|
Log-Analyse und Auswertung: Windows 7: ddlhost.exe zieht gesamten ArbeitsspeicherWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
31.01.2014, 19:43 | #1 |
| Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher Hallo, ich nutze Windows 7 auf einem Imac und habe seit einigen Tagen das Problem, dass die Arbeitsspeicherauslastung jedesmal wenige Minuten nach dem Hochfahren bei über 90% liegt. Der Task-Manager zeigt an, dass die Datei ddlhost.exe fast den gesamten RAM in Anspruch nimmt. Ich kann die Prozessstruktur beenden und dann, ohne das ich Einschränkungen merke, den Computer benutzen. Tue ich das nicht können die laufenden Programme nicht weiter ausgeführt werden und der Rechner stürzt ab. Ich würde gerne wissen was da los ist und habe Angst, dass ich mir einen Trojaner eingefangen haben könnte. Die übliche Internetrecherche hat mir nicht weitergeholfen. Die Zwischenspeicherungen von Miniaturansichten habe ich schon deaktiviert. Im Anhang füge ich einen screenshot vom process explorer bei. Ich habe die hier beschriebenen Schritte befolgt: http://www.trojaner-board.de/139852-...-ram-win7.html und hoffe ihr könnt mir weiterhelfen. Hier die log. Daten, gemäß eurer Anleitung: defogger: defogger_disable by jpshortstuff (23.02.10.1) Log created at 18:09 on 31/01/2014 (Erik) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-01-2014 01 Ran by Erik (administrator) on ERIK-PC on 31-01-2014 18:12:50 Running from C:\Users\Erik\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe () C:\Windows\System32\AppleOSSMgr.exe (Apple Inc.) C:\Windows\System32\AppleTimeSrv.exe (Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe (Dropbox, Inc.) C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Smartbar) C:\Users\Erik\AppData\Local\Smartbar\Application\Smartbar.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apple_KbdMgr] - C:\Program Files\Boot Camp\Bootcamp.exe [644920 2010-10-06] (Apple Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-09] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKCU\...\Run: [Browser Infrastructure Helper] - C:\Users\Erik\AppData\Local\Smartbar\Application\Smartbar.exe [20760 2013-11-21] (Smartbar) HKCU\...\Policies\Explorer: [NoThumbnailCache] 1 Startup: C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=22/01/2014&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=hp&fr=linkury-tb&installDate=22/01/2014&type=hp1000 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=22/01/2014&type=hp1000 SearchScopes: HKLM - DefaultScope {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=22/01/2014&type=hp1000 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=22/01/2014&type=hp1000 SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=22/01/2014&type=hp1000 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=22/01/2014&type=hp1000 SearchScopes: HKCU - {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} BHO: Yahoo Community Smartbar (by Linkury)Engine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) BHO-x32: Yahoo Community Smartbar (by Linkury)Engine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation) Toolbar: HKLM-x32 - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default FF DefaultSearchEngine: Web Search FF SearchEngineOrder.1: SuchMaschine FF SelectedSearchEngine: Web Search FF Homepage: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=hp&fr=linkury-tb&installDate=22/01/2014&type=hp1000 FF Keyword.URL: hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&fr=linkury-tb&installDate=22/01/2014&type=hp1000&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\startpage-https---deutsch.xml FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml Addition: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2014 01 Ran by Erik at 2014-01-31 18:13:30 Running from C:\Users\Erik\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated) Apple Software Update (x32 Version: 2.1.1.116 - Apple Inc.) Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira) AWIN NotenBox 7 (x32 Version: 7 - AWIN Software) Boot Camp-Dienste (Version: 3.1.36 - Apple Inc.) Digitale Schulbücher (x32 Version: 1.1.0.65 - VBM Service GmbH) Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) English G Lighthouse 1 DFF digital (x32 Version: 1.0.59.0 - Cornelsen Verlag) English G Lighthouse 2 DFF digital (x32 Version: 1.0.19.0 - Cornelsen Schulverlage) Google+ Auto Backup (x32 Version: 1.0.21.81 - Google) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden LibreOffice 4.1 Help Pack (German) (x32 Version: 4.1.4.2 - The Document Foundation) LibreOffice 4.1.4.2 (x32 Version: 4.1.4.2 - The Document Foundation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 24.2.0 - Mozilla) Mozilla Thunderbird 24.2.0 (x86 de) (x32 Version: 24.2.0 - Mozilla) myFuNe 2.0 (x32 Version: - Senatorin für Bildung in Bremen/Germany) Picasa 3 (x32 Version: 3.9 - Google, Inc.) Realtek High Definition Audio Driver (x32 Version: 6.0.1.5936 - Realtek Semiconductor Corp.) VLC media player 2.1.2 (Version: 2.1.2 - VideoLAN) Windows-Treiberpaket - Apple Inc. (AppleUSBEthernet) Net (01/11/2008 3.10.3.9) (Version: 01/11/2008 3.10.3.9 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Bluetooth (03/01/2010 3.0.0.5) (Version: 03/01/2010 3.0.0.5 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Bluetooth Enabler (06/27/2007 2.0.0.1) (Version: 06/27/2007 2.0.0.1 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Broadcom Bluetooth (03/01/2010 3.1.0.3) (Version: 03/01/2010 3.1.0.3 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Built-in iSight (10/25/2007 2.0.1.0) (Version: 10/25/2007 2.0.1.0 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Display (01/23/2009 3.0.0.0) (Version: 01/23/2009 3.0.0.0 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple IR Receiver (02/21/2008 2.0.4.0) (Version: 02/21/2008 2.0.4.0 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Keyboard (03/24/2010 3.1.0.3) (Version: 03/24/2010 3.1.0.3 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Multitouch (02/11/2010 3.1.0.0) (Version: 02/11/2010 3.1.0.0 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Multitouch Mouse (02/11/2010 3.1.0.0) (Version: 02/11/2010 3.1.0.0 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple ODD (01/17/2008 2.0.2.2) (Version: 01/17/2008 2.0.2.2 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Trackpad (07/13/2009 3.0.0.1) (Version: 07/13/2009 3.0.0.1 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Trackpad Enabler (07/13/2009 3.0.0.1) (Version: 07/13/2009 3.0.0.1 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Wireless Mouse (11/30/2009 3.0.0.6) (Version: 11/30/2009 3.0.0.6 - Apple Inc.) Windows-Treiberpaket - Apple Inc. Apple Wireless Trackpad (04/12/2010 3.1.0.5) (Version: 04/12/2010 3.1.0.5 - Apple Inc.) Windows-Treiberpaket - Apple Inc. System (08/22/2008 2.1.1.1) (Version: 08/22/2008 2.1.1.1 - Apple Inc.) Windows-Treiberpaket - Atheros Communications Inc. (athr) Net (11/18/2009 8.0.0.258) (Version: 11/18/2009 8.0.0.258 - Atheros Communications Inc.) Windows-Treiberpaket - Broadcom (b57nd60a) Net (02/09/2010 14.0.0.7) (Version: 02/09/2010 14.0.0.7 - Broadcom) Windows-Treiberpaket - Broadcom (BCM43XX) Net (08/21/2009 5.60.18.8) (Version: 08/21/2009 5.60.18.8 - Broadcom) Windows-Treiberpaket - Cirrus Logic, Inc. (CirrusFilter) MEDIA (04/28/2010 6.6001.1.25) (Version: 04/28/2010 6.6001.1.25 - Cirrus Logic, Inc.) Windows-Treiberpaket - Intel (e1express) Net (02/06/2008 9.12.17.0) (Version: 02/06/2008 9.12.17.0 - Intel) Windows-Treiberpaket - Intel (E1G60) Net (01/08/2008 8.3.9.0) (Version: 01/08/2008 8.3.9.0 - Intel) Windows-Treiberpaket - Intel (e1kexpress) Net (07/22/2008 10.3.45.0) (Version: 07/22/2008 10.3.45.0 - Intel) Windows-Treiberpaket - Intel (e1qexpress) Net (08/05/2008 10.3.49.0) (Version: 08/05/2008 10.3.49.0 - Intel) Windows-Treiberpaket - Intel (e1yexpress) Net (07/16/2008 9.52.10.0) (Version: 07/16/2008 9.52.10.0 - Intel) Windows-Treiberpaket - Intel Net (02/06/2008 9.12.18.0) (Version: 02/06/2008 9.12.18.0 - Intel) Windows-Treiberpaket - Intel Net (06/13/2008 9.52.9.0) (Version: 06/13/2008 9.52.9.0 - Intel) Windows-Treiberpaket - Intel Net (07/22/2008 10.3.45.0) (Version: 07/22/2008 10.3.45.0 - Intel) Windows-Treiberpaket - Intel Net (08/05/2008 10.3.49.0) (Version: 08/05/2008 10.3.49.0 - Intel) Windows-Treiberpaket - Intel Net (11/07/2007 8.10.1.0) (Version: 11/07/2007 8.10.1.0 - Intel) Windows-Treiberpaket - Intel System (07/20/2007 1.2.76.0) (Version: 07/20/2007 1.2.76.0 - Intel) Windows-Treiberpaket - Marvell (yukonx64) Net (12/06/2007 10.51.1.3) (Version: 12/06/2007 10.51.1.3 - Marvell) Yahoo Community Smartbar (x32 Version: 10.179.66.13636 - Linkury Inc.) <==== ATTENTION ==================== Restore Points ========================= 11-01-2014 10:04:47 Geplanter Prüfpunkt 11-01-2014 12:00:35 Installiert Digitale Schulbücher 16-01-2014 02:00:24 Windows Update 16-01-2014 18:34:34 Installed Java 7 Update 51 26-01-2014 12:16:12 TuneUp Utilities 2014 wird entfernt 26-01-2014 12:17:32 TuneUp Utilities 2014 (de-DE) wird entfernt 26-01-2014 15:39:56 Windows Update 30-01-2014 13:34:31 Windows Update 31-01-2014 13:38:01 RegClean Pro Fr, Jan 31, 14 14:37 GMER Logfile: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-01-31 19:05:02 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3500418AS rev.AP25 465,76GB Running: 1ntqbv44.exe; Driver: C:\Users\Erik\AppData\Local\Temp\pwldapow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002bf7000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff80002bf7011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f} ---- User code sections - GMER 2.1 ---- .text C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2728] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000075221465 2 bytes [22, 75] .text C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe[2728] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 00000000752214bb 2 bytes [22, 75] .text ... * 2 ---- Processes - GMER 2.1 ---- Library C:\Users\Erik\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2728](2014-01-03 00:45:04) 0000000004090000 Library C:\Users\Erik\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2728](2013-10-18 23:55:02) 000000006e200000 Library C:\Users\Erik\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe [2728] (ICU Data DLL/The ICU Project)(2013-10-18 23:55:00) 000000006d870000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\78ca39cd1fe9 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\78ca39cd1fe9@78ca39f2b86e 0xC4 0x8F 0xEF 0x42 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\78ca39cd1fe9@109add8ea1fe 0x8D 0xBB 0xBD 0x0F ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\78ca39cd1fe9 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\78ca39cd1fe9@78ca39f2b86e 0xC4 0x8F 0xEF 0x42 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\78ca39cd1fe9@109add8ea1fe 0x8D 0xBB 0xBD 0x0F ... ---- EOF - GMER 2.1 ---- |
31.01.2014, 22:16 | #2 | |
/// the machine /// TB-Ausbilder | Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ |
01.02.2014, 09:52 | #3 |
| Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher Moin,
__________________Combofix erstellt keine .log Datei. Der Prozess wird auch nicht beendet. Am Ende hab ich ein blaues Fenster mit folgendem Text: Bitte warten. Combofix wird vorbereitet, um ausgeführt zu werden. Versuche einen neuen Systemwiederherstellungspunkt zu erstellen. |
01.02.2014, 17:43 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher abbrechen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.02.2014, 22:03 | #5 |
| Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher Hey, die log Datei von Malwarebytes Anti-Malware ist zu groß. Soll ich sie anhängen? Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 01/02/2014 um 20:55:51 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Erik - ERIK-PC # Gestartet von : C:\Users\Erik\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\Users\Erik\AppData\Local\Temp\apn Ordner Gelöscht : C:\Users\Erik\AppData\Roaming\Advanced System Protector Ordner Gelöscht : C:\Users\Erik\AppData\Roaming\Systweak Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk Datei Gelöscht : C:\Users\Erik\Desktop\Startfenster.lnk Datei Gelöscht : C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\Web Search.xml ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Erik\Desktop\Search.lnk Verknüpfung Desinfiziert : C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk Verknüpfung Desinfiziert : C:\Users\Erik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Schlüssel Gelöscht : HKCU\Software\smartbar Schlüssel Gelöscht : HKCU\Software\smartbarbackup Schlüssel Gelöscht : HKCU\Software\smartbarlog Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKLM\Software\systweak ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\prefs.js ] Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=hp&fr=linkury-tb&installDate=22/01/2014&ty[...] Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", true); Zeile gelöscht : user_pref("extensions.helperbar.LastHiddenTime", 23175782); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false); Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", true); Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=b55dd269-4f73-bbec-1586-f9f2fde307ab&searchtype=ds&fr=linkury-tb&installDate=22/01/2014&type=hp1000&p="[...] ************************* AdwCleaner[R0].txt - [6551 octets] - [01/02/2014 20:54:13] AdwCleaner[S0].txt - [5236 octets] - [01/02/2014 20:55:51] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5296 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Professional x64 Ran by Erik on 01.02.2014 at 20:59:49,85 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Users\Erik\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk" ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Erik\AppData\Roaming\mozilla\firefox\profiles\e8jc5zqo.default\minidumps [35 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01.02.2014 at 21:05:17,95 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 04 Ran by Erik (administrator) on ERIK-PC on 01-02-2014 21:56:42 Running from C:\Users\Erik\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Windows\System32\AppleOSSMgr.exe (Apple Inc.) C:\Windows\System32\AppleTimeSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe (Dropbox, Inc.) C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apple_KbdMgr] - C:\Program Files\Boot Camp\Bootcamp.exe [644920 2010-10-06] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-735156766-1306294804-1889490019-1000\...\Policies\Explorer: [NoThumbnailCache] 1 Startup: C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com SearchScopes: HKLM - DefaultScope {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default FF DefaultSearchEngine: Startpage HTTPS - Deutsch FF SearchEngineOrder.1: SuchMaschine FF SelectedSearchEngine: Startpage HTTPS - Deutsch FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\startpage-https---deutsch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-01-08] FF Extension: YouTube Video and Audio Downloader - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\feca4b87-3be4-43da-a1b1-137c24220968@jetpack.xpi [2014-01-17] FF Extension: Sage - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}.xpi [2013-12-31] FF Extension: Adblock Plus - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-31] ==================== Services (Whitelisted) ================= R2 AppleOSSMgr; C:\Windows\system32\AppleOSSMgr.exe [171832 2010-10-06] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R3 applebmt; C:\Windows\System32\DRIVERS\applebmt.sys [51712 2010-09-17] (Apple Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-01 21:56 - 2014-02-01 21:56 - 00000000 ____D () C:\Users\Erik\Downloads\FRST-OlderVersion 2014-02-01 21:55 - 2014-02-01 21:55 - 00000000 ____D () C:\Users\Erik\Desktop\alte log 2014-02-01 21:05 - 2014-02-01 21:05 - 00000897 _____ () C:\Users\Erik\Desktop\JRT.txt 2014-02-01 20:59 - 2014-02-01 20:59 - 01037068 _____ (Thisisu) C:\Users\Erik\Downloads\JRT.exe 2014-02-01 20:59 - 2014-02-01 20:59 - 00000000 ____D () C:\Windows\ERUNT 2014-02-01 20:54 - 2014-02-01 20:55 - 00000000 ____D () C:\AdwCleaner 2014-02-01 20:53 - 2014-02-01 20:53 - 01166132 _____ () C:\Users\Erik\Desktop\adwcleaner.exe 2014-02-01 19:32 - 2014-02-01 19:32 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-01 19:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-01 19:27 - 2014-02-01 19:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Erik\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-01 14:56 - 2014-02-01 14:56 - 00457160 _____ () C:\Windows\Minidump\020114-12448-01.dmp 2014-02-01 12:54 - 2014-02-01 12:54 - 00000000 ___SD () C:\ComboFix 2014-01-31 22:59 - 2014-01-31 22:59 - 00000000 ____D () C:\Qoobox 2014-01-31 22:59 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-01-31 22:59 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-01-31 22:59 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-01-31 22:58 - 2014-01-31 22:58 - 00000000 ____D () C:\Windows\erdnt 2014-01-31 22:53 - 2014-02-01 12:53 - 05179159 ____R (Swearware) C:\Users\Erik\Desktop\ComboFix.exe 2014-01-31 19:09 - 2014-01-31 20:34 - 00000000 ____D () C:\ProgramData\Package Cache 2014-01-31 19:09 - 2014-01-31 20:08 - 00000000 ____D () C:\4673be0d0d73ae9aad34c6c970896e 2014-01-31 18:36 - 2014-01-31 18:36 - 00013824 _____ () C:\Users\Erik\Desktop\gmer absturz.odt 2014-01-31 18:18 - 2014-01-31 18:18 - 00380416 _____ () C:\Users\Erik\Downloads\1ntqbv44.exe 2014-01-31 18:13 - 2014-01-31 18:13 - 00020023 _____ () C:\Users\Erik\Downloads\Addition.txt 2014-01-31 18:12 - 2014-02-01 21:56 - 00006385 _____ () C:\Users\Erik\Downloads\FRST.txt 2014-01-31 18:12 - 2014-02-01 21:56 - 00000000 ____D () C:\FRST 2014-01-31 18:11 - 2014-02-01 21:56 - 02080256 _____ (Farbar) C:\Users\Erik\Downloads\FRST64.exe 2014-01-31 18:09 - 2014-01-31 18:09 - 00000000 _____ () C:\Users\Erik\defogger_reenable 2014-01-31 18:07 - 2014-01-31 18:07 - 00050477 _____ () C:\Users\Erik\Downloads\Defogger.exe 2014-01-31 17:45 - 2014-01-31 17:45 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-01-31 17:06 - 2014-01-31 17:27 - 00000662 __RSH () C:\Users\Erik\ntuser.pol 2014-01-31 16:01 - 2014-01-31 16:01 - 00000000 ____D () C:\Users\Erik\Documents\ProcessExplorer 2014-01-31 11:33 - 2014-01-31 11:34 - 00000000 ____D () C:\Users\Erik\Documents\1und1 2014-01-30 14:34 - 2014-01-30 14:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-30 14:34 - 2014-01-06 16:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-27 06:26 - 2014-01-27 06:26 - 01095405 _____ () C:\Users\Erik\Desktop\Antrag Fondbanking.pdf.jpeg 2014-01-26 15:14 - 2014-01-31 17:47 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-01-26 15:12 - 2014-01-26 15:12 - 02365840 _____ () C:\Users\Erik\Downloads\SecurityTaskManager_Setup.exe 2014-01-26 14:25 - 2014-01-31 19:27 - 00007601 _____ () C:\Users\Erik\AppData\Local\Resmon.ResmonCfg 2014-01-26 12:12 - 2014-01-26 12:12 - 00276680 _____ () C:\Windows\Minidump\012614-18704-01.dmp 2014-01-26 11:52 - 2014-01-26 11:52 - 00000000 ____D () C:\Users\Erik\Documents\BOB BSAG 2014-01-22 08:36 - 2014-01-23 06:07 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\TuneUp Software 2014-01-22 08:35 - 2014-02-01 20:55 - 00001087 _____ () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-01-22 08:35 - 2014-02-01 20:55 - 00001057 _____ () C:\Users\Erik\Desktop\Search.lnk 2014-01-22 08:33 - 2014-01-31 17:46 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\DVDVideoSoft 2014-01-22 08:29 - 2014-01-22 08:29 - 33000776 _____ (DVDVideoSoft Ltd. ) C:\Users\Erik\Downloads\FreeAudioConverter5.0.32.1230.exe 2014-01-17 15:46 - 2014-01-17 15:46 - 00276680 _____ () C:\Windows\Minidump\011714-19827-01.dmp 2014-01-17 08:33 - 2014-02-01 14:56 - 309019056 _____ () C:\Windows\MEMORY.DMP 2014-01-17 08:33 - 2014-02-01 14:56 - 00000000 ____D () C:\Windows\Minidump 2014-01-17 08:33 - 2014-01-17 08:33 - 00276680 _____ () C:\Windows\Minidump\011714-19858-01.dmp 2014-01-17 07:45 - 2014-01-17 07:45 - 02903369 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling & Die Gesellschaft - La La La Langweilig.mp4 2014-01-17 07:44 - 2014-01-17 07:44 - 10430499 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling - Wer hat uns verraten.mp4 2014-01-17 07:43 - 2014-01-17 07:43 - 16439242 _____ () C:\Users\Erik\Desktop\K.I.Z. - Raus aus dem Amt.mp4 2014-01-17 07:40 - 2014-01-17 07:41 - 04188816 _____ () C:\Users\Erik\Desktop\NMZS - 99 Leben.mp4 2014-01-17 07:40 - 2014-01-17 07:40 - 09035081 _____ () C:\Users\Erik\Desktop\Antilopen Gang - Leben und Streben des Friedrich Kautz.mp4 2014-01-17 07:39 - 2014-01-17 07:39 - 14068043 _____ () C:\Users\Erik\Desktop\Benjamin Blümchen auf dem Baum.mp4 2014-01-17 07:26 - 2014-01-17 07:37 - 420000818 _____ () C:\Users\Erik\Desktop\HINTERLAND FULL ALBUM - CASPER [HD].mp4 2014-01-16 20:22 - 2014-01-16 21:29 - 2147483648 _____ () C:\Users\Erik\Downloads\erik.tc 2014-01-16 19:35 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-16 19:35 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-16 19:35 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-16 19:35 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-16 19:34 - 2014-01-16 19:35 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-16 06:03 - 2014-01-16 06:08 - 211344833 _____ () C:\Users\Erik\Desktop\Planet Wissen Zivilcourage.webm 2014-01-15 15:24 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 15:24 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-12 14:21 - 2014-01-12 14:31 - 421347611 _____ () C:\Users\Erik\Downloads\Die_Germanen3-Die_Varusschlacht.mp4 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Digitale.Schulbucher 2014-01-11 13:00 - 2014-01-11 13:00 - 00001904 _____ () C:\Users\Public\Desktop\Digitale Schulbücher.lnk 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\YDP 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Program Files (x86)\Digitale Schulbücher 2014-01-11 12:59 - 2014-01-11 12:59 - 00000000 ____D () C:\Users\Erik\Documents\DigitaleSchulbuecher_WIN_200_b83 2014-01-08 08:26 - 2014-01-08 08:26 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup 2014-01-08 08:16 - 2014-01-16 06:10 - 00000000 ____D () C:\Users\Erik\dwhelper 2014-01-08 08:16 - 2014-01-08 08:19 - 76270230 _____ () C:\Users\Erik\Desktop\Unsere Erde.mp4 2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-01-05 21:10 - 2014-01-05 21:10 - 09544168 _____ (Senatorin für Bildung in Bremen/Germany ) C:\Users\Erik\Downloads\setup_myFuNe_2.exe 2014-01-05 21:10 - 2014-01-05 21:10 - 00000000 ____D () C:\Program Files (x86)\myFuNe 2014-01-05 21:10 - 2009-08-09 11:47 - 00032768 _____ (sfb) C:\Windows\SysWOW64\clsFileDownload.dll 2014-01-05 21:10 - 2004-03-09 01:00 - 01081616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00609824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMCTL32.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00224016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00124688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWINSCK.OCX 2014-01-05 21:10 - 2004-02-23 01:00 - 00322560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDBRPTR.DLL 2014-01-05 21:10 - 2004-02-23 01:00 - 00119808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL 2014-01-05 21:10 - 2001-04-24 15:24 - 00457257 _____ (Janus Systems SA de CV) C:\Windows\SysWOW64\GridEX20.ocx 2014-01-05 21:10 - 2000-10-02 01:00 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL 2014-01-05 21:10 - 2000-07-15 01:00 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DBRPRDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMDLGDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WINSKDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\STDFTDE.DLL 2014-01-05 21:10 - 1998-05-05 01:00 - 00112640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMCTLDE.DLL 2014-01-05 19:39 - 2014-01-05 19:39 - 00002140 _____ () C:\Users\Erik\Desktop\Schule - Verknüpfung.lnk 2014-01-05 15:33 - 2014-01-05 16:06 - 1368683531 _____ () C:\Users\Erik\Downloads\Römer - b.richter@lehrer4u.zip 2014-01-05 11:54 - 2014-01-20 14:39 - 00917504 _____ () C:\Users\Erik\Desktop\FLD_Pasemann_Erik_Pa_01_13_14_0445.mFN 2014-01-03 22:23 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-03 22:23 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-03 22:23 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-03 22:23 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-03 22:23 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-03 22:23 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-03 