommonLib.ni.dll 2013-08-16 09:39 - 2013-08-16 09:39 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\c5efe841e2998c266e0f5e29bed04b55\ASF_cSharpAPI.ni.dll 2012-02-09 21:43 - 2012-02-09 21:43 - 00004096 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-12-12 14:19 - 2013-12-12 23:19 - 00142848 _____ () C:\Program Files\Steam\libavresample-1.dll 2013-11-04 17:12 - 2013-11-05 02:12 - 00890592 _____ () C:\Program Files\Steam\libavutil-52.dll 2013-12-12 14:04 - 2013-12-12 23:04 - 00716800 _____ () C:\Program Files\Steam\SDL2.dll 2014-01-07 13:00 - 2014-01-07 22:00 - 01138088 _____ () C:\Program Files\Steam\bin\chromehtml.DLL 2013-12-12 14:04 - 2013-12-12 23:04 - 20625832 _____ () C:\Program Files\Steam\bin\libcef.dll 2013-06-14 15:49 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files\Steam\bin\avcodec-53.dll 2013-06-14 15:49 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files\Steam\bin\avutil-51.dll 2013-06-14 15:49 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files\Steam\bin\avformat-53.dll 2010-12-21 17:33 - 2010-12-21 17:33 - 00503202 _____ () C:\Program Files\Splashtop\Splashtop Connect IE\sqlite3.dll 2013-12-21 16:16 - 2013-12-21 16:16 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-12-21 15:59 - 2013-12-21 15:59 - 16242056 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/21/2014 00:48:49 AM) (Source: RasClient) (User: ) Description: CoID={E785D911-F89A-4674-916B-B53A7CFB20DE}: Der Benutzer "Fabian-PC\Fabian" hat eine Verbindung mit dem Namen "Breitbandverbindung" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 651. Error: (01/21/2014 00:47:28 AM) (Source: RasClient) (User: ) Description: CoID={5BA0D5B2-CBE9-4BC6-AA3A-222BECDBF094}: Der Benutzer "Fabian-PC\Fabian" hat eine Verbindung mit dem Namen "Breitbandverbindung" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 651. Error: (01/19/2014 01:22:40 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/19/2014 01:22:40 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/19/2014 01:22:38 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (01/19/2014 01:05:11 AM) (Source: RasClient) (User: ) Description: CoID={8F38299C-B44F-417B-BC28-05D4CF0D0953}: Der Benutzer "Fabian-PC\Fabian" hat eine Verbindung mit dem Namen "Breitbandverbindung" gewählt, die Verbindung konnte jedoch nicht hergestellt werden. Der durch den Fehler zurückgegebene Ursachencode lautet: 0. Error: (01/17/2014 00:39:23 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/17/2014 00:39:23 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1". Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/17/2014 00:39:21 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (01/17/2014 00:02:47 AM) (Source: Application Hang) (User: ) Description: Programm dota.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a40 Startzeit: 01cf1306bb6069d3 Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe Berichts-ID: System errors: ============= Error: (01/21/2014 00:07:28 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (01/21/2014 00:07:28 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (01/20/2014 09:20:20 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (01/20/2014 09:20:20 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (01/19/2014 00:25:18 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (01/19/2014 00:25:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (01/19/2014 00:25:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (01/18/2014 02:38:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (01/18/2014 02:38:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "nvUpdatusService" konnte sich nicht als ".\UpdatusUser" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%1330 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (01/17/2014 00:11:39 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Microsoft Office Sessions: ========================= Error: (01/21/2014 00:48:49 AM) (Source: RasClient)(User: ) Description: {E785D911-F89A-4674-916B-B53A7CFB20DE}Fabian-PC\FabianBreitbandverbindung651 Error: (01/21/2014 00:47:28 AM) (Source: RasClient)(User: ) Description: {5BA0D5B2-CBE9-4BC6-AA3A-222BECDBF094}Fabian-PC\FabianBreitbandverbindung651 Error: (01/19/2014 01:22:40 PM) (Source: SideBySide)(User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\STMicroelectronics\Software\Virtual COM Port Driver\dpinst_ia64.exe Error: (01/19/2014 01:22:40 PM) (Source: SideBySide)(User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\STMicroelectronics\Software\Virtual COM Port Driver\dpinst_amd64.exe Error: (01/19/2014 01:22:38 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-I9000\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-I9000\Microsoft.VC90.CRT.MANIFEST11 Error: (01/19/2014 01:05:11 AM) (Source: RasClient)(User: ) Description: {8F38299C-B44F-417B-BC28-05D4CF0D0953}Fabian-PC\FabianBreitbandverbindung0 Error: (01/17/2014 00:39:23 PM) (Source: SideBySide)(User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\STMicroelectronics\Software\Virtual COM Port Driver\dpinst_ia64.exe Error: (01/17/2014 00:39:23 PM) (Source: SideBySide)(User: ) Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\STMicroelectronics\Software\Virtual COM Port Driver\dpinst_amd64.exe Error: (01/17/2014 00:39:21 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-I9000\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-I9000\Microsoft.VC90.CRT.MANIFEST11 Error: (01/17/2014 00:02:47 AM) (Source: Application Hang)(User: ) Description: dota.exe0.0.0.0a4001cf1306bb6069d30C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 3247.12 MB Available physical RAM: 1678.61 MB Total Pagefile: 6492.52 MB Available Pagefile: 4642.87 MB Total Virtual: 2047.88 MB Available Virtual: 1882.59 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:149.04 GB) (Free:15.1 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Daten) (Fixed) (Total:316.72 GB) (Free:261.91 GB) NTFS Drive i: (USB-HDD) (Fixed) (Total:931.28 GB) (Free:353.44 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: D716D716) Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=317 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 932 GB) (Disk ID: 32ECF1CA) Partition 1: (Not Active) - (Size=932 GB) - (Type=0C) ==================== End Of Log ============================ |
22.01.2014, 09:40 | #4 |
/// the machine /// TB-Ausbilder | TR/Dropper.Gen-Avira-Windows 7 32 Bit hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.01.2014, 22:01 | #5 |
| TR/Dropper.Gen-Avira-Windows 7 32 Bit Danke für die schnelle Antwort! Hier die Logfile Code:
ATTFilter ComboFix 14-01-22.01 - Fabian 22.01.2014 21:46:51.1.4 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3247.2138 [GMT 1:00] ausgeführt von:: c:\users\Fabian\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Outdated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Outdated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . I:\Autorun.inf . . ((((((((((((((((((((((( Dateien erstellt von 2013-12-22 bis 2014-01-22 )))))))))))))))))))))))))))))) . . 2014-01-22 11:43 . 2014-01-22 11:43 -------- d-----w- c:\program files\MSECache 2014-01-21 12:56 . 2014-01-21 12:56 -------- d-----w- C:\FRST 2014-01-15 11:16 . 2013-11-27 01:14 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2014-01-15 11:16 . 2013-11-27 01:13 284672 ----a-w- c:\windows\system32\drivers\usbport.sys 2014-01-15 11:16 . 2013-11-27 01:13 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2014-01-15 11:16 . 2013-11-27 01:13 43520 ----a-w- c:\windows\system32\drivers\usbehci.sys 2014-01-15 11:16 . 2013-11-27 01:13 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys 2014-01-15 11:16 . 2013-11-27 01:13 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2014-01-15 11:16 . 2013-11-27 01:13 6016 ----a-w- c:\windows\system32\drivers\usbd.sys 2014-01-15 11:16 . 2013-11-26 10:10 2349056 ----a-w- c:\windows\system32\win32k.sys 2014-01-11 22:58 . 2014-01-11 22:58 999936 ----a-w- c:\program files\Internet Explorer\networkinspection.dll 2014-01-11 19:09 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll 2014-01-11 18:13 . 2014-01-22 12:06 -------- d-----w- c:\program files\Steam 2014-01-11 12:11 . 2013-10-17 18:02 139776 ----a-w- c:\windows\system32\drivers\ser2pl.sys 2014-01-11 12:11 . 2005-08-03 15:05 35892 ----a-w- c:\windows\system32\SER9PL.sys 2014-01-11 12:11 . 2005-08-03 15:04 26719 ----a-w- c:\windows\system32\SERSPL.VXD 2014-01-11 12:02 . 2014-01-11 12:02 -------- d-----w- c:\program files\STMicroelectronics 2014-01-11 12:01 . 2014-01-11 12:01 -------- d-----w- c:\windows\Downloaded Installations 2014-01-11 11:37 . 2014-01-11 11:37 -------- d-----w- c:\program files\sweetpacks bundle uninstaller . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-22 14:10 . 2013-12-22 14:10 640512 ----a-w- c:\windows\system32\advapi32.dll 2013-12-22 14:10 . 2013-12-22 14:10 619520 ----a-w- c:\windows\system32\tdh.dll 2013-12-22 14:10 . 2013-12-22 14:10 3969472 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-12-22 14:10 . 2013-12-22 14:10 3914176 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-12-22 14:10 . 2013-12-22 14:10 1289096 ----a-w- c:\windows\system32\ntdll.dll 2013-12-22 14:09 . 2013-12-22 14:09 338944 ----a-w- c:\windows\system32\drivers\afd.sys 2013-12-22 14:09 . 2013-12-22 14:09 231424 ----a-w- c:\windows\system32\mswsock.dll 2013-12-22 14:09 . 2013-12-22 14:09 1294272 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-12-21 14:59 . 2012-09-02 19:42 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-12-21 14:59 . 2012-09-02 19:42 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-11-12 02:07 . 2013-12-21 14:26 2048 ----a-w- c:\windows\system32\tzres.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2013-04-30 1521800] "{0F3DC9E0-C459-4a40-BCF8-747BD9322E10}"= "c:\program files\Splashtop\Splashtop Connect IE\AddressBarSearch.dll" [2011-03-04 165776] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_CLASSES_ROOT\clsid\{0f3dc9e0-c459-4a40-bcf8-747bd9322e10}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook.1] [HKEY_CLASSES_ROOT\TypeLib\{4E8E0178-00EF-413d-9324-E7B3E31572E3}] [HKEY_CLASSES_ROOT\AddressBarSearch.SearchHook] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-11-14 20584608] "KiesPreload"="c:\program files\Samsung\Kies\Kies.exe" [2013-04-23 1561968] "Steam"="c:\program files\Steam\Steam.exe" [2014-01-07 1815464] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "STCAgent"="c:\program files\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 776064] "ZyngaGamesAgent"="c:\program files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 841544] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-06-17 142616] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-06-17 177432] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-06-17 176408] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-06-07 10082920] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-07-18 348664] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-06-20 1568976] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048] "KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2013-04-23 311152] "PDFPrint"="c:\program files\PDF24\pdf24.exe" [2013-10-28 185896] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-03-22 280576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\nvinit.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [2010-04-06 31272] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2013-11-26 108032] R3 Ser2plx86;Prolific Serial port WDF driver;c:\windows\system32\DRIVERS\ser2pl.sys [2013-10-17 139776] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2013-04-03 136904] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2013-04-03 17864] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2013-04-03 153672] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 18544] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-07-18 36000] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2012-07-18 86224] S2 AntiVirWebService;Avira Browser Schutz;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2012-07-18 465360] S2 SCBackService;Splashtop Connect Service;c:\program files\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-01-18 383264] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] S2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384] S2 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [2011-05-25 41600] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [2011-05-25 61824] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 269824] S3 MEI;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECI.sys [2010-09-21 41088] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-05-16 391272] . . Inhalt des "geplante Tasks" Ordners . 2014-01-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-02 14:59] . . ------- Zusätzlicher Suchlauf ------- . LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: Interfaces\{747B7B48-3CFC-48EA-85EB-D67E18D1F350}: NameServer = 62.152.168.253 62.152.177.87 FF - ProfilePath - c:\users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=80f22c25-0382-413d-afbe-787a928982ed&apn_ptnrs=%5EABT&apn_sauid=C9F1F666-C303-4A38-A6EE-34A26979E43F&apn_dtid=%5EYYYYYY%5EYY%5EDE&&q= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-KiesAirMessage - c:\program files\Samsung\Kies\KiesAirMessage.exe AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-01-22 21:56:06 ComboFix-quarantined-files.txt 2014-01-22 20:56 . Vor Suchlauf: 16 Verzeichnis(se), 28.951.937.024 Bytes frei Nach Suchlauf: 21 Verzeichnis(se), 30.461.669.376 Bytes frei . - - End Of File - - C80013796DEC56145CC5DF18B3400168 A36C5E4F47E84449FF07ED3517B43A31 |
23.01.2014, 19:24 | #6 |
/// the machine /// TB-Ausbilder | TR/Dropper.Gen-Avira-Windows 7 32 Bit Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> TR/Dropper.Gen-Avira-Windows 7 32 Bit |
23.01.2014, 20:18 | #7 |
| TR/Dropper.Gen-Avira-Windows 7 32 Bit Ok zuerst der Malwarebytes log Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.23.06 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 11.0.9600.16476 Fabian :: FABIAN-PC [Administrator] 23.01.2014 19:50:43 mbam-log-2014-01-23 (19-50-43).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 224619 Laufzeit: 5 Minute(n), 6 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 2 HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: 1763663256229969919 -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Daten: 1763663256229969919 -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Fabian\Downloads\SoftonicDownloader_fuer_foxit-pdf-reader.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) nun der adwcleaner log Code:
ATTFilter # AdwCleaner v3.017 - Bericht erstellt am 23/01/2014 um 20:04:13 # Aktualisiert 12/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Fabian - FABIAN-PC # Gestartet von : C:\Users\Fabian\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : SCBackService ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Splashtop Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec Ordner Gelöscht : C:\Program Files\Ask.com Ordner Gelöscht : C:\Program Files\myfree codec Ordner Gelöscht : C:\Program Files\Splashtop Ordner Gelöscht : C:\Program Files\sweetpacks bundle uninstaller Ordner Gelöscht : C:\Windows\installer\{86d4b82a-abed-442a-be86-96357b70f4fe} Ordner Gelöscht : C:\Users\Fabian\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\Fabian\AppData\LocalLow\AskToolbar Ordner Gelöscht : C:\Users\Fabian\AppData\Roaming\Splashtop Ordner Gelöscht : C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\Extensions\toolbar@ask.com Datei Gelöscht : C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\searchplugins\conduit-search.xml Datei Gelöscht : C:\Windows\System32\Tasks\Scheduled Update for Ask Toolbar ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{28160ACD-3C44-4B49-BCA9-C2FE7CD97AFE} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28160ACD-3C44-4B49-BCA9-C2FE7CD97AFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AddressBarSearch.SearchHook.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.FBServiceAPPEventsSink Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.FBServiceAPPEventsSink.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.OptionMenu Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.OptionMenu.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.Protocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.Protocol.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.VisualBookmark Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.VisualBookmark.