22:23 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-03 22:23 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-03 22:23 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-03 22:23 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-03 22:23 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-03 22:23 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-03 22:23 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-03 22:23 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-03 22:23 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-03 22:23 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-03 22:23 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-03 22:23 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-03 22:23 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-03 22:23 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-03 22:23 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-03 22:23 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-03 22:23 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-03 22:23 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-03 22:23 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-03 22:23 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-03 22:23 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-03 22:23 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-03 22:23 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-03 22:23 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-03 22:23 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-01-02 16:14 - 2014-01-02 16:37 - 00000000 ____D () C:\ProgramData\Cornelsen 2014-01-02 16:14 - 2014-01-02 16:37 - 00000000 ____D () C:\Program Files (x86)\Cornelsen 2014-01-02 14:36 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2014-01-02 14:33 - 2014-01-02 14:33 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 14:33 - 2014-01-02 14:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 14:33 - 2014-01-02 14:33 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 14:33 - 2014-01-02 14:33 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 14:33 - 2014-01-02 14:33 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 14:33 - 2014-01-02 14:33 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 14:33 - 2014-01-02 14:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-02 14:32 - 2014-01-02 14:32 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-01-02 13:54 - 2014-01-02 13:54 - 00000000 ____D () C:\Users\Erik\Documents\Fax ==================== One Month Modified Files and Folders ======= 2014-02-01 21:57 - 2014-01-31 18:12 - 00006385 _____ () C:\Users\Erik\Downloads\FRST.txt 2014-02-01 21:56 - 2014-02-01 21:56 - 00000000 ____D () C:\Users\Erik\Downloads\FRST-OlderVersion 2014-02-01 21:56 - 2014-01-31 18:12 - 00000000 ____D () C:\FRST 2014-02-01 21:56 - 2014-01-31 18:11 - 02080256 _____ (Farbar) C:\Users\Erik\Downloads\FRST64.exe 2014-02-01 21:55 - 2014-02-01 21:55 - 00000000 ____D () C:\Users\Erik\Desktop\alte log 2014-02-01 21:53 - 2009-07-14 05:45 - 00026704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-01 21:53 - 2009-07-14 05:45 - 00026704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-01 21:50 - 2013-12-31 08:54 - 00643628 _____ () C:\Windows\system32\perfh007.dat 2014-02-01 21:50 - 2013-12-31 08:54 - 00126188 _____ () C:\Windows\system32\perfc007.dat 2014-02-01 21:50 - 2009-07-14 06:13 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-01 21:47 - 2013-12-31 19:10 - 00000000 ___RD () C:\Users\Erik\Dropbox 2014-02-01 21:47 - 2013-12-31 19:07 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Dropbox 2014-02-01 21:46 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-01 21:46 - 2009-07-14 05:51 - 00032033 _____ () C:\Windows\setupact.log 2014-02-01 21:45 - 2013-12-31 01:29 - 01742674 _____ () C:\Windows\WindowsUpdate.log 2014-02-01 21:19 - 2013-12-31 13:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-01 21:05 - 2014-02-01 21:05 - 00000897 _____ () C:\Users\Erik\Desktop\JRT.txt 2014-02-01 20:59 - 2014-02-01 20:59 - 01037068 _____ (Thisisu) C:\Users\Erik\Downloads\JRT.exe 2014-02-01 20:59 - 2014-02-01 20:59 - 00000000 ____D () C:\Windows\ERUNT 2014-02-01 20:55 - 2014-02-01 20:54 - 00000000 ____D () C:\AdwCleaner 2014-02-01 20:55 - 2014-01-22 08:35 - 00001087 _____ () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-02-01 20:55 - 2014-01-22 08:35 - 00001057 _____ () C:\Users\Erik\Desktop\Search.lnk 2014-02-01 20:53 - 2014-02-01 20:53 - 01166132 _____ () C:\Users\Erik\Desktop\adwcleaner.exe 2014-02-01 19:57 - 2010-11-21 04:47 - 00408880 _____ () C:\Windows\PFRO.log 2014-02-01 19:32 - 2014-02-01 19:32 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-01 19:27 - 2014-02-01 19:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Erik\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-01 14:56 - 2014-02-01 14:56 - 00457160 _____ () C:\Windows\Minidump\020114-12448-01.dmp 2014-02-01 14:56 - 2014-01-17 08:33 - 309019056 _____ () C:\Windows\MEMORY.DMP 2014-02-01 14:56 - 2014-01-17 08:33 - 00000000 ____D () C:\Windows\Minidump 2014-02-01 12:54 - 2014-02-01 12:54 - 00000000 ___SD () C:\ComboFix 2014-02-01 12:53 - 2014-01-31 22:53 - 05179159 ____R (Swearware) C:\Users\Erik\Desktop\ComboFix.exe 2014-01-31 22:59 - 2014-01-31 22:59 - 00000000 ____D () C:\Qoobox 2014-01-31 22:58 - 2014-01-31 22:58 - 00000000 ____D () C:\Windows\erdnt 2014-01-31 20:34 - 2014-01-31 19:09 - 00000000 ____D () C:\ProgramData\Package Cache 2014-01-31 20:08 - 2014-01-31 19:09 - 00000000 ____D () C:\4673be0d0d73ae9aad34c6c970896e 2014-01-31 19:27 - 2014-01-26 14:25 - 00007601 _____ () C:\Users\Erik\AppData\Local\Resmon.ResmonCfg 2014-01-31 18:36 - 2014-01-31 18:36 - 00013824 _____ () C:\Users\Erik\Desktop\gmer absturz.odt 2014-01-31 18:18 - 2014-01-31 18:18 - 00380416 _____ () C:\Users\Erik\Downloads\1ntqbv44.exe 2014-01-31 18:13 - 2014-01-31 18:13 - 00020023 _____ () C:\Users\Erik\Downloads\Addition.txt 2014-01-31 18:09 - 2014-01-31 18:09 - 00000000 _____ () C:\Users\Erik\defogger_reenable 2014-01-31 18:09 - 2013-12-31 01:30 - 00000000 ____D () C:\Users\Erik 2014-01-31 18:07 - 2014-01-31 18:07 - 00050477 _____ () C:\Users\Erik\Downloads\Defogger.exe 2014-01-31 17:47 - 2014-01-26 15:14 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-01-31 17:46 - 2014-01-22 08:33 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\DVDVideoSoft 2014-01-31 17:45 - 2014-01-31 17:45 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-01-31 17:27 - 2014-01-31 17:06 - 00000662 __RSH () C:\Users\Erik\ntuser.pol 2014-01-31 16:36 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-01-31 16:01 - 2014-01-31 16:01 - 00000000 ____D () C:\Users\Erik\Documents\ProcessExplorer 2014-01-31 11:34 - 2014-01-31 11:33 - 00000000 ____D () C:\Users\Erik\Documents\1und1 2014-01-30 14:35 - 2014-01-30 14:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-27 06:26 - 2014-01-27 06:26 - 01095405 _____ () C:\Users\Erik\Desktop\Antrag Fondbanking.pdf.jpeg 2014-01-26 15:12 - 2014-01-26 15:12 - 02365840 _____ () C:\Users\Erik\Downloads\SecurityTaskManager_Setup.exe 2014-01-26 12:12 - 2014-01-26 12:12 - 00276680 _____ () C:\Windows\Minidump\012614-18704-01.dmp 2014-01-26 12:00 - 2013-12-31 16:23 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\vlc 2014-01-26 11:52 - 2014-01-26 11:52 - 00000000 ____D () C:\Users\Erik\Documents\BOB BSAG 2014-01-23 06:07 - 2014-01-22 08:36 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-01-22 08:57 - 2013-12-31 01:30 - 00000000 ____D () C:\Users\Erik\AppData\Local\VirtualStore 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\TuneUp Software 2014-01-22 08:29 - 2014-01-22 08:29 - 33000776 _____ (DVDVideoSoft Ltd. ) C:\Users\Erik\Downloads\FreeAudioConverter5.0.32.1230.exe 2014-01-20 17:47 - 2013-12-31 12:25 - 00000000 ____D () C:\Users\Public\Documents\Schule 2014-01-20 14:39 - 2014-01-05 11:54 - 00917504 _____ () C:\Users\Erik\Desktop\FLD_Pasemann_Erik_Pa_01_13_14_0445.mFN 2014-01-17 15:46 - 2014-01-17 15:46 - 00276680 _____ () C:\Windows\Minidump\011714-19827-01.dmp 2014-01-17 08:39 - 2013-12-31 19:10 - 00000984 _____ () C:\Users\Erik\Desktop\Dropbox.lnk 2014-01-17 08:39 - 2013-12-31 19:08 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-17 08:39 - 2013-12-31 01:30 - 00000000 ___RD () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-17 08:33 - 2014-01-17 08:33 - 00276680 _____ () C:\Windows\Minidump\011714-19858-01.dmp 2014-01-17 07:45 - 2014-01-17 07:45 - 02903369 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling & Die Gesellschaft - La La La Langweilig.mp4 2014-01-17 07:44 - 2014-01-17 07:44 - 10430499 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling - Wer hat uns verraten.mp4 2014-01-17 07:43 - 2014-01-17 07:43 - 16439242 _____ () C:\Users\Erik\Desktop\K.I.Z. - Raus aus dem Amt.mp4 2014-01-17 07:41 - 2014-01-17 07:40 - 04188816 _____ () C:\Users\Erik\Desktop\NMZS - 99 Leben.mp4 2014-01-17 07:40 - 2014-01-17 07:40 - 09035081 _____ () C:\Users\Erik\Desktop\Antilopen Gang - Leben und Streben des Friedrich Kautz.mp4 2014-01-17 07:39 - 2014-01-17 07:39 - 14068043 _____ () C:\Users\Erik\Desktop\Benjamin Blümchen auf dem Baum.mp4 2014-01-17 07:37 - 2014-01-17 07:26 - 420000818 _____ () C:\Users\Erik\Desktop\HINTERLAND FULL ALBUM - CASPER [HD].mp4 2014-01-16 21:29 - 2014-01-16 20:22 - 2147483648 _____ () C:\Users\Erik\Downloads\erik.tc 2014-01-16 19:35 - 2014-01-16 19:34 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-16 19:35 - 2013-12-31 14:37 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-16 19:35 - 2013-12-31 14:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-01-16 06:10 - 2014-01-08 08:16 - 00000000 ____D () C:\Users\Erik\dwhelper 2014-01-16 06:08 - 2014-01-16 06:03 - 211344833 _____ () C:\Users\Erik\Desktop\Planet Wissen Zivilcourage.webm 2014-01-16 03:17 - 2009-07-14 05:45 - 00328464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-12 15:54 - 2013-12-31 13:26 - 00000000 ____D () C:\Users\Public\Documents\Finanzen 2014-01-12 14:31 - 2014-01-12 14:21 - 421347611 _____ () C:\Users\Erik\Downloads\Die_Germanen3-Die_Varusschlacht.mp4 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Digitale.Schulbucher 2014-01-11 13:01 - 2013-12-31 01:40 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-11 13:00 - 2014-01-11 13:00 - 00001904 _____ () C:\Users\Public\Desktop\Digitale Schulbücher.lnk 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\YDP 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Program Files (x86)\Digitale Schulbücher 2014-01-11 12:59 - 2014-01-11 12:59 - 00000000 ____D () C:\Users\Erik\Documents\DigitaleSchulbuecher_WIN_200_b83 2014-01-08 08:26 - 2014-01-08 08:26 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup 2014-01-08 08:19 - 2014-01-08 08:16 - 76270230 _____ () C:\Users\Erik\Desktop\Unsere Erde.mp4 2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-01-06 16:20 - 2014-01-30 14:34 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-05 21:10 - 2014-01-05 21:10 - 09544168 _____ (Senatorin für Bildung in Bremen/Germany ) C:\Users\Erik\Downloads\setup_myFuNe_2.exe 2014-01-05 21:10 - 2014-01-05 21:10 - 00000000 ____D () C:\Program Files (x86)\myFuNe 2014-01-05 19:39 - 2014-01-05 19:39 - 00002140 _____ () C:\Users\Erik\Desktop\Schule - Verknüpfung.lnk 2014-01-05 16:06 - 2014-01-05 15:33 - 1368683531 _____ () C:\Users\Erik\Downloads\Römer - b.richter@lehrer4u.zip 2014-01-03 10:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-01-02 22:02 - 2010-11-21 08:17 - 00000000 ____D () C:\Program Files\Windows Journal 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\winrm 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\WCN 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\slmgr 2014-01-02 22:02 - 2010-11-21 08:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts 2014-01-02 22:02 - 2009-07-14 06:37 - 00000000 ____D () C:\Windows\DigitalLocker 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Sidebar 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\Windows Defender 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\DVD Maker 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Photo Viewer 2014-01-02 22:02 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Setup 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\migwiz 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\com 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Setup 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\oobe 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\migwiz 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\com 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\IME 2014-01-02 22:02 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-01-02 20:31 - 2013-12-31 14:48 - 00002005 _____ () C:\Users\Erik\Desktop\Kies Air Discovery Service.lnk 2014-01-02 16:37 - 2014-01-02 16:14 - 00000000 ____D () C:\ProgramData\Cornelsen 2014-01-02 16:37 - 2014-01-02 16:14 - 00000000 ____D () C:\Program Files (x86)\Cornelsen 2014-01-02 16:33 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries 2014-01-02 16:03 - 2013-12-31 01:30 - 00001417 _____ () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-01-02 15:01 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-01-02 14:36 - 2013-12-31 18:23 - 00018587 _____ () C:\Windows\IE11_main.log 2014-01-02 14:33 - 2014-01-02 14:33 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2014-01-02 14:33 - 2014-01-02 14:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2014-01-02 14:33 - 2014-01-02 14:33 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2014-01-02 14:33 - 2014-01-02 14:33 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2014-01-02 14:33 - 2014-01-02 14:33 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2014-01-02 14:33 - 2014-01-02 14:33 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2014-01-02 14:33 - 2014-01-02 14:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2014-01-02 14:33 - 2014-01-02 14:33 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-01-02 14:33 - 2014-01-02 14:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-01-02 14:32 - 2014-01-02 14:32 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-01-02 14:32 - 2014-01-02 14:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-01-02 14:32 - 2014-01-02 14:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-01-02 13:54 - 2014-01-02 13:54 - 00000000 ____D () C:\Users\Erik\Documents\Fax 2014-01-02 01:13 - 2009-07-14 04:20 - 00000000 __RSD () C:\Windows\Media 2014-01-02 01:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration 2014-01-02 01:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared Some content of TEMP: ==================== C:\Users\Erik\AppData\Local\Temp\avgnt.exe C:\Users\Erik\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Erik\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Erik\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Erik\AppData\Local\Temp\Quarantine.exe C:\Users\Erik\AppData\Local\Temp\Setup64.exe C:\Users\Erik\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 08:54 ==================== End Of Log ============================ --- --- --- |
02.02.2014, 07:33 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: ddlhost.exe zieht gesamten ArbeitsspeicherESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher |
02.02.2014, 14:07 | #7 |