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.WebObject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STC.WebObject.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STCHelper.BHOHelper Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STCHelper.BHOHelper.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STCHelper.FBServiceAPP Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STCHelper.FBServiceAPP.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STCHelper.Protocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\STCHelper.Protocol.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_foxit-pdf-reader_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_foxit-pdf-reader_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{82A5CE4D-AF0C-45B6-8AF8-75625BE6A08D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B2B7E0CD-E169-43B3-A233-E129610EE314} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0DEC13F0-5C8C-4147-8329-6CDFAD9755B7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0F3DC9E0-C459-4A40-BCF8-747BD9322E10} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E97F0FA-3B44-4634-A87E-8B0D5CFD6365} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{951F5841-FD1E-4F1D-8607-67B174DBD753} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D1CCB0CC-DA45-4797-93D3-DEE7A13F8177} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DCE24E28-D8EF-49BE-BC01-A1DD3B58FCE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E4F7F1A5-490E-4884-A9E3-CBD6A25749E1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E8E0178-00EF-413D-9324-E7B3E31572E3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A1A533A8-E106-422B-AE29-D0025269AF83} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{B1759D04-0EF9-472A-B5C3-C774997B5321} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFE66D00-A56A-4F7F-81D7-4A28C5816D6C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E5680D1-BF44-4929-94AF-FD30D784AD1D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80ED3EBC-CC05-4336-ABCC-295798855718} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0F3DC9E0-C459-4A40-BCF8-747BD9322E10}] Schlüssel Gelöscht : HKCU\Software\Ask.com Schlüssel Gelöscht : HKCU\Software\AskToolbar Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\IM Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\Splashtop Inc. Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar Schlüssel Gelöscht : HKLM\Software\AskToolbar Schlüssel Gelöscht : HKLM\Software\Myfree Codec Schlüssel Gelöscht : HKLM\Software\Splashtop Inc. Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (en-US) [ Datei : C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\prefs.js ] Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", ""); Zeile gelöscht : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=80f22c25-0382-413d-afbe-787a928982ed&apn_ptnrs=%5EABT&apn_sauid=C9F1F666-C303-4A38[...] ************************* AdwCleaner[R0].txt - [12739 octets] - [23/01/2014 20:03:48] AdwCleaner[S0].txt - [12693 octets] - [23/01/2014 20:04:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12754 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Home Premium x86 Ran by Fabian on 23.01.2014 at 20:07:42,46 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] wcuservice_stc_ie Successfully deleted: [Service] wcuservice_stc_ie ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{53BF67CF-B31A-43E3-8AB4-EFA6F2296173} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Fabian\AppData\Roaming\mozilla\firefox\profiles\5bnevo0z.default\minidumps [309 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 23.01.2014 at 20:08:48,37 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-01-2014 Ran by Fabian (administrator) on FABIAN-PC on 23-01-2014 20:09:12 Running from C:\Users\Fabian\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple, Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [STCAgent] - "C:\Program Files\Splashtop\Splashtop Connect IE\STCAgent.exe" HKLM\...\Run: [ZyngaGamesAgent] - "C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-06-07] (Realtek Semiconductor) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [348664 2012-07-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2008-03-28] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [267048 2008-03-30] (Apple Inc.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [185896 2013-10-28] (Geek Software GmbH) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1815464 2014-01-07] (Valve Corporation) AppInit_DLLs: C:\Windows\System32\nvinit.dll => C:\Windows\System32\nvinit.dll [201576 2013-02-25] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x41F793AE84ECCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {6B02B0A8-8809-447d-85BE-B42C9CDA89B5} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {9EB71124-A817-4c0f-B4C9-CE1F524393E6} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {EBB94A4B-A86F-4ad1-A484-9D929B783CC1} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) FireFox: ======== FF ProfilePath: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Extension: Adblock Plus - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-16] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-21] FF HKLM\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} FF HKLM\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} FF HKLM\...\Firefox\Extensions: [{d9284e50-81fc-11da-a72b-0800200c9a66}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [86224 2012-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [110032 2012-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [465360 2012-07-18] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [110592 2008-02-18] (Apple, Inc.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S2 WCUService_STC_FF; C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [x] ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [18544 2011-01-10] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-07-18] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-07-18] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2012-07-18] (Avira GmbH) R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [41600 2011-05-25] (Etron Technology Inc) R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [61824 2011-05-25] (Etron Technology Inc) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-09-21] (Intel Corporation) S3 Ser2plx86; C:\Windows\System32\DRIVERS\ser2pl.sys [139776 2013-10-17] (Prolific Technology Inc.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\Fabian\AppData\Local\Temp\catchme.sys [x] S3 gdrv; \??\C:\Windows\gdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-23 20:09 - 2014-01-23 20:09 - 00009894 _____ C:\Users\Fabian\Desktop\FRST.txt 2014-01-23 20:08 - 2014-01-23 20:08 - 00001143 _____ C:\Users\Fabian\Desktop\JRT.txt 2014-01-23 20:07 - 2014-01-23 20:07 - 00000000 ____D C:\Windows\ERUNT 2014-01-23 20:03 - 2014-01-23 20:04 - 00000000 ____D C:\AdwCleaner 2014-01-23 20:02 - 2014-01-23 20:02 - 01037068 _____ (Thisisu) C:\Users\Fabian\Desktop\JRT.exe 2014-01-23 20:01 - 2014-01-23 20:02 - 01236282 _____ C:\Users\Fabian\Desktop\adwcleaner.exe 2014-01-23 19:48 - 2014-01-23 19:48 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-23 19:48 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-23 19:46 - 2014-01-23 19:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Fabian\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-22 22:57 - 2014-01-22 22:57 - 00054156 ____H C:\Windows\QTFont.qfn 2014-01-22 22:57 - 2014-01-22 22:57 - 00001409 _____ C:\Windows\QTFont.for 2014-01-22 21:56 - 2014-01-22 21:56 - 00011687 _____ C:\ComboFix.txt 2014-01-22 21:45 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-22 21:45 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-22 21:45 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-22 21:44 - 2014-01-22 21:56 - 00000000 ____D C:\Qoobox 2014-01-22 21:44 - 2014-01-22 21:53 - 00000000 ____D C:\Windows\erdnt 2014-01-22 16:49 - 2014-01-22 16:49 - 00000000 ____D C:\Users\Fabian\Downloads\psaiko dino 2014-01-22 16:05 - 2014-01-22 16:47 - 130201928 _____ C:\Users\Fabian\Downloads\#2773#.rar 2014-01-22 13:11 - 2014-01-22 13:10 - 00010384 _____ C:\Users\Fabian\Desktop\Rückmeldung Alumni.xlsx 2014-01-22 12:44 - 2014-01-22 12:44 - 00000000 ____D C:\Program Files\Microsoft Office 2014-01-22 12:43 - 2014-01-22 