| Windows 7: ddlhost.exe zieht gesamten ArbeitsspeicherCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=b9a7ca947d94064296b25edfa47f81be # engine=16907 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-02 11:40:34 # local_time=2014-02-02 12:40:34 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 62038 142971084 0 0 # scanned=559662 # found=0 # cleaned=0 # scan_time=6414 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Flash Player 11.9.900.170 Adobe Reader XI Mozilla Firefox (26.0) Mozilla Thunderbird (24.2.0) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2014 04 Ran by Erik (administrator) on ERIK-PC on 02-02-2014 14:05:11 Running from C:\Users\Erik\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Windows\System32\AppleOSSMgr.exe (Apple Inc.) C:\Windows\System32\AppleTimeSrv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Apple Inc.) C:\Program Files\Boot Camp\Bootcamp.exe (Dropbox, Inc.) C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apple_KbdMgr] - C:\Program Files\Boot Camp\Bootcamp.exe [644920 2010-10-06] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-735156766-1306294804-1889490019-1000\...\Policies\Explorer: [NoThumbnailCache] 1 Startup: C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Erik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com SearchScopes: HKLM - DefaultScope {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {A04F8E38-1F1D-4B10-96E2-789259D692E1} URL = hxxp://www.sm.de/?q={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default FF DefaultSearchEngine: Startpage HTTPS - Deutsch FF SearchEngineOrder.1: SuchMaschine FF SelectedSearchEngine: Startpage HTTPS - Deutsch FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\search_engine.xml FF SearchPlugin: C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\searchplugins\startpage-https---deutsch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-01-08] FF Extension: YouTube Video and Audio Downloader - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\feca4b87-3be4-43da-a1b1-137c24220968@jetpack.xpi [2014-01-17] FF Extension: Sage - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\{a6ca9b3b-5e52-4f47-85d8-cca35bb57596}.xpi [2013-12-31] FF Extension: Adblock Plus - C:\Users\Erik\AppData\Roaming\Mozilla\Firefox\Profiles\e8jc5zqo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-31] ==================== Services (Whitelisted) ================= R2 AppleOSSMgr; C:\Windows\system32\AppleOSSMgr.exe [171832 2010-10-06] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R3 applebmt; C:\Windows\System32\DRIVERS\applebmt.sys [51712 2010-09-17] (Apple Inc.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-02 14:05 - 2014-02-02 14:05 - 00006309 _____ () C:\Users\Erik\Desktop\FRST.txt 2014-02-02 13:59 - 2014-02-02 13:59 - 00987425 _____ () C:\Users\Erik\Desktop\SecurityCheck.exe 2014-02-02 10:46 - 2014-02-02 10:46 - 02347384 _____ (ESET) C:\Users\Erik\Downloads\esetsmartinstaller_enu.exe 2014-02-01 21:56 - 2014-02-01 21:56 - 00000000 ____D () C:\Users\Erik\Downloads\FRST-OlderVersion 2014-02-01 21:55 - 2014-02-01 21:55 - 00000000 ____D () C:\Users\Erik\Desktop\alte log 2014-02-01 21:05 - 2014-02-01 21:05 - 00000897 _____ () C:\Users\Erik\Desktop\JRT.txt 2014-02-01 20:59 - 2014-02-01 20:59 - 01037068 _____ (Thisisu) C:\Users\Erik\Downloads\JRT.exe 2014-02-01 20:59 - 2014-02-01 20:59 - 00000000 ____D () C:\Windows\ERUNT 2014-02-01 20:54 - 2014-02-01 20:55 - 00000000 ____D () C:\AdwCleaner 2014-02-01 20:53 - 2014-02-01 20:53 - 01166132 _____ () C:\Users\Erik\Desktop\adwcleaner.exe 2014-02-01 19:32 - 2014-02-01 19:32 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-01 19:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-01 19:27 - 2014-02-01 19:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Erik\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-01 14:56 - 2014-02-01 14:56 - 00457160 _____ () C:\Windows\Minidump\020114-12448-01.dmp 2014-02-01 12:54 - 2014-02-01 12:54 - 00000000 ___SD () C:\ComboFix 2014-01-31 22:59 - 2014-01-31 22:59 - 00000000 ____D () C:\Qoobox 2014-01-31 22:59 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-01-31 22:59 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-01-31 22:59 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-01-31 22:59 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-01-31 22:58 - 2014-01-31 22:58 - 00000000 ____D () C:\Windows\erdnt 2014-01-31 22:53 - 2014-02-01 12:53 - 05179159 ____R (Swearware) C:\Users\Erik\Desktop\ComboFix.exe 2014-01-31 19:09 - 2014-01-31 20:34 - 00000000 ____D () C:\ProgramData\Package Cache 2014-01-31 19:09 - 2014-01-31 20:08 - 00000000 ____D () C:\4673be0d0d73ae9aad34c6c970896e 2014-01-31 18:36 - 2014-01-31 18:36 - 00013824 _____ () C:\Users\Erik\Desktop\gmer absturz.odt 2014-01-31 18:18 - 2014-01-31 18:18 - 00380416 _____ () C:\Users\Erik\Downloads\1ntqbv44.exe 2014-01-31 18:13 - 2014-01-31 18:13 - 00020023 _____ () C:\Users\Erik\Downloads\Addition.txt 2014-01-31 18:12 - 2014-02-02 14:05 - 00000000 ____D () C:\FRST 2014-01-31 18:12 - 2014-02-01 21:57 - 00059022 _____ () C:\Users\Erik\Downloads\FRST.txt 2014-01-31 18:11 - 2014-02-01 21:56 - 02080256 _____ (Farbar) C:\Users\Erik\Desktop\FRST64.exe 2014-01-31 18:09 - 2014-01-31 18:09 - 00000000 _____ () C:\Users\Erik\defogger_reenable 2014-01-31 18:07 - 2014-01-31 18:07 - 00050477 _____ () C:\Users\Erik\Downloads\Defogger.exe 2014-01-31 17:45 - 2014-01-31 17:45 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-01-31 17:06 - 2014-01-31 17:27 - 00000662 __RSH () C:\Users\Erik\ntuser.pol 2014-01-31 16:01 - 2014-01-31 16:01 - 00000000 ____D () C:\Users\Erik\Documents\ProcessExplorer 2014-01-31 11:33 - 2014-01-31 11:34 - 00000000 ____D () C:\Users\Erik\Documents\1und1 2014-01-30 14:34 - 2014-01-30 14:35 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-30 14:34 - 2014-01-06 16:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-27 06:26 - 2014-01-27 06:26 - 01095405 _____ () C:\Users\Erik\Desktop\Antrag Fondbanking.pdf.jpeg 2014-01-26 15:14 - 2014-01-31 17:47 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-01-26 15:12 - 2014-01-26 15:12 - 02365840 _____ () C:\Users\Erik\Downloads\SecurityTaskManager_Setup.exe 2014-01-26 14:25 - 2014-01-31 19:27 - 00007601 _____ () C:\Users\Erik\AppData\Local\Resmon.ResmonCfg 2014-01-26 12:12 - 2014-01-26 12:12 - 00276680 _____ () C:\Windows\Minidump\012614-18704-01.dmp 2014-01-26 11:52 - 2014-01-26 11:52 - 00000000 ____D () C:\Users\Erik\Documents\BOB BSAG 2014-01-22 08:36 - 2014-01-23 06:07 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\TuneUp Software 2014-01-22 08:35 - 2014-02-01 20:55 - 00001087 _____ () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-01-22 08:35 - 2014-02-01 20:55 - 00001057 _____ () C:\Users\Erik\Desktop\Search.lnk 2014-01-22 08:33 - 2014-01-31 17:46 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\DVDVideoSoft 2014-01-22 08:29 - 2014-01-22 08:29 - 33000776 _____ (DVDVideoSoft Ltd. ) C:\Users\Erik\Downloads\FreeAudioConverter5.0.32.1230.exe 2014-01-17 15:46 - 2014-01-17 15:46 - 00276680 _____ () C:\Windows\Minidump\011714-19827-01.dmp 2014-01-17 08:33 - 2014-02-01 14:56 - 309019056 _____ () C:\Windows\MEMORY.DMP 2014-01-17 08:33 - 2014-02-01 14:56 - 00000000 ____D () C:\Windows\Minidump 2014-01-17 08:33 - 2014-01-17 08:33 - 00276680 _____ () C:\Windows\Minidump\011714-19858-01.dmp 2014-01-17 07:45 - 2014-01-17 07:45 - 02903369 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling & Die Gesellschaft - La La La Langweilig.mp4 2014-01-17 07:44 - 2014-01-17 07:44 - 10430499 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling - Wer hat uns verraten.mp4 2014-01-17 07:43 - 2014-01-17 07:43 - 16439242 _____ () C:\Users\Erik\Desktop\K.I.Z. - Raus aus dem Amt.mp4 2014-01-17 07:40 - 2014-01-17 07:41 - 04188816 _____ () C:\Users\Erik\Desktop\NMZS - 99 Leben.mp4 2014-01-17 07:40 - 2014-01-17 07:40 - 09035081 _____ () C:\Users\Erik\Desktop\Antilopen Gang - Leben und Streben des Friedrich Kautz.mp4 2014-01-17 07:39 - 2014-01-17 07:39 - 14068043 _____ () C:\Users\Erik\Desktop\Benjamin Blümchen auf dem Baum.mp4 2014-01-17 07:26 - 2014-01-17 07:37 - 420000818 _____ () C:\Users\Erik\Desktop\HINTERLAND FULL ALBUM - CASPER [HD].mp4 2014-01-16 20:22 - 2014-01-16 21:29 - 2147483648 _____ () C:\Users\Erik\Downloads\erik.tc 2014-01-16 19:35 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-16 19:35 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-16 19:35 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-16 19:35 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-16 19:34 - 2014-01-16 19:35 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-16 06:03 - 2014-01-16 06:08 - 211344833 _____ () C:\Users\Erik\Desktop\Planet Wissen Zivilcourage.webm 2014-01-15 15:24 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 15:24 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 15:24 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-12 14:21 - 2014-01-12 14:31 - 421347611 _____ () C:\Users\Erik\Downloads\Die_Germanen3-Die_Varusschlacht.mp4 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Digitale.Schulbucher 2014-01-11 13:00 - 2014-01-11 13:00 - 00001904 _____ () C:\Users\Public\Desktop\Digitale Schulbücher.lnk 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\YDP 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Program Files (x86)\Digitale Schulbücher 2014-01-11 12:59 - 2014-01-11 12:59 - 00000000 ____D () C:\Users\Erik\Documents\DigitaleSchulbuecher_WIN_200_b83 2014-01-08 08:26 - 2014-01-08 08:26 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup 2014-01-08 08:16 - 2014-01-16 06:10 - 00000000 ____D () C:\Users\Erik\dwhelper 2014-01-08 08:16 - 2014-01-08 08:19 - 76270230 _____ () C:\Users\Erik\Desktop\Unsere Erde.mp4 2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-01-05 21:10 - 2014-01-05 21:10 - 09544168 _____ (Senatorin für Bildung in Bremen/Germany ) C:\Users\Erik\Downloads\setup_myFuNe_2.exe 2014-01-05 21:10 - 2014-01-05 21:10 - 00000000 ____D () C:\Program Files (x86)\myFuNe 2014-01-05 21:10 - 2009-08-09 11:47 - 00032768 _____ (sfb) C:\Windows\SysWOW64\clsFileDownload.dll 2014-01-05 21:10 - 2004-03-09 01:00 - 01081616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00662288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCT2.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00609824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMCTL32.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00224016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTL32.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00152848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\COMDLG32.OCX 2014-01-05 21:10 - 2004-03-09 01:00 - 00124688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWINSCK.OCX 2014-01-05 21:10 - 2004-02-23 01:00 - 00322560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSDBRPTR.DLL 2014-01-05 21:10 - 2004-02-23 01:00 - 00119808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL 2014-01-05 21:10 - 2001-04-24 15:24 - 00457257 _____ (Janus Systems SA de CV) C:\Windows\SysWOW64\GridEX20.ocx 2014-01-05 21:10 - 2000-10-02 01:00 - 00125712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6DE.DLL 2014-01-05 21:10 - 2000-07-15 01:00 - 00101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VB6STKIT.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00158208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCMCDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCC2DE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DBRPRDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMDLGDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TABCTDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00016896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WINSKDE.DLL 2014-01-05 21:10 - 1998-07-06 01:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\STDFTDE.DLL 2014-01-05 21:10 - 1998-05-05 01:00 - 00112640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CMCTLDE.DLL 2014-01-05 19:39 - 2014-01-05 19:39 - 00002140 _____ () C:\Users\Erik\Desktop\Schule - Verknüpfung.lnk 2014-01-05 15:33 - 2014-01-05 16:06 - 1368683531 _____ () C:\Users\Erik\Downloads\Römer - b.richter@lehrer4u.zip 2014-01-05 11:54 - 2014-01-20 14:39 - 00917504 _____ () C:\Users\Erik\Desktop\FLD_Pasemann_Erik_Pa_01_13_14_0445.mFN 2014-01-03 22:23 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-01-03 22:23 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-01-03 22:23 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-01-03 22:23 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-01-03 22:23 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-01-03 22:23 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-01-03 22:23 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-01-03 22:23 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-01-03 22:23 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-01-03 22:23 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-01-03 22:23 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-01-03 22:23 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-01-03 22:23 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-01-03 22:23 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-01-03 22:23 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-01-03 22:23 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-01-03 22:23 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-01-03 22:23 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-01-03 22:23 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-01-03 22:23 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-01-03 22:23 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-01-03 22:23 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-01-03 22:23 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-01-03 22:23 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-01-03 22:23 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-01-03 22:23 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-01-03 22:23 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-01-03 22:23 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-01-03 22:23 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-01-03 22:23 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-01-03 22:23 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll ==================== One Month Modified Files and Folders ======= 2014-02-02 14:05 - 2014-02-02 14:05 - 00006309 _____ () C:\Users\Erik\Desktop\FRST.txt 2014-02-02 14:05 - 2014-01-31 18:12 - 00000000 ____D () C:\FRST 2014-02-02 13:59 - 2014-02-02 13:59 - 00987425 _____ () C:\Users\Erik\Desktop\SecurityCheck.exe 2014-02-02 13:52 - 2013-12-31 13:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-02 10:46 - 2014-02-02 10:46 - 02347384 _____ (ESET) C:\Users\Erik\Downloads\esetsmartinstaller_enu.exe 2014-02-02 10:41 - 2013-12-31 08:54 - 00643628 _____ () C:\Windows\system32\perfh007.dat 2014-02-02 10:41 - 2013-12-31 08:54 - 00126188 _____ () C:\Windows\system32\perfc007.dat 2014-02-02 10:41 - 2009-07-14 06:13 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-02 10:40 - 2009-07-14 05:45 - 00026704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-02 10:40 - 2009-07-14 05:45 - 00026704 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-02 10:36 - 2013-12-31 01:29 - 01760338 _____ () C:\Windows\WindowsUpdate.log 2014-02-02 10:34 - 2013-12-31 19:10 - 00000000 ___RD () C:\Users\Erik\Dropbox 2014-02-02 10:34 - 2013-12-31 19:07 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Dropbox 2014-02-02 10:33 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-02 10:33 - 2009-07-14 05:51 - 00032089 _____ () C:\Windows\setupact.log 2014-02-01 21:57 - 2014-01-31 18:12 - 00059022 _____ () C:\Users\Erik\Downloads\FRST.txt 2014-02-01 21:56 - 2014-02-01 21:56 - 00000000 ____D () C:\Users\Erik\Downloads\FRST-OlderVersion 2014-02-01 21:56 - 2014-01-31 18:11 - 02080256 _____ (Farbar) C:\Users\Erik\Desktop\FRST64.exe 2014-02-01 21:55 - 2014-02-01 21:55 - 00000000 ____D () C:\Users\Erik\Desktop\alte log 2014-02-01 21:05 - 2014-02-01 21:05 - 00000897 _____ () C:\Users\Erik\Desktop\JRT.txt 2014-02-01 20:59 - 2014-02-01 20:59 - 01037068 _____ (Thisisu) C:\Users\Erik\Downloads\JRT.exe 2014-02-01 20:59 - 2014-02-01 20:59 - 00000000 ____D () C:\Windows\ERUNT 2014-02-01 20:55 - 2014-02-01 20:54 - 00000000 ____D () C:\AdwCleaner 2014-02-01 20:55 - 2014-01-22 08:35 - 00001087 _____ () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk 2014-02-01 20:55 - 2014-01-22 08:35 - 00001057 _____ () C:\Users\Erik\Desktop\Search.lnk 2014-02-01 20:53 - 2014-02-01 20:53 - 01166132 _____ () C:\Users\Erik\Desktop\adwcleaner.exe 2014-02-01 19:57 - 2010-11-21 04:47 - 00408880 _____ () C:\Windows\PFRO.log 2014-02-01 19:32 - 2014-02-01 19:32 - 00001117 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-01 19:32 - 2014-02-01 19:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-01 19:27 - 2014-02-01 19:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Erik\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-01 14:56 - 2014-02-01 14:56 - 00457160 _____ () C:\Windows\Minidump\020114-12448-01.dmp 2014-02-01 14:56 - 2014-01-17 08:33 - 309019056 _____ () C:\Windows\MEMORY.DMP 2014-02-01 14:56 - 2014-01-17 08:33 - 00000000 ____D () C:\Windows\Minidump 2014-02-01 12:54 - 2014-02-01 12:54 - 00000000 ___SD () C:\ComboFix 2014-02-01 12:53 - 