12:43 - 00000000 ____D C:\Program Files\MSECache 2014-01-22 12:29 - 2014-01-22 12:37 - 53634800 _____ (Microsoft Corporation) C:\Users\Fabian\Downloads\ExcelViewer.exe 2014-01-22 12:27 - 2014-01-22 12:26 - 00027282 _____ C:\Users\Fabian\Desktop\Mitgliederliste MFCC März 2013.xlsx 2014-01-22 12:24 - 2014-01-22 12:25 - 05173757 ____R (Swearware) C:\Users\Fabian\Desktop\ComboFix.exe 2014-01-21 13:56 - 2014-01-21 13:56 - 00000000 ____D C:\FRST 2014-01-21 13:55 - 2014-01-21 13:55 - 01222144 _____ (Farbar) C:\Users\Fabian\Desktop\FRST.exe 2014-01-21 12:49 - 2014-01-21 12:49 - 00110700 _____ C:\Users\Fabian\Downloads\OTL.Txt 2014-01-21 12:49 - 2014-01-21 12:49 - 00048124 _____ C:\Users\Fabian\Downloads\Extras.Txt 2014-01-21 12:38 - 2014-01-21 12:38 - 00602112 _____ (OldTimer Tools) C:\Users\Fabian\Downloads\OTL.exe 2014-01-15 12:16 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 12:16 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-13 00:42 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-13 00:42 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-13 00:42 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-13 00:42 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-13 00:42 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-13 00:42 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-13 00:42 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-13 00:42 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-13 00:42 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-13 00:42 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-13 00:42 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-13 00:42 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-13 00:42 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-13 00:42 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-13 00:42 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-13 00:42 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-13 00:42 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-13 00:42 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-13 00:42 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-12 13:57 - 2014-01-12 13:57 - 00001107 _____ C:\Users\Fabian\Desktop\Steam - Verknüpfung.lnk 2014-01-11 23:58 - 2014-01-11 23:58 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-11 23:58 - 2014-01-11 23:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-11 23:58 - 2014-01-11 23:58 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-11 23:58 - 2014-01-11 23:58 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-11 20:09 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-11 20:09 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-11 20:09 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-11 20:09 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-11 20:09 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-11 20:09 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-11 20:09 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-11 20:09 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-11 20:09 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-11 20:09 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-11 20:09 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-11 20:09 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-11 20:09 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-11 20:09 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-11 20:09 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-11 20:09 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-11 20:09 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-11 20:09 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-11 20:09 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-11 20:09 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-11 20:09 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-11 20:09 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-11 20:09 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-11 20:09 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-11 20:09 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-11 20:09 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-11 20:09 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-11 20:09 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-11 20:09 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-11 20:09 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-11 20:09 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-11 20:09 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-11 20:09 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-11 20:09 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-11 20:09 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-11 20:09 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-11 20:09 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-11 20:09 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-11 20:09 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-11 20:09 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-11 20:09 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-11 20:09 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-01-11 20:09 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-01-11 20:09 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-01-11 20:09 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-01-11 20:09 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-01-11 20:09 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-01-11 20:09 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-01-11 20:09 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-01-11 20:09 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-01-11 20:09 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-01-11 20:09 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-01-11 20:09 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-01-11 19:13 - 2014-01-23 20:06 - 00000000 ____D C:\Program Files\Steam 2014-01-11 19:13 - 2014-01-11 19:13 - 00000875 _____ C:\Users\Public\Desktop\Steam.lnk 2014-01-11 19:11 - 2014-01-11 19:12 - 08531968 _____ C:\Users\Fabian\Downloads\SteamInstall_German.msi 2014-01-11 13:11 - 2013-10-17 19:02 - 00139776 _____ (Prolific Technology Inc.) C:\Windows\system32\Drivers\ser2pl.sys 2014-01-11 13:11 - 2005-08-03 16:05 - 00035892 _____ (Prolific Technology Inc.) C:\Windows\system32\SER9PL.sys 2014-01-11 13:11 - 2005-08-03 16:04 - 00026719 _____ C:\Windows\system32\SERSPL.VXD 2014-01-11 13:05 - 2014-01-11 13:20 - 00000000 ____D C:\Users\Fabian\Documents\gpsPhotoTagger_Workspace 2014-01-11 13:02 - 2014-01-11 13:02 - 00002370 _____ C:\Windows\DPINST.LOG 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D C:\Program Files\STMicroelectronics 2014-01-11 13:01 - 2014-01-11 13:01 - 00000804 _____ C:\Users\Public\Desktop\GPS Photo Tagger.lnk 2014-01-11 13:01 - 2014-01-11 13:01 - 00000000 ____D C:\Windows\Downloaded Installations ==================== One Month Modified Files and Folders ======= 2014-01-23 20:09 - 2014-01-23 20:09 - 00009894 _____ C:\Users\Fabian\Desktop\FRST.txt 2014-01-23 20:08 - 2014-01-23 20:08 - 00001143 _____ C:\Users\Fabian\Desktop\JRT.txt 2014-01-23 20:07 - 2014-01-23 20:07 - 00000000 ____D C:\Windows\ERUNT 2014-01-23 20:06 - 2014-01-11 19:13 - 00000000 ____D C:\Program Files\Steam 2014-01-23 20:06 - 2012-09-09 12:02 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Skype 2014-01-23 20:05 - 2012-11-19 01:33 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-23 20:05 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-23 20:05 - 2009-07-14 05:39 - 00089737 _____ C:\Windows\setupact.log 2014-01-23 20:05 - 2009-07-14 05:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-23 20:05 - 2009-07-14 05:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-23 20:04 - 2014-01-23 20:03 - 00000000 ____D C:\AdwCleaner 2014-01-23 20:04 - 2012-09-02 18:27 - 01412835 _____ C:\Windows\WindowsUpdate.log 2014-01-23 20:02 - 2014-01-23 20:02 - 01037068 _____ (Thisisu) C:\Users\Fabian\Desktop\JRT.exe 2014-01-23 20:02 - 2014-01-23 20:01 - 01236282 _____ C:\Users\Fabian\Desktop\adwcleaner.exe 2014-01-23 19:58 - 2012-09-06 22:21 - 00161694 _____ C:\Windows\PFRO.log 2014-01-23 19:57 - 2013-05-11 02:25 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\TS3Client 2014-01-23 19:55 - 2012-09-02 20:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-23 19:48 - 2014-01-23 19:48 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-23 19:47 - 2014-01-23 19:46 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Fabian\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-22 22:57 - 2014-01-22 22:57 - 00054156 ____H C:\Windows\QTFont.qfn 2014-01-22 22:57 - 2014-01-22 22:57 - 00001409 _____ C:\Windows\QTFont.for 2014-01-22 21:56 - 2014-01-22 21:56 - 00011687 _____ C:\ComboFix.txt 2014-01-22 21:56 - 2014-01-22 21:44 - 00000000 ____D C:\Qoobox 2014-01-22 21:56 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default 2014-01-22 21:56 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public 2014-01-22 21:53 - 2014-01-22 21:44 - 00000000 ____D C:\Windows\erdnt 2014-01-22 21:52 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini 2014-01-22 16:49 - 2014-01-22 16:49 - 00000000 ____D C:\Users\Fabian\Downloads\psaiko dino 2014-01-22 16:47 - 2014-01-22 16:05 - 130201928 _____ C:\Users\Fabian\Downloads\#2773#.rar 2014-01-22 13:10 - 2014-01-22 13:11 - 00010384 _____ C:\Users\Fabian\Desktop\Rückmeldung Alumni.xlsx 2014-01-22 12:44 - 2014-01-22 12:44 - 00000000 ____D C:\Program Files\Microsoft Office 2014-01-22 12:44 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2014-01-22 12:43 - 2014-01-22 12:43 - 00000000 ____D C:\Program Files\MSECache 2014-01-22 12:37 - 2014-01-22 12:29 - 53634800 _____ (Microsoft Corporation) C:\Users\Fabian\Downloads\ExcelViewer.exe 2014-01-22 12:26 - 2014-01-22 12:27 - 00027282 _____ C:\Users\Fabian\Desktop\Mitgliederliste MFCC März 2013.xlsx 2014-01-22 12:25 - 2014-01-22 12:24 - 05173757 ____R (Swearware) C:\Users\Fabian\Desktop\ComboFix.exe 2014-01-21 16:55 - 2011-06-19 23:29 - 00000000 ____D C:\patch 2014-01-21 13:56 - 2014-01-21 13:56 - 00000000 ____D C:\FRST 2014-01-21 13:55 - 2014-01-21 13:55 - 01222144 _____ (Farbar) C:\Users\Fabian\Desktop\FRST.exe 2014-01-21 12:49 - 2014-01-21 12:49 - 00110700 _____ C:\Users\Fabian\Downloads\OTL.Txt 2014-01-21 12:49 - 2014-01-21 12:49 - 00048124 _____ C:\Users\Fabian\Downloads\Extras.Txt 2014-01-21 12:38 - 2014-01-21 12:38 - 00602112 _____ (OldTimer Tools) C:\Users\Fabian\Downloads\OTL.exe 2014-01-16 12:13 - 2009-07-14 05:33 - 00278840 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-16 02:08 - 2013-10-06 19:34 - 00000000 ____D C:\Windows\system32\MRT 2014-01-16 02:07 - 2013-10-06 19:34 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-12 13:57 - 2014-01-12 13:57 - 00001107 _____ C:\Users\Fabian\Desktop\Steam - Verknüpfung.lnk 2014-01-12 13:52 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2014-01-12 12:53 - 2012-09-07 00:09 - 00000000 ____D C:\Program Files\Common Files\Steam 2014-01-12 12:53 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2014-01-12 00:00 - 2013-12-22 15:09 - 00183927 _____ C:\Windows\IE11_main.log 2014-01-11 23:58 - 2014-01-11 23:58 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-11 23:58 - 2014-01-11 23:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-11 23:58 - 2014-01-11 23:58 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-11 23:58 - 2014-01-11 23:58 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-11 23:57 - 2013-05-10 19:43 - 00888237 _____ C:\Windows\IE10_main.log 2014-01-11 19:13 - 2014-01-11 19:13 - 00000875 _____ C:\Users\Public\Desktop\Steam.lnk 2014-01-11 19:13 - 2012-09-02 19:11 - 00000000 ____D C:\Users\Fabian 2014-01-11 19:12 - 2014-01-11 19:11 - 08531968 _____ C:\Users\Fabian\Downloads\SteamInstall_German.msi 2014-01-11 13:39 - 2012-09-02 19:14 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 13:20 - 2014-01-11 13:05 - 00000000 ____D C:\Users\Fabian\Documents\gpsPhotoTagger_Workspace 2014-01-11 13:11 - 2012-09-02 19:22 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2014-01-11 13:02 - 2014-01-11 13:02 - 00002370 _____ C:\Windows\DPINST.LOG 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D C:\Program Files\STMicroelectronics 2014-01-11 13:01 - 2014-01-11 13:01 - 00000804 _____ C:\Users\Public\Desktop\GPS Photo Tagger.lnk 2014-01-11 13:01 - 2014-01-11 13:01 - 00000000 ____D C:\Windows\Downloaded Installations 2014-01-11 13:01 - 2012-09-02 19:22 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2014-01-10 15:09 - 2008-04-22 16:18 - 00000000 ___RD C:\Programme Some content of TEMP: ==================== C:\Users\Fabian\AppData\Local\Temp\Foxit Updater.exe C:\Users\Fabian\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-19 12:52 ==================== End Of Log ============================ Grüße Niggel |
24.01.2014, 10:52 | #8 |
/// the machine /// TB-Ausbilder | TR/Dropper.Gen-Avira-Windows 7 32 BitESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.01.2014, 17:29 | #9 |
| TR/Dropper.Gen-Avira-Windows 7 32 Bit Hi 1.log Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=4a9dd1b4acf344478b1119667868f7c0 # engine=16784 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-24 04:20:09 # local_time=2014-01-24 05:20:09 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 98 33705126 256003699 33937799 0 # compatibility_mode=5893 16776574 66 85 16153991 142211600 0 0 # scanned=507824 # found=44 # cleaned=0 # scan_time=11040 sh=8677B6E03ED26043F72BD08D7302848EC32CB2FF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\15\cf01f0f-228b387a" sh=8677B6E03ED26043F72BD08D7302848EC32CB2FF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\19\43272693-670fd63f" sh=ADCEC5FDB979085D41746101D7F366AA2099E37A ft=1 fh=f69d84aa6f616de6 vn="a variant of Win32/Kryptik.NWO trojan" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\20\4142f714-6f21be2c" sh=E278218138CDA3F43F98BA4EE78D704A545E3201 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.NDH trojan" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\27\17ffaa5b-7400a87c" sh=07012F1D3A6EB5D215F4498A1A745E92FE9399F0 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\27\7061701b-4e56295c" sh=617D29E52A52870DBAB04EF0CE037CAEF148C426 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\27\7061701b-52c92d0f" sh=69E79853C4227AF902A71A53F82CF1CCD2D03DC2 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\34\c669a2-12ad51dd" sh=4609190463E2E46CFF8DB6A232430C3BC153813A ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NCQ trojan" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\38\36269e6-70b33c34" sh=8677B6E03ED26043F72BD08D7302848EC32CB2FF ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Anwendungsdaten\Sun\Java\Deployment\cache\6.0\58\58f6f4ba-71b8f282" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Win32/Virut.NBP virus" ac=I fn="C:\Dokumente und Einstellungen\Aram\Desktop\fallout\sambadance\Fallout.3.GERMAN-0x0007\fallout3d.iso" sh=39C5C9B5637365C888D015E613CBD4D9346DFB42 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Dokumente und Einstellungen\Aram\Lokale Einstellungen\Temp\jar_cache6922037337926413629.tmp" sh=F85ACC6D44ED37D5C487581495CD52F644911B2B ft=1 fh=b11cb89f3457cf6c vn="Win32/Virut.NBP virus" ac=I fn="C:\System Volume Information\_restore{E6F748F3-D76F-4099-8D09-CA41050C8051}\RP1071\A0520096.exe" sh=810E28D4E7B28D658DC48A82F0C65B46149AAE89 ft=1 fh=120d32a29875bbd8 vn="Win64/Conedex.B trojan" ac=I fn="C:\Windows.old.000\$Recycle.Bin\S-1-5-21-1099255470-2525012948-2189102361-1000\$330d9a4f64fb23c2fec4a8e3a3d1d4da\U\000000cb.@" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\All Users\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\All Users\Anwendungsdaten\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\All Users\Application Data\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=DE64801FF2237CF6AA48AD29EA72A1C893A44EDA ft=1 fh=aa773b37bc3bbe3b vn="a variant of Win32/Medfos.CZ trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\Anwendungsdaten\tshoft.dll" sh=06D02D3FD7B9943476886F1F5CA19BCAB24CAA7E ft=1 fh=87c272877793e2fd vn="Win32/Spy.Zbot.AAO trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\Anwendungsdaten\Utsey\ryav.exe" sh=1B4C52CE17011C262B43F0D43E267939091F7233 ft=1 fh=694d72ba7cf590e0 vn="a variant of Win32/Vcaredrix.B trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\Anwendungsdaten\xsecva\xsecva.exe" sh=14F0722F20829B7E2BD2CB87E51CEED1A4F2AABF ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Local\Anwendungsdaten\Opera\Opera\cache\g_0072\opr03TOV.tmp" sh=AA64FB34DF27460F64E106A2465BB2B454963490 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Local\Anwendungsdaten\Temp\jar_cache774646181357330261.tmp" sh=14F0722F20829B7E2BD2CB87E51CEED1A4F2AABF ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Local\Opera\Opera\cache\g_0072\opr03TOV.tmp" sh=AA64FB34DF27460F64E106A2465BB2B454963490 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Local\Temp\jar_cache774646181357330261.tmp" sh=28BA447017D81E69ECF3003D4F5AA41D2692E341 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.NEO trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\5fef98f5-3d61973b" sh=DE64801FF2237CF6AA48AD29EA72A1C893A44EDA ft=1 fh=aa773b37bc3bbe3b vn="a variant of Win32/Medfos.CZ trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Roaming\tshoft.dll" sh=06D02D3FD7B9943476886F1F5CA19BCAB24CAA7E ft=1 fh=87c272877793e2fd vn="Win32/Spy.Zbot.AAO trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Roaming\Utsey\ryav.exe" sh=1B4C52CE17011C262B43F0D43E267939091F7233 ft=1 fh=694d72ba7cf590e0 vn="a variant of Win32/Vcaredrix.B trojan" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\AppData\Roaming\xsecva\xsecva.exe" sh=14F0722F20829B7E2BD2CB87E51CEED1A4F2AABF ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\Lokale Einstellungen\Opera\Opera\cache\g_0072\opr03TOV.tmp" sh=AA64FB34DF27460F64E106A2465BB2B454963490 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Windows.old.000\Documents and Settings\Nick\Lokale Einstellungen\Temp\jar_cache774646181357330261.tmp" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\ProgramData\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\Users\All Users\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\Users\All Users\Anwendungsdaten\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=F3BB7D5CEA7F9BAC36B8123E87BA428D82F229C4 ft=1 fh=c71c00117cf2e9c3 vn="a variant of Win32/Kryptik.ALHV trojan" ac=I fn="C:\Windows.old.000\Users\All Users\Application Data\7531CCA900091D2502C1E5A5F875EF60\7531CCA900091D2502C1E5A5F875EF60.exe" sh=DE64801FF2237CF6AA48AD29EA72A1C893A44EDA ft=1 fh=aa773b37bc3bbe3b vn="a variant of Win32/Medfos.CZ trojan" ac=I fn="C:\Windows.old.000\Users\Nick\Anwendungsdaten\tshoft.dll" sh=06D02D3FD7B9943476886F1F5CA19BCAB24CAA7E ft=1 fh=87c272877793e2fd vn="Win32/Spy.Zbot.AAO trojan" ac=I fn="C:\Windows.old.000\Users\Nick\Anwendungsdaten\Utsey\ryav.exe" sh=1B4C52CE17011C262B43F0D43E267939091F7233 ft=1 fh=694d72ba7cf590e0 vn="a variant of Win32/Vcaredrix.B trojan" ac=I fn="C:\Windows.old.000\Users\Nick\Anwendungsdaten\xsecva\xsecva.exe" sh=14F0722F20829B7E2BD2CB87E51CEED1A4F2AABF ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="C:\Windows.old.000\Users\Nick\AppData\Local\Opera\Opera\cache\g_0072\opr03TOV.tmp" sh=AA64FB34DF27460F64E106A2465BB2B454963490 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Windows.old.000\Users\Nick\AppData\Local\Temp\jar_cache774646181357330261.tmp" sh=28BA447017D81E69ECF3003D4F5AA41D2692E341 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.Agent.NEO trojan" ac=I fn="C:\Windows.old.000\Users\Nick\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\5fef98f5-3d61973b" sh=DE64801FF2237CF6AA48AD29EA72A1C893A44EDA ft=1 fh=aa773b37bc3bbe3b vn="a variant of Win32/Medfos.CZ trojan" ac=I fn="C:\Windows.old.000\Users\Nick\AppData\Roaming\tshoft.dll" sh=06D02D3FD7B9943476886F1F5CA19BCAB24CAA7E ft=1 fh=87c272877793e2fd vn="Win32/Spy.Zbot.AAO trojan" ac=I fn="C:\Windows.old.000\Users\Nick\AppData\Roaming\Utsey\ryav.exe" sh=1B4C52CE17011C262B43F0D43E267939091F7233 ft=1 fh=694d72ba7cf590e0 vn="a variant of Win32/Vcaredrix.B trojan" ac=I fn="C:\Windows.old.000\Users\Nick\AppData\Roaming\xsecva\xsecva.exe" sh=14F0722F20829B7E2BD2CB87E51CEED1A4F2AABF ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen virus" ac=I fn="C:\Windows.old.000\Users\Nick\Lokale Einstellungen\Opera\Opera\cache\g_0072\opr03TOV.tmp" sh=AA64FB34DF27460F64E106A2465BB2B454963490 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Windows.old.000\Users\Nick\Lokale Einstellungen\Temp\jar_cache774646181357330261.tmp" Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 11.9.900.170 Mozilla Firefox (for.) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-01-2014 Ran by Fabian (administrator) on FABIAN-PC on 24-01-2014 17:26:41 Running from C:\Users\Fabian\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple, Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Samsung) C:\Program Files\Samsung\Kies\Kies.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [STCAgent] - "C:\Program Files\Splashtop\Splashtop Connect IE\STCAgent.exe" HKLM\...\Run: [ZyngaGamesAgent] - "C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-06-07] (Realtek Semiconductor) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [348664 2012-07-18] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [413696 2008-03-28] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [267048 2008-03-30] (Apple Inc.) HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-04-23] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [185896 2013-10-28] (Geek Software GmbH) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1561968 2013-04-23] (Samsung) HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1815464 2014-01-07] (Valve Corporation) AppInit_DLLs: C:\Windows\System32\nvinit.dll => C:\Windows\System32\nvinit.dll [201576 2013-02-25] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x41F793AE84ECCE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {6B02B0A8-8809-447d-85BE-B42C9CDA89B5} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV SearchScopes: HKCU - {9EB71124-A817-4c0f-B4C9-CE1F524393E6} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {EBB94A4B-A86F-4ad1-A484-9D929B783CC1} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [147456] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [261840] (Avira Operations GmbH & Co. KG) Tcpip\..\Interfaces\{747B7B48-3CFC-48EA-85EB-D67E18D1F350}: [NameServer]62.152.168.253 62.152.177.87 FireFox: ======== FF ProfilePath: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Extension: Adblock Plus - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\5bnevo0z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-11-16] FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-21] FF HKLM\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} FF HKLM\...\Firefox\Extensions: [{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} FF HKLM\...\Firefox\Extensions: [{d9284e50-81fc-11da-a72b-0800200c9a66}] - C:\Program Files\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [86224 2012-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [110032 2012-07-18] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [465360 2012-07-18] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [110592 2008-02-18] (Apple, Inc.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S2 WCUService_STC_FF; C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [x] ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [18544 2011-01-10] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-07-18] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-07-18] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2012-07-18] (Avira GmbH) R3 EtronHub3; C:\Windows\System32\Drivers\EtronHub3.sys [41600 2011-05-25] (Etron Technology Inc) R3 EtronXHCI; C:\Windows\System32\Drivers\EtronXHCI.sys [61824 2011-05-25] (Etron Technology Inc) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-09-21] (Intel Corporation) S3 Ser2plx86; C:\Windows\System32\DRIVERS\ser2pl.sys [139776 2013-10-17] (Prolific Technology Inc.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2010-06-17] (Avira GmbH) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\Fabian\AppData\Local\Temp\catchme.sys [x] S3 gdrv; \??\C:\Windows\gdrv.