2014-01-31 22:53 - 05179159 ____R (Swearware) C:\Users\Erik\Desktop\ComboFix.exe 2014-01-31 22:59 - 2014-01-31 22:59 - 00000000 ____D () C:\Qoobox 2014-01-31 22:58 - 2014-01-31 22:58 - 00000000 ____D () C:\Windows\erdnt 2014-01-31 20:34 - 2014-01-31 19:09 - 00000000 ____D () C:\ProgramData\Package Cache 2014-01-31 20:08 - 2014-01-31 19:09 - 00000000 ____D () C:\4673be0d0d73ae9aad34c6c970896e 2014-01-31 19:27 - 2014-01-26 14:25 - 00007601 _____ () C:\Users\Erik\AppData\Local\Resmon.ResmonCfg 2014-01-31 18:36 - 2014-01-31 18:36 - 00013824 _____ () C:\Users\Erik\Desktop\gmer absturz.odt 2014-01-31 18:18 - 2014-01-31 18:18 - 00380416 _____ () C:\Users\Erik\Downloads\1ntqbv44.exe 2014-01-31 18:13 - 2014-01-31 18:13 - 00020023 _____ () C:\Users\Erik\Downloads\Addition.txt 2014-01-31 18:09 - 2014-01-31 18:09 - 00000000 _____ () C:\Users\Erik\defogger_reenable 2014-01-31 18:09 - 2013-12-31 01:30 - 00000000 ____D () C:\Users\Erik 2014-01-31 18:07 - 2014-01-31 18:07 - 00050477 _____ () C:\Users\Erik\Downloads\Defogger.exe 2014-01-31 17:47 - 2014-01-26 15:14 - 00000000 ____D () C:\ProgramData\SecTaskMan 2014-01-31 17:46 - 2014-01-22 08:33 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\DVDVideoSoft 2014-01-31 17:45 - 2014-01-31 17:45 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-01-31 17:27 - 2014-01-31 17:06 - 00000662 __RSH () C:\Users\Erik\ntuser.pol 2014-01-31 16:36 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-01-31 16:01 - 2014-01-31 16:01 - 00000000 ____D () C:\Users\Erik\Documents\ProcessExplorer 2014-01-31 11:34 - 2014-01-31 11:33 - 00000000 ____D () C:\Users\Erik\Documents\1und1 2014-01-30 14:35 - 2014-01-30 14:34 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-27 06:26 - 2014-01-27 06:26 - 01095405 _____ () C:\Users\Erik\Desktop\Antrag Fondbanking.pdf.jpeg 2014-01-26 15:12 - 2014-01-26 15:12 - 02365840 _____ () C:\Users\Erik\Downloads\SecurityTaskManager_Setup.exe 2014-01-26 12:12 - 2014-01-26 12:12 - 00276680 _____ () C:\Windows\Minidump\012614-18704-01.dmp 2014-01-26 12:00 - 2013-12-31 16:23 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\vlc 2014-01-26 11:52 - 2014-01-26 11:52 - 00000000 ____D () C:\Users\Erik\Documents\BOB BSAG 2014-01-23 06:07 - 2014-01-22 08:36 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-01-22 08:57 - 2013-12-31 01:30 - 00000000 ____D () C:\Users\Erik\AppData\Local\VirtualStore 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-01-22 08:36 - 2014-01-22 08:36 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\TuneUp Software 2014-01-22 08:29 - 2014-01-22 08:29 - 33000776 _____ (DVDVideoSoft Ltd. ) C:\Users\Erik\Downloads\FreeAudioConverter5.0.32.1230.exe 2014-01-20 17:47 - 2013-12-31 12:25 - 00000000 ____D () C:\Users\Public\Documents\Schule 2014-01-20 14:39 - 2014-01-05 11:54 - 00917504 _____ () C:\Users\Erik\Desktop\FLD_Pasemann_Erik_Pa_01_13_14_0445.mFN 2014-01-17 15:46 - 2014-01-17 15:46 - 00276680 _____ () C:\Windows\Minidump\011714-19827-01.dmp 2014-01-17 08:39 - 2013-12-31 19:10 - 00000984 _____ () C:\Users\Erik\Desktop\Dropbox.lnk 2014-01-17 08:39 - 2013-12-31 19:08 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-17 08:39 - 2013-12-31 01:30 - 00000000 ___RD () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-17 08:33 - 2014-01-17 08:33 - 00276680 _____ () C:\Windows\Minidump\011714-19858-01.dmp 2014-01-17 07:45 - 2014-01-17 07:45 - 02903369 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling & Die Gesellschaft - La La La Langweilig.mp4 2014-01-17 07:44 - 2014-01-17 07:44 - 10430499 _____ () C:\Users\Erik\Desktop\Marc-Uwe Kling - Wer hat uns verraten.mp4 2014-01-17 07:43 - 2014-01-17 07:43 - 16439242 _____ () C:\Users\Erik\Desktop\K.I.Z. - Raus aus dem Amt.mp4 2014-01-17 07:41 - 2014-01-17 07:40 - 04188816 _____ () C:\Users\Erik\Desktop\NMZS - 99 Leben.mp4 2014-01-17 07:40 - 2014-01-17 07:40 - 09035081 _____ () C:\Users\Erik\Desktop\Antilopen Gang - Leben und Streben des Friedrich Kautz.mp4 2014-01-17 07:39 - 2014-01-17 07:39 - 14068043 _____ () C:\Users\Erik\Desktop\Benjamin Blümchen auf dem Baum.mp4 2014-01-17 07:37 - 2014-01-17 07:26 - 420000818 _____ () C:\Users\Erik\Desktop\HINTERLAND FULL ALBUM - CASPER [HD].mp4 2014-01-16 21:29 - 2014-01-16 20:22 - 2147483648 _____ () C:\Users\Erik\Downloads\erik.tc 2014-01-16 19:35 - 2014-01-16 19:34 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-16 19:35 - 2013-12-31 14:37 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-16 19:35 - 2013-12-31 14:37 - 00000000 ____D () C:\Program Files (x86)\Java 2014-01-16 06:10 - 2014-01-08 08:16 - 00000000 ____D () C:\Users\Erik\dwhelper 2014-01-16 06:08 - 2014-01-16 06:03 - 211344833 _____ () C:\Users\Erik\Desktop\Planet Wissen Zivilcourage.webm 2014-01-16 03:17 - 2009-07-14 05:45 - 00328464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-12 15:54 - 2013-12-31 13:26 - 00000000 ____D () C:\Users\Public\Documents\Finanzen 2014-01-12 14:31 - 2014-01-12 14:21 - 421347611 _____ () C:\Users\Erik\Downloads\Die_Germanen3-Die_Varusschlacht.mp4 2014-01-11 13:02 - 2014-01-11 13:02 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Digitale.Schulbucher 2014-01-11 13:01 - 2013-12-31 01:40 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-01-11 13:00 - 2014-01-11 13:00 - 00001904 _____ () C:\Users\Public\Desktop\Digitale Schulbücher.lnk 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\YDP 2014-01-11 13:00 - 2014-01-11 13:00 - 00000000 ____D () C:\Program Files (x86)\Digitale Schulbücher 2014-01-11 12:59 - 2014-01-11 12:59 - 00000000 ____D () C:\Users\Erik\Documents\DigitaleSchulbuecher_WIN_200_b83 2014-01-08 08:26 - 2014-01-08 08:26 - 00000000 ____D () C:\Users\Erik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup 2014-01-08 08:19 - 2014-01-08 08:16 - 76270230 _____ () C:\Users\Erik\Desktop\Unsere Erde.mp4 2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr 2014-01-06 16:20 - 2014-01-30 14:34 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-05 21:10 - 2014-01-05 21:10 - 09544168 _____ (Senatorin für Bildung in Bremen/Germany ) C:\Users\Erik\Downloads\setup_myFuNe_2.exe 2014-01-05 21:10 - 2014-01-05 21:10 - 00000000 ____D () C:\Program Files (x86)\myFuNe 2014-01-05 19:39 - 2014-01-05 19:39 - 00002140 _____ () C:\Users\Erik\Desktop\Schule - Verknüpfung.lnk 2014-01-05 16:06 - 2014-01-05 15:33 - 1368683531 _____ () C:\Users\Erik\Downloads\Römer - b.richter@lehrer4u.zip 2014-01-03 10:35 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache Some content of TEMP: ==================== C:\Users\Erik\AppData\Local\Temp\avgnt.exe C:\Users\Erik\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Erik\AppData\Local\Temp\Offercast_AVIRAV7_.exe C:\Users\Erik\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Erik\AppData\Local\Temp\Quarantine.exe C:\Users\Erik\AppData\Local\Temp\Setup64.exe C:\Users\Erik\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-29 08:54 ==================== End Of Log ============================ --- --- --- |
02.02.2014, 14:24 | #8 |
| Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher Hallo, also obwohl einiges an malware gefunden und entfernt wurde(vielen Dank!), besteht mein Problem leider immer noch. Im Anhang füge ich noch mal nen aktuellen screenshot vom Process Explorer bei. Habe ich 4-5 min nach dem Hochfahren gemacht. |
03.02.2014, 13:21 | #9 |
/// the machine /// TB-Ausbilder | Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.02.2014, 15:33 | #10 |
| Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher Clean boot durchgeführt. Das Problem besteht leider immernoch.. So ne Kacke. Komm ich um eine Neuinstallation wohl nich drum herum oder hast du noch Ideen? |
04.02.2014, 10:50 | #11 |
/// the machine /// TB-Ausbilder | Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher Dann ist es ein Windows Dienst, die würd ich jetzt auch mal einzeln abschalten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: ddlhost.exe zieht gesamten Arbeitsspeicher |
administrator, adobe, antivir, antivirus, avira, browser, computer, defender, desktop, explorer, firefox, flash player, helper, homepage, mozilla, opera, problem, registry, security, smartbar, software, system, task-manager, temp, trojaner, windows, yahoo community smartbar |