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-24 17:25 - 2014-01-24 17:25 - 00987425 _____ C:\Users\Fabian\Desktop\SecurityCheck.exe 2014-01-24 14:04 - 2014-01-24 14:05 - 02347384 _____ (ESET) C:\Users\Fabian\Desktop\esetsmartinstaller_enu.exe 2014-01-23 20:09 - 2014-01-24 17:26 - 00010461 _____ C:\Users\Fabian\Desktop\FRST.txt 2014-01-23 20:08 - 2014-01-23 20:08 - 00001143 _____ C:\Users\Fabian\Desktop\JRT.txt 2014-01-23 20:07 - 2014-01-23 20:07 - 00000000 ____D C:\Windows\ERUNT 2014-01-23 20:03 - 2014-01-23 20:04 - 00000000 ____D C:\AdwCleaner 2014-01-23 20:02 - 2014-01-23 20:02 - 01037068 _____ (Thisisu) C:\Users\Fabian\Desktop\JRT.exe 2014-01-23 20:01 - 2014-01-23 20:02 - 01236282 _____ C:\Users\Fabian\Desktop\adwcleaner.exe 2014-01-23 19:48 - 2014-01-23 19:48 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-23 19:48 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-23 19:46 - 2014-01-23 19:47 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Fabian\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-22 22:57 - 2014-01-22 22:57 - 00054156 ____H C:\Windows\QTFont.qfn 2014-01-22 22:57 - 2014-01-22 22:57 - 00001409 _____ C:\Windows\QTFont.for 2014-01-22 21:56 - 2014-01-22 21:56 - 00011687 _____ C:\ComboFix.txt 2014-01-22 21:45 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-22 21:45 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-22 21:45 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-22 21:45 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-22 21:44 - 2014-01-22 21:56 - 00000000 ____D C:\Qoobox 2014-01-22 21:44 - 2014-01-22 21:53 - 00000000 ____D C:\Windows\erdnt 2014-01-22 16:49 - 2014-01-22 16:49 - 00000000 ____D C:\Users\Fabian\Downloads\psaiko dino 2014-01-22 16:05 - 2014-01-22 16:47 - 130201928 _____ C:\Users\Fabian\Downloads\#2773#.rar 2014-01-22 13:11 - 2014-01-22 13:10 - 00010384 _____ C:\Users\Fabian\Desktop\Rückmeldung Alumni.xlsx 2014-01-22 12:44 - 2014-01-22 12:44 - 00000000 ____D C:\Program Files\Microsoft Office 2014-01-22 12:43 - 2014-01-22 12:43 - 00000000 ____D C:\Program Files\MSECache 2014-01-22 12:29 - 2014-01-22 12:37 - 53634800 _____ (Microsoft Corporation) C:\Users\Fabian\Downloads\ExcelViewer.exe 2014-01-22 12:27 - 2014-01-22 12:26 - 00027282 _____ C:\Users\Fabian\Desktop\Mitgliederliste MFCC März 2013.xlsx 2014-01-22 12:24 - 2014-01-22 12:25 - 05173757 ____R (Swearware) C:\Users\Fabian\Desktop\ComboFix.exe 2014-01-21 13:56 - 2014-01-21 13:56 - 00000000 ____D C:\FRST 2014-01-21 13:55 - 2014-01-21 13:55 - 01222144 _____ (Farbar) C:\Users\Fabian\Desktop\FRST.exe 2014-01-21 12:49 - 2014-01-21 12:49 - 00110700 _____ C:\Users\Fabian\Downloads\OTL.Txt 2014-01-21 12:49 - 2014-01-21 12:49 - 00048124 _____ C:\Users\Fabian\Downloads\Extras.Txt 2014-01-21 12:38 - 2014-01-21 12:38 - 00602112 _____ (OldTimer Tools) C:\Users\Fabian\Downloads\OTL.exe 2014-01-15 12:16 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 12:16 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 12:16 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-13 00:42 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-13 00:42 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-13 00:42 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-13 00:42 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-13 00:42 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-13 00:42 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-13 00:42 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-13 00:42 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-13 00:42 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-13 00:42 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-13 00:42 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-13 00:42 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-13 00:42 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-13 00:42 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-13 00:42 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-13 00:42 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-13 00:42 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-13 00:42 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-13 00:42 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-12 13:57 - 2014-01-12 13:57 - 00001107 _____ C:\Users\Fabian\Desktop\Steam - Verknüpfung.lnk 2014-01-11 23:58 - 2014-01-11 23:58 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-11 23:58 - 2014-01-11 23:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-11 23:58 - 2014-01-11 23:58 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-11 23:58 - 2014-01-11 23:58 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-11 20:09 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll 2014-01-11 20:09 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll 2014-01-11 20:09 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll 2014-01-11 20:09 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll 2014-01-11 20:09 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll 2014-01-11 20:09 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll 2014-01-11 20:09 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll 2014-01-11 20:09 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll 2014-01-11 20:09 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll 2014-01-11 20:09 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll 2014-01-11 20:09 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll 2014-01-11 20:09 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll 2014-01-11 20:09 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll 2014-01-11 20:09 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll 2014-01-11 20:09 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll 2014-01-11 20:09 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll 2014-01-11 20:09 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll 2014-01-11 20:09 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll 2014-01-11 20:09 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll 2014-01-11 20:09 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll 2014-01-11 20:09 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll 2014-01-11 20:09 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll 2014-01-11 20:09 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll 2014-01-11 20:09 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll 2014-01-11 20:09 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll 2014-01-11 20:09 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll 2014-01-11 20:09 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll 2014-01-11 20:09 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll 2014-01-11 20:09 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll 2014-01-11 20:09 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll 2014-01-11 20:09 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll 2014-01-11 20:09 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll 2014-01-11 20:09 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll 2014-01-11 20:09 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll 2014-01-11 20:09 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll 2014-01-11 20:09 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll 2014-01-11 20:09 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll 2014-01-11 20:09 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll 2014-01-11 20:09 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll 2014-01-11 20:09 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll 2014-01-11 20:09 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll 2014-01-11 20:09 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll 2014-01-11 20:09 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll 2014-01-11 20:09 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll 2014-01-11 20:09 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll 2014-01-11 20:09 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll 2014-01-11 20:09 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll 2014-01-11 20:09 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll 2014-01-11 20:09 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll 2014-01-11 20:09 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll 2014-01-11 20:09 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll 2014-01-11 20:09 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll 2014-01-11 20:09 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll 2014-01-11 20:09 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll 2014-01-11 20:09 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll 2014-01-11 20:09 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll 2014-01-11 20:09 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll 2014-01-11 20:09 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll 2014-01-11 20:09 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll 2014-01-11 20:09 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll 2014-01-11 20:09 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll 2014-01-11 20:09 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll 2014-01-11 20:09 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll 2014-01-11 19:13 - 2014-01-24 12:19 - 00000000 ____D C:\Program Files\Steam 2014-01-11 19:13 - 2014-01-11 19:13 - 00000875 _____ C:\Users\Public\Desktop\Steam.lnk 2014-01-11 19:11 - 2014-01-11 19:12 - 08531968 _____ C:\Users\Fabian\Downloads\SteamInstall_German.msi 2014-01-11 13:11 - 2013-10-17 19:02 - 00139776 _____ (Prolific Technology Inc.) C:\Windows\system32\Drivers\ser2pl.sys 2014-01-11 13:11 - 2005-08-03 16:05 - 00035892 _____ (Prolific Technology Inc.) C:\Windows\system32\SER9PL.sys 2014-01-11 13:11 - 2005-08-03 16:04 - 00026719 _____ C:\Windows\system32\SERSPL.VXD 2014-01-11 13:05 - 2014-01-11 13:20 - 00000000 ____D C:\Users\Fabian\Documents\gpsPhotoTagger_Workspace 2014-01-11 13:02 - 2014-01-11 13:02 - 00002370 _____ C:\Windows\DPINST.LOG 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D C:\Program Files\STMicroelectronics 2014-01-11 13:01 - 2014-01-11 13:01 - 00000804 _____ C:\Users\Public\Desktop\GPS Photo Tagger.lnk 2014-01-11 13:01 - 2014-01-11 13:01 - 00000000 ____D C:\Windows\Downloaded Installations ==================== One Month Modified Files and Folders ======= 2014-01-24 17:26 - 2014-01-23 20:09 - 00010461 _____ C:\Users\Fabian\Desktop\FRST.txt 2014-01-24 17:25 - 2014-01-24 17:25 - 00987425 _____ C:\Users\Fabian\Desktop\SecurityCheck.exe 2014-01-24 17:24 - 2012-09-09 12:02 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Skype 2014-01-24 16:55 - 2012-09-02 20:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-24 16:55 - 2009-07-14 05:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-24 16:55 - 2009-07-14 05:34 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-24 14:05 - 2014-01-24 14:04 - 02347384 _____ (ESET) C:\Users\Fabian\Desktop\esetsmartinstaller_enu.exe 2014-01-24 13:52 - 2013-05-11 02:25 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\TS3Client 2014-01-24 12:19 - 2014-01-11 19:13 - 00000000 ____D C:\Program Files\Steam 2014-01-24 11:59 - 2012-09-02 18:27 - 01429154 _____ C:\Windows\WindowsUpdate.log 2014-01-24 11:55 - 2012-11-19 01:33 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-24 11:55 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-24 11:55 - 2009-07-14 05:39 - 00089849 _____ C:\Windows\setupact.log 2014-01-23 20:08 - 2014-01-23 20:08 - 00001143 _____ C:\Users\Fabian\Desktop\JRT.txt 2014-01-23 20:07 - 2014-01-23 20:07 - 00000000 ____D C:\Windows\ERUNT 2014-01-23 20:04 - 2014-01-23 20:03 - 00000000 ____D C:\AdwCleaner 2014-01-23 20:02 - 2014-01-23 20:02 - 01037068 _____ (Thisisu) C:\Users\Fabian\Desktop\JRT.exe 2014-01-23 20:02 - 2014-01-23 20:01 - 01236282 _____ C:\Users\Fabian\Desktop\adwcleaner.exe 2014-01-23 19:58 - 2012-09-06 22:21 - 00161694 _____ C:\Windows\PFRO.log 2014-01-23 19:48 - 2014-01-23 19:48 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Users\Fabian\AppData\Roaming\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-23 19:48 - 2014-01-23 19:48 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-23 19:47 - 2014-01-23 19:46 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Fabian\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-22 22:57 - 2014-01-22 22:57 - 00054156 ____H C:\Windows\QTFont.qfn 2014-01-22 22:57 - 2014-01-22 22:57 - 00001409 _____ C:\Windows\QTFont.for 2014-01-22 21:56 - 2014-01-22 21:56 - 00011687 _____ C:\ComboFix.txt 2014-01-22 21:56 - 2014-01-22 21:44 - 00000000 ____D C:\Qoobox 2014-01-22 21:56 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Default 2014-01-22 21:56 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public 2014-01-22 21:53 - 2014-01-22 21:44 - 00000000 ____D C:\Windows\erdnt 2014-01-22 21:52 - 2009-07-14 03:04 - 00000215 _____ C:\Windows\system.ini 2014-01-22 16:49 - 2014-01-22 16:49 - 00000000 ____D C:\Users\Fabian\Downloads\psaiko dino 2014-01-22 16:47 - 2014-01-22 16:05 - 130201928 _____ C:\Users\Fabian\Downloads\#2773#.rar 2014-01-22 13:10 - 2014-01-22 13:11 - 00010384 _____ C:\Users\Fabian\Desktop\Rückmeldung Alumni.xlsx 2014-01-22 12:44 - 2014-01-22 12:44 - 00000000 ____D C:\Program Files\Microsoft Office 2014-01-22 12:44 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2014-01-22 12:43 - 2014-01-22 12:43 - 00000000 ____D C:\Program Files\MSECache 2014-01-22 12:37 - 2014-01-22 12:29 - 53634800 _____ (Microsoft Corporation) C:\Users\Fabian\Downloads\ExcelViewer.exe 2014-01-22 12:26 - 2014-01-22 12:27 - 00027282 _____ C:\Users\Fabian\Desktop\Mitgliederliste MFCC März 2013.xlsx 2014-01-22 12:25 - 2014-01-22 12:24 - 05173757 ____R (Swearware) C:\Users\Fabian\Desktop\ComboFix.exe 2014-01-21 16:55 - 2011-06-19 23:29 - 00000000 ____D C:\patch 2014-01-21 13:56 - 2014-01-21 13:56 - 00000000 ____D C:\FRST 2014-01-21 13:55 - 2014-01-21 13:55 - 01222144 _____ (Farbar) C:\Users\Fabian\Desktop\FRST.exe 2014-01-21 12:49 - 2014-01-21 12:49 - 00110700 _____ C:\Users\Fabian\Downloads\OTL.Txt 2014-01-21 12:49 - 2014-01-21 12:49 - 00048124 _____ C:\Users\Fabian\Downloads\Extras.Txt 2014-01-21 12:38 - 2014-01-21 12:38 - 00602112 _____ (OldTimer Tools) C:\Users\Fabian\Downloads\OTL.exe 2014-01-16 12:13 - 2009-07-14 05:33 - 00278840 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-16 02:08 - 2013-10-06 19:34 - 00000000 ____D C:\Windows\system32\MRT 2014-01-16 02:07 - 2013-10-06 19:34 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-12 13:57 - 2014-01-12 13:57 - 00001107 _____ C:\Users\Fabian\Desktop\Steam - Verknüpfung.lnk 2014-01-12 13:52 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2014-01-12 12:53 - 2012-09-07 00:09 - 00000000 ____D C:\Program Files\Common Files\Steam 2014-01-12 12:53 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2014-01-12 00:00 - 2013-12-22 15:09 - 00183927 _____ C:\Windows\IE11_main.log 2014-01-11 23:58 - 2014-01-11 23:58 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-11 23:58 - 2014-01-11 23:58 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-11 23:58 - 2014-01-11 23:58 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-11 23:58 - 2014-01-11 23:58 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-11 23:58 - 2014-01-11 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-11 23:58 - 2014-01-11 23:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-11 23:57 - 2013-05-10 19:43 - 00888237 _____ C:\Windows\IE10_main.log 2014-01-11 19:13 - 2014-01-11 19:13 - 00000875 _____ C:\Users\Public\Desktop\Steam.lnk 2014-01-11 19:13 - 2012-09-02 19:11 - 00000000 ____D C:\Users\Fabian 2014-01-11 19:12 - 2014-01-11 19:11 - 08531968 _____ C:\Users\Fabian\Downloads\SteamInstall_German.msi 2014-01-11 13:39 - 2012-09-02 19:14 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 13:20 - 2014-01-11 13:05 - 00000000 ____D C:\Users\Fabian\Documents\gpsPhotoTagger_Workspace 2014-01-11 13:11 - 2012-09-02 19:22 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2014-01-11 13:02 - 2014-01-11 13:02 - 00002370 _____ C:\Windows\DPINST.LOG 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D C:\Program Files\STMicroelectronics 2014-01-11 13:01 - 2014-01-11 13:01 - 00000804 _____ C:\Users\Public\Desktop\GPS Photo Tagger.lnk 2014-01-11 13:01 - 2014-01-11 13:01 - 00000000 ____D C:\Windows\Downloaded Installations 2014-01-11 13:01 - 2012-09-02 19:22 - 00000000 ____D C:\Program Files\Common Files\InstallShield 2014-01-10 15:09 - 2008-04-22 16:18 - 00000000 ___RD C:\Programme Some content of TEMP: ==================== C:\Users\Fabian\AppData\Local\Temp\AskSLib.dll C:\Users\Fabian\AppData\Local\Temp\Foxit Updater.exe C:\Users\Fabian\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-19 12:52 ==================== End Of Log ============================ --- --- --- Also ESET tool hat 44 infizierte dateien gemeldet. Grüße Niggel333 |
25.01.2014, 13:06 | #10 |
/// the machine /// TB-Ausbilder | TR/Dropper.Gen-Avira-Windows 7 32 Bit Funde sind nur in den temps und in Windows.old. Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Ordner Windows.old komplett löschen. Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |