|
Plagegeister aller Art und deren Bekämpfung: DHCP Dienst lässt sich nicht startenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.02.2014, 16:40 | #16 |
/// the machine /// TB-Ausbilder | DHCP Dienst lässt sich nicht starten Combofix löschen, neu laden und auf dem DEsktop speichern.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.02.2014, 21:17 | #17 |
| DHCP Dienst lässt sich nicht startenCode:
ATTFilter ComboFix 14-02-19.01 - Administrator 19.02.2014 21:11:32.1.4 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.2047.1003 [GMT 1:00] ausgeführt von:: c:\users\Administrator\Desktop\ComboFixsaddsa.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END c:\programdata\184185822.exe c:\programdata\184185822.vbs C:\System c:\users\Administrator\AppData\Roaming\12e95.exe c:\users\Administrator\AppData\Roaming\174ee.exe c:\users\Administrator\AppData\Roaming\194d5.exe c:\users\Administrator\AppData\Roaming\1a582.exe c:\users\Administrator\AppData\Roaming\21f60.exe c:\users\Administrator\AppData\Roaming\29137.exe c:\users\Administrator\AppData\Roaming\2ea50.exe c:\users\Administrator\AppData\Roaming\42d89.exe c:\users\Administrator\AppData\Roaming\4f91f.exe c:\users\Administrator\AppData\Roaming\521c6.exe c:\users\Administrator\AppData\Roaming\55aad.exe c:\users\Administrator\AppData\Roaming\59611.exe c:\users\Administrator\AppData\Roaming\637dc.exe c:\users\Administrator\AppData\Roaming\6936f.exe c:\users\Administrator\AppData\Roaming\6bb9b.exe c:\users\Administrator\AppData\Roaming\6cbab.exe c:\users\Administrator\AppData\Roaming\6e6d7.exe c:\users\Administrator\AppData\Roaming\70c8e.exe c:\users\Administrator\AppData\Roaming\73f3f.exe c:\users\Administrator\AppData\Roaming\75349.exe c:\users\Administrator\AppData\Roaming\83d00.exe c:\users\Administrator\AppData\Roaming\865ed.exe c:\users\Administrator\AppData\Roaming\8ab58.exe c:\users\Administrator\AppData\Roaming\8b1b9.exe c:\users\Administrator\AppData\Roaming\904c4.exe c:\users\Administrator\AppData\Roaming\93316.exe c:\users\Administrator\AppData\Roaming\94f7d.exe c:\users\Administrator\AppData\Roaming\96055.exe c:\users\Administrator\AppData\Roaming\987b6.exe c:\users\Administrator\AppData\Roaming\9a557.exe c:\users\Administrator\AppData\Roaming\9b8d6.exe c:\users\Administrator\AppData\Roaming\ab24c.exe c:\users\Administrator\AppData\Roaming\ac248.exe c:\users\Administrator\AppData\Roaming\b43a8.exe c:\users\Administrator\AppData\Roaming\c8c52.exe c:\users\Administrator\AppData\Roaming\cbdfd.exe c:\users\Administrator\AppData\Roaming\cf101.exe c:\users\Administrator\AppData\Roaming\d6056.exe c:\users\Administrator\AppData\Roaming\db8f4.exe c:\users\Administrator\AppData\Roaming\de54d.exe c:\users\Administrator\AppData\Roaming\f3e73.exe c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google.com.url c:\users\Administrator\AppData\Roaming\msconfig.ini . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-19 bis 2014-02-19 )))))))))))))))))))))))))))))) . . 2014-02-19 20:16 . 2014-02-19 20:16 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-02-17 02:30 . 2014-02-17 02:30 -------- d-----w- c:\program files\AC3Filter 2014-02-17 02:30 . 2013-04-05 20:26 1679360 ----a-w- c:\windows\system32\ac3filter.acm 2014-02-17 02:28 . 2014-02-17 02:28 -------- d-----w- c:\program files\Common Files\DivX Shared 2014-02-17 02:27 . 2014-02-17 02:28 -------- d-----w- c:\program files\DivX 2014-02-17 02:27 . 2014-02-17 02:28 -------- d-----w- c:\programdata\DivX 2014-02-17 01:46 . 2014-02-17 16:34 -------- d-----w- c:\programdata\Creative 2014-02-17 01:18 . 2003-06-12 22:25 7062 ----a-w- c:\windows\system32\audiopid.vxd 2014-02-17 01:18 . 2014-02-17 01:18 -------- d-----w- c:\program files\Common Files\Creative Labs Shared 2014-02-17 01:17 . 2009-02-17 16:33 106496 ----a-w- c:\windows\system32\cttele32.dll 2014-02-17 01:17 . 2014-02-17 01:17 445016 ----a-w- c:\windows\system32\wrap_oal.dll 2014-02-17 01:17 . 2014-02-17 01:17 109144 ----a-w- c:\windows\system32\OpenAL32.dll 2014-02-17 01:17 . 2014-02-17 01:17 -------- d-----w- c:\program files\OpenAL 2014-02-17 01:17 . 2009-06-29 09:54 164864 ----a-w- c:\windows\system32\APOMngr.DLL 2014-02-17 01:17 . 2009-02-06 17:52 73728 ----a-w- c:\windows\system32\CmdRtr.DLL 2014-02-17 01:16 . 2014-02-17 01:17 -------- d-----w- c:\windows\system32\Data 2014-02-17 01:16 . 2007-09-13 17:05 2560 ----a-w- c:\windows\CTXFIGER.DLL 2014-02-17 01:16 . 2004-07-30 13:46 20480 ----a-w- c:\windows\INRESGER.DLL 2014-02-17 01:16 . 2014-02-17 01:18 -------- d-----w- c:\program files\Creative 2014-02-17 01:16 . 2014-02-17 01:16 -------- d-----w- c:\program files\Common Files\InstallShield 2014-02-17 01:08 . 2014-02-19 02:14 -------- d-----w- c:\program files\Mozilla Maintenance Service 2014-02-16 23:35 . 2014-02-16 23:38 -------- d-----w- c:\programdata\NVIDIA 2014-02-15 19:34 . 2014-02-15 19:34 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-02-15 19:34 . 2014-02-15 19:34 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-02-15 19:34 . 2014-02-15 19:34 -------- d-----w- c:\windows\system32\Macromed 2014-02-15 18:54 . 2014-02-15 18:54 -------- d-----w- c:\program files\AGEIA Technologies 2014-02-15 18:53 . 2013-12-19 18:37 4317984 ----a-w- c:\windows\system32\nvcpl.dll 2014-02-15 18:53 . 2013-12-19 18:37 3036960 ----a-w- c:\windows\system32\nvsvc.dll 2014-02-15 18:53 . 2013-12-19 18:37 664352 ----a-w- c:\windows\system32\nvvsvc.exe 2014-02-15 18:53 . 2013-12-19 18:37 62752 ----a-w- c:\windows\system32\nvshext.dll 2014-02-15 18:53 . 2013-12-19 18:37 2555168 ----a-w- c:\windows\system32\nvsvcr.dll 2014-02-15 18:53 . 2013-12-19 18:37 376096 ----a-w- c:\windows\system32\nvmctray.dll 2014-02-15 18:53 . 2013-12-19 03:39 3539040 ----a-w- c:\windows\system32\nvcoproc.bin 2014-02-15 18:53 . 2013-12-19 20:26 53024 ----a-w- c:\windows\system32\OpenCL.dll 2014-02-15 18:53 . 2014-02-15 18:57 -------- d-----w- c:\programdata\NVIDIA Corporation 2014-02-15 18:48 . 2014-02-15 18:48 -------- d-----w- c:\program files\Microsoft.NET 2014-02-15 18:48 . 2014-02-17 02:28 -------- d-sh--w- c:\windows\Installer 2014-02-15 18:46 . 2013-12-19 20:26 9700224 ----a-w- c:\windows\system32\nvcuda.dll 2014-02-15 18:46 . 2013-12-19 20:26 2698272 ----a-w- c:\windows\system32\nvapi.dll 2014-02-15 18:46 . 2013-12-19 20:26 17560352 ----a-w- c:\windows\system32\nvcompiler.dll 2014-02-15 18:46 . 2014-02-15 18:54 -------- d-----w- c:\program files\NVIDIA Corporation 2014-02-15 18:45 . 2014-02-15 18:45 -------- d-----w- C:\NVIDIA 2014-02-15 18:43 . 2014-02-19 20:07 -------- d-----w- C:\{$4212-2194-8701-4316$} 2014-02-15 18:25 . 2013-12-16 00:54 7760024 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A88A16BC-BD61-4C15-8818-CC6908E642B5}\mpengine.dll 2014-02-15 18:25 . 2013-12-18 05:13 231584 ------w- c:\windows\system32\MpSigStub.exe 2014-02-15 18:22 . 2014-02-17 00:01 -------- d-----w- c:\users\Administrator 2014-02-15 18:16 . 2014-02-17 01:18 -------- d--h--w- c:\program files\InstallShield Installation Information 2014-02-15 18:16 . 2011-04-20 02:06 1570304 ----a-w- c:\windows\system32\drivers\athur.sys 2014-02-15 18:16 . 2011-04-20 02:06 1570304 ----a-w- c:\windows\system32\athur.sys 2014-02-15 18:15 . 2014-02-15 18:15 -------- d-----w- c:\programdata\TP-LINK 2014-02-15 17:51 . 2014-02-15 18:07 -------- d-----w- c:\windows\Panther 2014-02-15 17:41 . 2014-02-15 17:41 -------- d-----w- C:\Windows.old 2014-02-11 17:25 . 2014-02-11 17:25 -------- d-----w- C:\RegBackup 2014-02-09 17:36 . 2014-02-17 00:04 -------- d-----w- C:\FRST . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-12-18 06:11 . 2013-12-18 06:11 354656 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTxfiHlp"="CTXFIHLP.EXE" [2012-12-18 24576] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-11-15 1861968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer7"=wdmaud.drv . R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-02-17 79360] R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2012-12-18 200624] R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2012-12-18 1355696] R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2012-12-18 76208] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848] S3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athur.sys [2011-04-20 1570304] S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2012-12-18 200624] S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2012-12-18 1355696] S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2012-12-18 76208] S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2012-12-18 1233328] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080] S3 yukonw7;NDIS6.2-Miniporttreiber für Marvell Yukon-Ethernet-Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296] . . Inhalt des "geplante Tasks" Ordners . 2014-02-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-15 19:34] . . ------- Zusätzlicher Suchlauf ------- . TCP: DhcpNameServer = 192.168.1.1 193.189.244.202 193.189.244.194 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM-Run-Windows COM Host - c:\programdata\184185822.exe MSConfigStartUp-Windows COM Host - c:\programdata\184185822.exe AddRemove-DivX Setup - c:\programdata\DivX\Setup\DivXSetup.exe AddRemove-uTorrent - c:\users\Administrator\AppData\Roaming\uTorrent\uTorrent.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (Administrator) "Progid"="ThunderbirdEML" . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdseml\UserChoice] @Denied: (2) (Administrator) "Progid"="ThunderbirdEML" . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" . [HKEY_USERS\S-1-5-21-3550051241-3284215751-1626915073-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-02-19 21:18:30 ComboFix-quarantined-files.txt 2014-02-19 20:18 . Vor Suchlauf: 14 Verzeichnis(se), 19.547.721.728 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 29.492.854.784 Bytes frei . - - End Of File - - A8AF80051D40168244D2EFC51164F60D A36C5E4F47E84449FF07ED3517B43A31 |
20.02.2014, 14:34 | #18 |
/// the machine /// TB-Ausbilder | DHCP Dienst lässt sich nicht starten Downloade Dir bitte Malwarebytes Anti-Malware
__________________
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
21.02.2014, 09:40 | #19 |
| DHCP Dienst lässt sich nicht starten Guten Morgen, habe alles getan wie beschrieben. Hier die Logs: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.21.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 Administrator :: PC [Administrator] 21.02.2014 09:16:25 mbam-log-2014-02-21 (09-16-25).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 226531 Laufzeit: 5 Minute(n), 49 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.019 - Bericht erstellt am 21/02/2014 um 09:29:46 # Aktualisiert 17/02/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzername : Administrator - PC # Gestartet von : C:\Users\Administrator\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Administrator\AppData\LocalLow\boost_interprocess ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7601.17514 -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\ich\AppData\Roaming\Mozilla\Firefox\Profiles\8n5ywoeg.default\prefs.js ] [ Datei : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1123 octets] - [21/02/2014 09:28:51] AdwCleaner[S0].txt - [1047 octets] - [21/02/2014 09:29:46] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1107 octets] ########## JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.2 (02.20.2014:1) OS: Windows 7 Professional x86 Ran by Administrator on 21.02.2014 at 9:36:15,56 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.02.2014 at 9:37:33,64 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-02-2014 Ran by Administrator (administrator) on PC on 21-02-2014 09:40:02 Running from C:\Users\Administrator\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Creative Technology Ltd) C:\Windows\System32\Ctxfihlp.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Creative Technology Ltd) C:\Windows\SYSTEM32\CTXFISPI.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CTxfiHlp] - C:\Windows\system32\CTXFIHLP.EXE [24576 2012-12-18] (Creative Technology Ltd) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-15] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 193.189.244.202 193.189.244.194 FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Extension: FireShot - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2014-02-15] FF Extension: ProxTube - Unblock YouTube - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2014-02-15] FF Extension: Reddit Enhancement Suite - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi [2014-02-15] FF Extension: Adblock Plus - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-15] FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe ========================== Services (Whitelisted) ================= R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation) ==================== Drivers (Whitelisted) ==================== R3 athur; C:\Windows\System32\DRIVERS\athur.sys [1570304 2011-04-20] (Atheros Communications, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation) S3 catchme; \??\C:\Users\ADMINI~1\AppData\Local\Temp\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-21 09:40 - 2014-02-21 09:40 - 00004912 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-02-21 09:39 - 2014-02-21 09:39 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-02-21 09:37 - 2014-02-21 09:37 - 00000656 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-02-21 09:34 - 2014-02-21 09:34 - 00000000 ____D () C:\Windows\ERUNT 2014-02-21 09:33 - 2014-02-21 09:33 - 01037734 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-02-21 09:31 - 2014-02-21 09:31 - 00001187 _____ () C:\Users\Administrator\Desktop\adw.txt 2014-02-21 09:28 - 2014-02-21 09:29 - 00000000 ____D () C:\AdwCleaner 2014-02-21 09:27 - 2014-02-21 09:27 - 01241834 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-02-21 09:26 - 2014-02-21 09:26 - 00001062 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-02-21 09:14 - 2014-02-21 09:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-21 09:13 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-20 06:45 - 2014-02-20 06:45 - 00001300 _____ () C:\Users\Administrator\Desktop\foobar2000 - Verknüpfung.lnk 2014-02-20 06:35 - 2014-02-20 06:35 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\OpenOffice 2014-02-20 06:34 - 2014-02-20 06:34 - 00000000 ____D () C:\Program Files\OpenOffice 4 2014-02-20 06:28 - 2014-02-20 06:31 - 163606685 _____ () C:\Users\Administrator\Desktop\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFixsaddsa.exe 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 _____ (Swearware) C:\Users\Administrator\Desktop\ComboFix(2).exe 2014-02-19 21:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-19 21:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-19 21:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-19 21:08 - 2014-02-21 09:26 - 00000000 ____D () C:\Qoobox 2014-02-19 21:08 - 2014-02-19 21:17 - 00000000 ____D () C:\Windows\erdnt 2014-02-19 21:07 - 2014-02-19 21:08 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\NVIDIA 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-02-19 10:13 - 2014-02-19 12:33 - 00000000 ____D () C:\Users\Administrator\Downloads\John Carter (2012) [1080p] [3D] [HSBS] 2014-02-19 10:11 - 2014-02-19 11:48 - 00000000 ____D () C:\Users\Administrator\Downloads\Green Lantern (2011) [3D] [1080p] 2014-02-19 10:07 - 2014-02-19 12:48 - 00000000 ____D () C:\Users\Administrator\Downloads\Life of Pi (2012) [3D] [HSBS] 2014-02-19 10:06 - 2014-02-19 11:56 - 00000000 ____D () C:\Users\Administrator\Downloads\Dredd (2012) [3D] [HSBS] 2014-02-19 10:05 - 2014-02-19 10:36 - 00000000 ____D () C:\Users\Administrator\Downloads\The Green Hornet 3D (2011) [1080p] [3D] [HSBS] 2014-02-19 10:03 - 2014-02-19 15:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent 2014-02-19 10:02 - 2014-02-19 10:02 - 01520208 _____ (BitTorrent Inc.) C:\Users\Administrator\Desktop\uTorrent.exe 2014-02-18 02:34 - 2014-02-18 03:38 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm 2014-02-18 02:34 - 2014-02-18 03:38 - 00001080 _____ () C:\Windows\system32\settings.sfm 2014-02-17 18:26 - 2014-02-17 18:26 - 193831120 _____ () C:\Windows\MEMORY.DMP 2014-02-17 18:26 - 2014-02-17 18:26 - 00157584 _____ () C:\Windows\Minidump\021714-24757-01.dmp 2014-02-17 18:26 - 2014-02-17 18:26 - 00000000 ____D () C:\Windows\Minidump 2014-02-17 03:31 - 2014-02-17 03:31 - 00000000 ____D () C:\Users\Administrator\AppData\Local\DDMSettings 2014-02-17 03:30 - 2014-02-17 03:30 - 00000000 ____D () C:\Program Files\AC3Filter 2014-02-17 03:30 - 2013-04-05 21:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm 2014-02-17 03:28 - 2014-02-17 03:28 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-02-17 03:27 - 2014-02-17 03:28 - 00000000 ____D () C:\ProgramData\DivX 2014-02-17 03:27 - 2014-02-17 03:28 - 00000000 ____D () C:\Program Files\DivX 2014-02-17 02:46 - 2014-02-17 17:34 - 00000000 ____D () C:\ProgramData\Creative 2014-02-17 02:18 - 2014-02-17 02:18 - 00000000 ____D () C:\Program Files\Common Files\Creative Labs Shared 2014-02-17 02:18 - 2003-06-12 23:25 - 00007062 _____ () C:\Windows\system32\audiopid.vxd 2014-02-17 02:17 - 2014-02-17 02:17 - 00445016 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00000087 ___RH () C:\Windows\ctfile.rfc 2014-02-17 02:17 - 2014-02-17 02:17 - 00000000 ____D () C:\Program Files\OpenAL 2014-02-17 02:17 - 2009-06-29 10:54 - 00164864 _____ () C:\Windows\system32\APOMngr.DLL 2014-02-17 02:17 - 2009-02-17 17:33 - 00106496 _____ (Creative Technology Ltd) C:\Windows\system32\cttele32.dll 2014-02-17 02:17 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\system32\CmdRtr.DLL 2014-02-17 02:16 - 2014-02-17 02:18 - 00000000 ____D () C:\Program Files\Creative 2014-02-17 02:16 - 2014-02-17 02:17 - 00000000 ____D () C:\Windows\system32\Data 2014-02-17 02:16 - 2014-02-17 02:16 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-02-17 02:16 - 2007-09-13 18:05 - 00002560 _____ () C:\Windows\CTXFIGER.DLL 2014-02-17 02:16 - 2004-07-30 14:46 - 00020480 _____ (Creative Technology Limited) C:\Windows\INRESGER.DLL 2014-02-17 02:08 - 2014-02-20 05:20 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-17 02:08 - 2014-02-17 02:08 - 00000000 ____D () C:\ProgramData\Mozilla 2014-02-17 01:01 - 2014-02-17 01:01 - 00380416 _____ () C:\Users\Administrator\Desktop\Gmer-19357.exe 2014-02-17 01:01 - 2014-02-17 01:01 - 00000000 _____ () C:\Users\Administrator\defogger_reenable 2014-02-17 01:00 - 2014-02-21 09:39 - 01142784 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2014-02-17 01:00 - 2014-02-17 01:00 - 00050477 _____ () C:\Users\Administrator\Desktop\Defogger.exe 2014-02-17 00:39 - 2014-02-17 00:39 - 00000000 ____D () C:\Windows\pss 2014-02-17 00:36 - 2014-02-19 03:15 - 00057560 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-17 00:35 - 2014-02-17 00:38 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Macromedia 2014-02-15 20:34 - 2014-02-16 08:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-15 20:34 - 2014-02-15 20:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-15 20:34 - 2014-02-15 20:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-15 20:34 - 2014-02-15 20:34 - 00000000 ____D () C:\Windows\system32\Macromed 2014-02-15 20:05 - 2014-02-20 08:34 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\foobar2000 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Thunderbird 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Media Player Classic 2014-02-15 20:03 - 2014-02-15 21:46 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Thunderbird 2014-02-15 20:03 - 2014-02-15 20:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\altThunderbird 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Program Files\AGEIA Technologies 2014-02-15 19:53 - 2014-02-15 19:57 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-15 19:53 - 2013-12-19 21:26 - 00053024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 04317984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 03036960 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 02555168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 00664352 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-15 19:53 - 2013-12-19 19:37 - 00376096 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 00062752 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-15 19:53 - 2013-12-19 04:39 - 03539040 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-15 19:48 - 2014-02-15 19:48 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-02-15 19:47 - 2013-12-19 21:26 - 22960416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 15877216 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 15230352 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 10471712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-15 19:47 - 2013-12-19 21:26 - 09657464 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 02947872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 02747680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 01242400 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233221.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233221.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00852768 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00847648 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00266984 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00141336 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00018439 _____ () C:\Windows\system32\nvinfo.pb 2014-02-15 19:47 - 2013-12-05 09:42 - 00034080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys 2014-02-15 19:47 - 2013-12-05 09:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll 2014-02-15 19:46 - 2014-02-15 19:54 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-15 19:46 - 2013-12-19 21:26 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-15 19:46 - 2013-12-19 21:26 - 09700224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-15 19:46 - 2013-12-19 21:26 - 02698272 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2014-02-15 19:45 - 2014-02-15 19:45 - 00000000 ____D () C:\NVIDIA 2014-02-15 19:43 - 2014-02-15 19:43 - 00000000 ____D () C:\Users\Administrator\Desktop\Windows_Loader_v2.2.1 2014-02-15 19:25 - 2013-12-18 06:13 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-02-15 19:23 - 2014-02-15 19:51 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-02-15 19:23 - 2014-02-15 19:23 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-02-15 19:22 - 2014-02-17 01:01 - 00000000 ____D () C:\Users\Administrator 2014-02-15 19:22 - 2014-02-15 19:22 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-15 19:22 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-15 19:22 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-15 19:18 - 2014-02-15 19:18 - 00001326 _____ () C:\Users\ich\Desktop\firefox - Verknüpfung.lnk 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Roaming\Mozilla 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Local\Mozilla 2014-02-15 19:16 - 2014-02-17 02:18 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-02-15 19:16 - 2011-05-03 22:13 - 00008816 _____ () C:\Windows\system32\athurext.cat 2014-02-15 19:16 - 2011-04-20 03:06 - 01570304 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athur.sys 2014-02-15 19:16 - 2011-04-20 03:06 - 01570304 _____ (Atheros Communications, Inc.) C:\Windows\system32\athur.sys 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\Users\ich\Desktop\TL-WN722N_V1_Driver 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-02-15 19:11 - 2014-02-15 19:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-02-15 19:08 - 2014-02-15 19:08 - 00001432 _____ () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-15 19:07 - 2014-02-15 19:08 - 00000000 ____D () C:\Users\ich 2014-02-15 19:07 - 2014-02-15 19:07 - 00000020 ___SH () C:\Users\ich\ntuser.ini 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 ____D () C:\Users\ich\AppData\Local\VirtualStore 2014-02-15 19:07 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-15 19:07 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-15 18:56 - 2014-02-21 09:34 - 00071882 _____ () C:\Windows\WindowsUpdate.log 2014-02-15 18:55 - 2014-02-15 18:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-02-15 18:54 - 2014-02-15 18:57 - 00001355 _____ () C:\Windows\TSSysprep.log 2014-02-15 18:51 - 2014-02-15 19:07 - 00000000 ____D () C:\Windows\Panther 2014-02-15 18:41 - 2014-02-15 18:41 - 00000000 ____D () C:\Windows.old 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 ____D () C:\RegBackup 2014-02-11 18:08 - 2014-02-11 18:08 - 00003288 ____N () C:\bootsqm.dat 2014-02-09 18:36 - 2014-02-21 09:40 - 00000000 ____D () C:\FRST ==================== One Month Modified Files and Folders ======= 2014-02-21 09:40 - 2014-02-21 09:40 - 00004912 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-02-21 09:40 - 2014-02-09 18:36 - 00000000 ____D () C:\FRST 2014-02-21 09:39 - 2014-02-21 09:39 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-02-21 09:39 - 2014-02-17 01:00 - 01142784 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2014-02-21 09:39 - 2014-02-15 18:56 - 00071882 _____ () C:\Windows\WindowsUpdate.log 2014-02-21 09:37 - 2014-02-21 09:37 - 00000656 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-02-21 09:36 - 2009-07-14 05:39 - 00026408 _____ () C:\Windows\setupact.log 2014-02-21 09:34 - 2014-02-21 09:34 - 00000000 ____D () C:\Windows\ERUNT 2014-02-21 09:34 - 2009-07-14 05:34 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-21 09:34 - 2009-07-14 05:34 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-21 09:33 - 2014-02-21 09:33 - 01037734 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-02-21 09:31 - 2014-02-21 09:31 - 00001187 _____ () C:\Users\Administrator\Desktop\adw.txt 2014-02-21 09:29 - 2014-02-21 09:28 - 00000000 ____D () C:\AdwCleaner 2014-02-21 09:27 - 2014-02-21 09:27 - 01241834 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-02-21 09:26 - 2014-02-21 09:26 - 00001062 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-02-21 09:26 - 2014-02-19 21:08 - 00000000 ____D () C:\Qoobox 2014-02-21 09:14 - 2014-02-21 09:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-21 07:00 - 2010-11-20 22:01 - 01611160 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-20 13:08 - 2009-07-14 05:33 - 00296920 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-20 08:34 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\foobar2000 2014-02-20 06:45 - 2014-02-20 06:45 - 00001300 _____ () C:\Users\Administrator\Desktop\foobar2000 - Verknüpfung.lnk 2014-02-20 06:35 - 2014-02-20 06:35 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\OpenOffice 2014-02-20 06:34 - 2014-02-20 06:34 - 00000000 ____D () C:\Program Files\OpenOffice 4 2014-02-20 06:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-02-20 06:31 - 2014-02-20 06:28 - 163606685 _____ () C:\Users\Administrator\Desktop\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2014-02-20 05:20 - 2014-02-17 02:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-20 05:20 - 2010-11-20 22:48 - 00006780 _____ () C:\Windows\PFRO.log 2014-02-19 21:18 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default 2014-02-19 21:18 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-02-19 21:17 - 2014-02-19 21:08 - 00000000 ____D () C:\Windows\erdnt 2014-02-19 21:17 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFixsaddsa.exe 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 _____ (Swearware) C:\Users\Administrator\Desktop\ComboFix(2).exe 2014-02-19 21:08 - 2014-02-19 21:07 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\NVIDIA 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-02-19 15:57 - 2014-02-19 10:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent 2014-02-19 12:48 - 2014-02-19 10:07 - 00000000 ____D () C:\Users\Administrator\Downloads\Life of Pi (2012) [3D] [HSBS] 2014-02-19 12:33 - 2014-02-19 10:13 - 00000000 ____D () C:\Users\Administrator\Downloads\John Carter (2012) [1080p] [3D] [HSBS] 2014-02-19 11:56 - 2014-02-19 10:06 - 00000000 ____D () C:\Users\Administrator\Downloads\Dredd (2012) [3D] [HSBS] 2014-02-19 11:48 - 2014-02-19 10:11 - 00000000 ____D () C:\Users\Administrator\Downloads\Green Lantern (2011) [3D] [1080p] 2014-02-19 10:36 - 2014-02-19 10:05 - 00000000 ____D () C:\Users\Administrator\Downloads\The Green Hornet 3D (2011) [1080p] [3D] [HSBS] 2014-02-19 10:02 - 2014-02-19 10:02 - 01520208 _____ (BitTorrent Inc.) C:\Users\Administrator\Desktop\uTorrent.exe 2014-02-19 03:15 - 2014-02-17 00:36 - 00057560 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-19 03:14 - 2009-07-14 04:20 - 00000000 ___RD () C:\Program Files (x86) 2014-02-18 03:38 - 2014-02-18 02:34 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm 2014-02-18 03:38 - 2014-02-18 02:34 - 00001080 _____ () C:\Windows\system32\settings.sfm 2014-02-17 18:26 - 2014-02-17 18:26 - 193831120 _____ () C:\Windows\MEMORY.DMP 2014-02-17 18:26 - 2014-02-17 18:26 - 00157584 _____ () C:\Windows\Minidump\021714-24757-01.dmp 2014-02-17 18:26 - 2014-02-17 18:26 - 00000000 ____D () C:\Windows\Minidump 2014-02-17 17:34 - 2014-02-17 02:46 - 00000000 ____D () C:\ProgramData\Creative 2014-02-17 03:31 - 2014-02-17 03:31 - 00000000 ____D () C:\Users\Administrator\AppData\Local\DDMSettings 2014-02-17 03:30 - 2014-02-17 03:30 - 00000000 ____D () C:\Program Files\AC3Filter 2014-02-17 03:28 - 2014-02-17 03:28 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-02-17 03:28 - 2014-02-17 03:27 - 00000000 ____D () C:\ProgramData\DivX 2014-02-17 03:28 - 2014-02-17 03:27 - 00000000 ____D () C:\Program Files\DivX 2014-02-17 02:18 - 2014-02-17 02:18 - 00000000 ____D () C:\Program Files\Common Files\Creative Labs Shared 2014-02-17 02:18 - 2014-02-17 02:16 - 00000000 ____D () C:\Program Files\Creative 2014-02-17 02:18 - 2014-02-15 19:16 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-02-17 02:17 - 2014-02-17 02:17 - 00445016 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00000087 ___RH () C:\Windows\ctfile.rfc 2014-02-17 02:17 - 2014-02-17 02:17 - 00000000 ____D () C:\Program Files\OpenAL 2014-02-17 02:17 - 2014-02-17 02:16 - 00000000 ____D () C:\Windows\system32\Data 2014-02-17 02:16 - 2014-02-17 02:16 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-02-17 02:08 - 2014-02-17 02:08 - 00000000 ____D () C:\ProgramData\Mozilla 2014-02-17 01:17 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-02-17 01:01 - 2014-02-17 01:01 - 00380416 _____ () C:\Users\Administrator\Desktop\Gmer-19357.exe 2014-02-17 01:01 - 2014-02-17 01:01 - 00000000 _____ () C:\Users\Administrator\defogger_reenable 2014-02-17 01:01 - 2014-02-15 19:22 - 00000000 ____D () C:\Users\Administrator 2014-02-17 01:00 - 2014-02-17 01:00 - 00050477 _____ () C:\Users\Administrator\Desktop\Defogger.exe 2014-02-17 00:39 - 2014-02-17 00:39 - 00000000 ____D () C:\Windows\pss 2014-02-17 00:38 - 2014-02-17 00:35 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-16 08:13 - 2014-02-15 20:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-16 04:18 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-15 21:46 - 2014-02-15 20:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Thunderbird 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Macromedia 2014-02-15 20:34 - 2014-02-15 20:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-15 20:34 - 2014-02-15 20:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-15 20:34 - 2014-02-15 20:34 - 00000000 ____D () C:\Windows\system32\Macromed 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Thunderbird 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Media Player Classic 2014-02-15 20:03 - 2014-02-15 20:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\altThunderbird 2014-02-15 19:57 - 2014-02-15 19:53 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Program Files\AGEIA Technologies 2014-02-15 19:54 - 2014-02-15 19:46 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-15 19:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help 2014-02-15 19:51 - 2014-02-15 19:23 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-02-15 19:51 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-02-15 19:48 - 2014-02-15 19:48 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-02-15 19:45 - 2014-02-15 19:45 - 00000000 ____D () C:\NVIDIA 2014-02-15 19:43 - 2014-02-15 19:43 - 00000000 ____D () C:\Users\Administrator\Desktop\Windows_Loader_v2.2.1 2014-02-15 19:23 - 2014-02-15 19:23 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-02-15 19:22 - 2014-02-15 19:22 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-15 19:18 - 2014-02-15 19:18 - 00001326 _____ () C:\Users\ich\Desktop\firefox - Verknüpfung.lnk 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Roaming\Mozilla 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Local\Mozilla 2014-02-15 19:17 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\Users\ich\Desktop\TL-WN722N_V1_Driver 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-02-15 19:15 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\restore 2014-02-15 19:11 - 2014-02-15 19:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-02-15 19:08 - 2014-02-15 19:08 - 00001432 _____ () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-15 19:08 - 2014-02-15 19:07 - 00000000 ____D () C:\Users\ich 2014-02-15 19:07 - 2014-02-15 19:07 - 00000020 ___SH () C:\Users\ich\ntuser.ini 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 ____D () C:\Users\ich\AppData\Local\VirtualStore 2014-02-15 19:07 - 2014-02-15 18:51 - 00000000 ____D () C:\Windows\Panther 2014-02-15 19:07 - 2013-01-13 13:15 - 00000000 ____D () C:\Recovery 2014-02-15 19:07 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-15 19:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\Recovery 2014-02-15 19:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-02-15 19:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Windows NT 2014-02-15 18:57 - 2014-02-15 18:54 - 00001355 _____ () C:\Windows\TSSysprep.log 2014-02-15 18:55 - 2014-02-15 18:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-02-15 18:54 - 2010-11-21 01:55 - 00000000 ____D () C:\Windows\CSC 2014-02-15 18:54 - 2009-07-14 05:34 - 00002790 _____ () C:\Windows\DtcInstall.log 2014-02-15 18:51 - 2009-07-14 05:57 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-02-15 18:51 - 2009-07-14 05:52 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-02-15 18:41 - 2014-02-15 18:41 - 00000000 ____D () C:\Windows.old 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 ____D () C:\RegBackup 2014-02-11 18:08 - 2014-02-11 18:08 - 00003288 ____N () C:\bootsqm.dat 2014-02-01 19:32 - 2013-01-13 16:35 - 00000000 ____D () C:\backup Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\catchme.dll C:\Users\Administrator\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-15 18:53 ==================== End Of Log ============================ --- --- --- Scheint wieder gut auszusehen, oder? |
22.02.2014, 12:57 | #20 |
/// the machine /// TB-Ausbilder | DHCP Dienst lässt sich nicht startenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.02.2014, 16:04 | #21 |
| DHCP Dienst lässt sich nicht starten Hi! Mit ESET wurde was gefunden, deswegen eine kurze Zwischenmeldung: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3353f5e0140c384cae46cd62330c7bde # engine=17180 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-22 03:04:06 # local_time=2014-02-22 04:04:06 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 187388 144712637 0 0 # scanned=362467 # found=17 # cleaned=0 # scan_time=8564 sh=78362C20D6F6E3BC66CDE31D7C3DE04921C8A8E0 ft=1 fh=a760f8a235713244 vn="a variant of MSIL/Injector.CNY trojan" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\184185822.exe.vir" sh=3B9B4F8A22B59AAF79359E4D9878DDDAC8ECA653 ft=0 fh=0000000000000000 vn="VBS/Runner.NBU trojan" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\184185822.vbs.vir" sh=A69A08C8A58366931DFFE3A641E71FC424815E36 ft=1 fh=0ae01e9e0641f273 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="C:\Windows.old\Documents and Settings\ich\AppData\Local\Anwendungsdaten\Temp\TInTkZV9.exe.part" sh=1715B61AA3387B6562CE2603DAF1880212DC0CC4 ft=0 fh=0000000000000000 vn="a variant of Win32/Kryptik.BCIS trojan" ac=I fn="C:\Windows.old\Documents and Settings\ich\AppData\Local\Anwendungsdaten\Temp\YMNH7h67.zip.part" sh=ACEFA2371BF259D9193AC2A765EAACE14810F147 ft=1 fh=7f4b7937791eb736 vn="multiple threats" ac=I fn="C:\Windows.old\Documents and Settings\ich\AppData\Local\Anwendungsdaten\Temp\is1070216317\8587049_Setup.EXE" sh=A69A08C8A58366931DFFE3A641E71FC424815E36 ft=1 fh=0ae01e9e0641f273 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="C:\Windows.old\Documents and Settings\ich\AppData\Local\Temp\TInTkZV9.exe.part" sh=1715B61AA3387B6562CE2603DAF1880212DC0CC4 ft=0 fh=0000000000000000 vn="a variant of Win32/Kryptik.BCIS trojan" ac=I fn="C:\Windows.old\Documents and Settings\ich\AppData\Local\Temp\YMNH7h67.zip.part" sh=ACEFA2371BF259D9193AC2A765EAACE14810F147 ft=1 fh=7f4b7937791eb736 vn="multiple threats" ac=I fn="C:\Windows.old\Documents and Settings\ich\AppData\Local\Temp\is1070216317\8587049_Setup.EXE" sh=A69A08C8A58366931DFFE3A641E71FC424815E36 ft=1 fh=0ae01e9e0641f273 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="C:\Windows.old\Documents and Settings\ich\Lokale Einstellungen\Temp\TInTkZV9.exe.part" sh=1715B61AA3387B6562CE2603DAF1880212DC0CC4 ft=0 fh=0000000000000000 vn="a variant of Win32/Kryptik.BCIS trojan" ac=I fn="C:\Windows.old\Documents and Settings\ich\Lokale Einstellungen\Temp\YMNH7h67.zip.part" sh=ACEFA2371BF259D9193AC2A765EAACE14810F147 ft=1 fh=7f4b7937791eb736 vn="multiple threats" ac=I fn="C:\Windows.old\Documents and Settings\ich\Lokale Einstellungen\Temp\is1070216317\8587049_Setup.EXE" sh=A69A08C8A58366931DFFE3A641E71FC424815E36 ft=1 fh=0ae01e9e0641f273 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="C:\Windows.old\Users\ich\AppData\Local\Temp\TInTkZV9.exe.part" sh=1715B61AA3387B6562CE2603DAF1880212DC0CC4 ft=0 fh=0000000000000000 vn="a variant of Win32/Kryptik.BCIS trojan" ac=I fn="C:\Windows.old\Users\ich\AppData\Local\Temp\YMNH7h67.zip.part" sh=ACEFA2371BF259D9193AC2A765EAACE14810F147 ft=1 fh=7f4b7937791eb736 vn="multiple threats" ac=I fn="C:\Windows.old\Users\ich\AppData\Local\Temp\is1070216317\8587049_Setup.EXE" sh=A69A08C8A58366931DFFE3A641E71FC424815E36 ft=1 fh=0ae01e9e0641f273 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="C:\Windows.old\Users\ich\Lokale Einstellungen\Temp\TInTkZV9.exe.part" sh=1715B61AA3387B6562CE2603DAF1880212DC0CC4 ft=0 fh=0000000000000000 vn="a variant of Win32/Kryptik.BCIS trojan" ac=I fn="C:\Windows.old\Users\ich\Lokale Einstellungen\Temp\YMNH7h67.zip.part" sh=ACEFA2371BF259D9193AC2A765EAACE14810F147 ft=1 fh=7f4b7937791eb736 vn="multiple threats" ac=I fn="C:\Windows.old\Users\ich\Lokale Einstellungen\Temp\is1070216317\8587049_Setup.EXE" |
23.02.2014, 11:38 | #22 |
/// the machine /// TB-Ausbilder | DHCP Dienst lässt sich nicht starten Jap als weiter. Ordner Windows.old löschen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.02.2014, 13:28 | #23 |
| DHCP Dienst lässt sich nicht startenCode:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x86 (UAC is enabled) ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Adobe Flash Player 12.0.0.70 Mozilla Firefox (27.0.1) Mozilla Thunderbird (24.3.0) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-02-2014 Ran by Administrator (administrator) on PC on 23-02-2014 13:27:40 Running from C:\Users\Administrator\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Creative Technology Ltd) C:\Windows\System32\Ctxfihlp.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Creative Technology Ltd) C:\Windows\SYSTEM32\CTXFISPI.EXE (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [CTxfiHlp] - C:\Windows\system32\CTXFIHLP.EXE [24576 2012-12-18] (Creative Technology Ltd) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-11-15] () HKLM\...\Run: [LifeCam] - C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 193.189.244.202 193.189.244.194 FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Extension: FireShot - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2014-02-15] FF Extension: ProxTube - Unblock YouTube - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} [2014-02-15] FF Extension: Reddit Enhancement Suite - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi [2014-02-15] FF Extension: Adblock Plus - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\a9b69vyj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-15] FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe ========================== Services (Whitelisted) ================= R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation) ==================== Drivers (Whitelisted) ==================== R3 athur; C:\Windows\System32\DRIVERS\athur.sys [1570304 2011-04-20] (Atheros Communications, Inc.) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation) S3 catchme; \??\C:\Users\ADMINI~1\AppData\Local\Temp\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-23 13:26 - 2014-02-23 13:26 - 00987425 _____ () C:\Users\Administrator\Desktop\SecurityCheck.exe 2014-02-23 11:16 - 2014-02-23 11:16 - 00000336 ____H () C:\Windows\Tasks\Microsoft_Hardware_Launch_rundll32_exe.job 2014-02-23 11:15 - 2014-02-23 11:15 - 00000000 ____D () C:\Program Files\Microsoft LifeCam 2014-02-23 11:15 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll 2014-02-23 11:15 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll 2014-02-22 14:47 - 2014-02-22 14:47 - 00000009 _____ () C:\Users\Administrator\Desktop\Neues Textdokument.txt 2014-02-22 13:21 - 2014-02-22 13:21 - 00000000 ____D () C:\Program Files\ESET 2014-02-21 09:40 - 2014-02-23 13:27 - 00005198 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-02-21 09:39 - 2014-02-21 09:39 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-02-21 09:37 - 2014-02-21 09:37 - 00000656 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-02-21 09:34 - 2014-02-21 09:34 - 00000000 ____D () C:\Windows\ERUNT 2014-02-21 09:33 - 2014-02-21 09:33 - 01037734 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-02-21 09:31 - 2014-02-21 09:31 - 00001187 _____ () C:\Users\Administrator\Desktop\adw.txt 2014-02-21 09:28 - 2014-02-21 09:29 - 00000000 ____D () C:\AdwCleaner 2014-02-21 09:27 - 2014-02-21 09:27 - 01241834 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-02-21 09:26 - 2014-02-21 09:26 - 00001062 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-02-21 09:14 - 2014-02-21 09:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-21 09:13 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-20 06:45 - 2014-02-20 06:45 - 00001300 _____ () C:\Users\Administrator\Desktop\foobar2000 - Verknüpfung.lnk 2014-02-20 06:35 - 2014-02-20 06:35 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\OpenOffice 2014-02-20 06:34 - 2014-02-20 06:34 - 00000000 ____D () C:\Program Files\OpenOffice 4 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFixsaddsa.exe 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 _____ (Swearware) C:\Users\Administrator\Desktop\ComboFix(2).exe 2014-02-19 21:09 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-19 21:09 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-19 21:09 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-19 21:09 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-19 21:08 - 2014-02-21 09:26 - 00000000 ____D () C:\Qoobox 2014-02-19 21:08 - 2014-02-19 21:17 - 00000000 ____D () C:\Windows\erdnt 2014-02-19 21:07 - 2014-02-19 21:08 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\NVIDIA 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-02-19 10:13 - 2014-02-19 12:33 - 00000000 ____D () C:\Users\Administrator\Downloads\John Carter (2012) [1080p] [3D] [HSBS] 2014-02-19 10:11 - 2014-02-19 11:48 - 00000000 ____D () C:\Users\Administrator\Downloads\Green Lantern (2011) [3D] [1080p] 2014-02-19 10:07 - 2014-02-19 12:48 - 00000000 ____D () C:\Users\Administrator\Downloads\Life of Pi (2012) [3D] [HSBS] 2014-02-19 10:06 - 2014-02-19 11:56 - 00000000 ____D () C:\Users\Administrator\Downloads\Dredd (2012) [3D] [HSBS] 2014-02-19 10:05 - 2014-02-19 10:36 - 00000000 ____D () C:\Users\Administrator\Downloads\The Green Hornet 3D (2011) [1080p] [3D] [HSBS] 2014-02-19 10:03 - 2014-02-19 15:57 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent 2014-02-18 02:34 - 2014-02-18 03:38 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm 2014-02-18 02:34 - 2014-02-18 03:38 - 00001080 _____ () C:\Windows\system32\settings.sfm 2014-02-17 18:26 - 2014-02-17 18:26 - 193831120 _____ () C:\Windows\MEMORY.DMP 2014-02-17 18:26 - 2014-02-17 18:26 - 00157584 _____ () C:\Windows\Minidump\021714-24757-01.dmp 2014-02-17 18:26 - 2014-02-17 18:26 - 00000000 ____D () C:\Windows\Minidump 2014-02-17 03:31 - 2014-02-17 03:31 - 00000000 ____D () C:\Users\Administrator\AppData\Local\DDMSettings 2014-02-17 03:30 - 2014-02-17 03:30 - 00000000 ____D () C:\Program Files\AC3Filter 2014-02-17 03:30 - 2013-04-05 21:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm 2014-02-17 03:28 - 2014-02-17 03:28 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-02-17 03:27 - 2014-02-17 03:28 - 00000000 ____D () C:\ProgramData\DivX 2014-02-17 03:27 - 2014-02-17 03:28 - 00000000 ____D () C:\Program Files\DivX 2014-02-17 02:46 - 2014-02-17 17:34 - 00000000 ____D () C:\ProgramData\Creative 2014-02-17 02:18 - 2014-02-17 02:18 - 00000000 ____D () C:\Program Files\Common Files\Creative Labs Shared 2014-02-17 02:18 - 2003-06-12 23:25 - 00007062 _____ () C:\Windows\system32\audiopid.vxd 2014-02-17 02:17 - 2014-02-17 02:17 - 00445016 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00000087 ___RH () C:\Windows\ctfile.rfc 2014-02-17 02:17 - 2014-02-17 02:17 - 00000000 ____D () C:\Program Files\OpenAL 2014-02-17 02:17 - 2009-06-29 10:54 - 00164864 _____ () C:\Windows\system32\APOMngr.DLL 2014-02-17 02:17 - 2009-02-17 17:33 - 00106496 _____ (Creative Technology Ltd) C:\Windows\system32\cttele32.dll 2014-02-17 02:17 - 2009-02-06 18:52 - 00073728 _____ () C:\Windows\system32\CmdRtr.DLL 2014-02-17 02:16 - 2014-02-17 02:18 - 00000000 ____D () C:\Program Files\Creative 2014-02-17 02:16 - 2014-02-17 02:17 - 00000000 ____D () C:\Windows\system32\Data 2014-02-17 02:16 - 2014-02-17 02:16 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-02-17 02:16 - 2007-09-13 18:05 - 00002560 _____ () C:\Windows\CTXFIGER.DLL 2014-02-17 02:16 - 2004-07-30 14:46 - 00020480 _____ (Creative Technology Limited) C:\Windows\INRESGER.DLL 2014-02-17 02:08 - 2014-02-20 05:20 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-17 02:08 - 2014-02-17 02:08 - 00000000 ____D () C:\ProgramData\Mozilla 2014-02-17 01:01 - 2014-02-17 01:01 - 00380416 _____ () C:\Users\Administrator\Desktop\Gmer-19357.exe 2014-02-17 01:01 - 2014-02-17 01:01 - 00000000 _____ () C:\Users\Administrator\defogger_reenable 2014-02-17 01:00 - 2014-02-21 09:39 - 01142784 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2014-02-17 01:00 - 2014-02-17 01:00 - 00050477 _____ () C:\Users\Administrator\Desktop\Defogger.exe 2014-02-17 00:39 - 2014-02-17 00:39 - 00000000 ____D () C:\Windows\pss 2014-02-17 00:36 - 2014-02-21 13:58 - 00063568 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-17 00:35 - 2014-02-17 00:38 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Macromedia 2014-02-15 20:34 - 2014-02-23 04:02 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-15 20:34 - 2014-02-23 04:02 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-15 20:34 - 2014-02-23 04:02 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-15 20:34 - 2014-02-15 20:34 - 00000000 ____D () C:\Windows\system32\Macromed 2014-02-15 20:05 - 2014-02-22 20:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\foobar2000 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Thunderbird 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Media Player Classic 2014-02-15 20:03 - 2014-02-15 21:46 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Thunderbird 2014-02-15 20:03 - 2014-02-15 20:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\altThunderbird 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Program Files\AGEIA Technologies 2014-02-15 19:53 - 2014-02-15 19:57 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-15 19:53 - 2013-12-19 21:26 - 00053024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 04317984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 03036960 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 02555168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 00664352 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-15 19:53 - 2013-12-19 19:37 - 00376096 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-15 19:53 - 2013-12-19 19:37 - 00062752 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-15 19:53 - 2013-12-19 04:39 - 03539040 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-15 19:48 - 2014-02-15 19:48 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-02-15 19:47 - 2013-12-19 21:26 - 22960416 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 15877216 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 15230352 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 10471712 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-15 19:47 - 2013-12-19 21:26 - 09657464 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 02947872 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 02747680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 01242400 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233221.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233221.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00852768 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00847648 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00266984 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00141336 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll 2014-02-15 19:47 - 2013-12-19 21:26 - 00018439 _____ () C:\Windows\system32\nvinfo.pb 2014-02-15 19:47 - 2013-12-05 09:42 - 00034080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys 2014-02-15 19:47 - 2013-12-05 09:42 - 00032544 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll 2014-02-15 19:46 - 2014-02-15 19:54 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-15 19:46 - 2013-12-19 21:26 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-15 19:46 - 2013-12-19 21:26 - 09700224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-15 19:46 - 2013-12-19 21:26 - 02698272 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2014-02-15 19:43 - 2014-02-15 19:43 - 00000000 ____D () C:\Users\Administrator\Desktop\Windows_Loader_v2.2.1 2014-02-15 19:25 - 2013-12-18 06:13 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-02-15 19:23 - 2014-02-15 19:51 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-02-15 19:23 - 2014-02-15 19:23 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-02-15 19:22 - 2014-02-17 01:01 - 00000000 ____D () C:\Users\Administrator 2014-02-15 19:22 - 2014-02-15 19:22 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-15 19:22 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-15 19:22 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-15 19:18 - 2014-02-15 19:18 - 00001326 _____ () C:\Users\ich\Desktop\firefox - Verknüpfung.lnk 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Roaming\Mozilla 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Local\Mozilla 2014-02-15 19:16 - 2014-02-17 02:18 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-02-15 19:16 - 2011-05-03 22:13 - 00008816 _____ () C:\Windows\system32\athurext.cat 2014-02-15 19:16 - 2011-04-20 03:06 - 01570304 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athur.sys 2014-02-15 19:16 - 2011-04-20 03:06 - 01570304 _____ (Atheros Communications, Inc.) C:\Windows\system32\athur.sys 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\Users\ich\Desktop\TL-WN722N_V1_Driver 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-02-15 19:11 - 2014-02-15 19:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-02-15 19:08 - 2014-02-15 19:08 - 00001432 _____ () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-15 19:07 - 2014-02-15 19:08 - 00000000 ____D () C:\Users\ich 2014-02-15 19:07 - 2014-02-15 19:07 - 00000020 ___SH () C:\Users\ich\ntuser.ini 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 ____D () C:\Users\ich\AppData\Local\VirtualStore 2014-02-15 19:07 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2014-02-15 19:07 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2014-02-15 18:56 - 2014-02-23 11:16 - 00086600 _____ () C:\Windows\WindowsUpdate.log 2014-02-15 18:55 - 2014-02-15 18:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-02-15 18:54 - 2014-02-15 18:57 - 00001355 _____ () C:\Windows\TSSysprep.log 2014-02-15 18:51 - 2014-02-15 19:07 - 00000000 ____D () C:\Windows\Panther 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 ____D () C:\RegBackup 2014-02-11 18:08 - 2014-02-11 18:08 - 00003288 ____N () C:\bootsqm.dat 2014-02-09 18:36 - 2014-02-23 13:27 - 00000000 ____D () C:\FRST ==================== One Month Modified Files and Folders ======= 2014-02-23 13:27 - 2014-02-21 09:40 - 00005198 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-02-23 13:27 - 2014-02-09 18:36 - 00000000 ____D () C:\FRST 2014-02-23 13:26 - 2014-02-23 13:26 - 00987425 _____ () C:\Users\Administrator\Desktop\SecurityCheck.exe 2014-02-23 12:46 - 2009-07-14 05:34 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-23 12:46 - 2009-07-14 05:34 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-23 11:56 - 2009-07-14 05:39 - 00027510 _____ () C:\Windows\setupact.log 2014-02-23 11:16 - 2014-02-23 11:16 - 00000336 ____H () C:\Windows\Tasks\Microsoft_Hardware_Launch_rundll32_exe.job 2014-02-23 11:16 - 2014-02-15 18:56 - 00086600 _____ () C:\Windows\WindowsUpdate.log 2014-02-23 11:15 - 2014-02-23 11:15 - 00000000 ____D () C:\Program Files\Microsoft LifeCam 2014-02-23 10:48 - 2010-11-20 22:01 - 01611160 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-23 04:02 - 2014-02-15 20:34 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-23 04:02 - 2014-02-15 20:34 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-23 04:02 - 2014-02-15 20:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-22 20:18 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\foobar2000 2014-02-22 14:47 - 2014-02-22 14:47 - 00000009 _____ () C:\Users\Administrator\Desktop\Neues Textdokument.txt 2014-02-22 13:21 - 2014-02-22 13:21 - 00000000 ____D () C:\Program Files\ESET 2014-02-21 13:58 - 2014-02-17 00:36 - 00063568 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-21 09:39 - 2014-02-21 09:39 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-02-21 09:39 - 2014-02-17 01:00 - 01142784 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2014-02-21 09:37 - 2014-02-21 09:37 - 00000656 _____ () C:\Users\Administrator\Desktop\JRT.txt 2014-02-21 09:34 - 2014-02-21 09:34 - 00000000 ____D () C:\Windows\ERUNT 2014-02-21 09:33 - 2014-02-21 09:33 - 01037734 _____ (Thisisu) C:\Users\Administrator\Desktop\JRT.exe 2014-02-21 09:31 - 2014-02-21 09:31 - 00001187 _____ () C:\Users\Administrator\Desktop\adw.txt 2014-02-21 09:29 - 2014-02-21 09:28 - 00000000 ____D () C:\AdwCleaner 2014-02-21 09:27 - 2014-02-21 09:27 - 01241834 _____ () C:\Users\Administrator\Desktop\adwcleaner.exe 2014-02-21 09:26 - 2014-02-21 09:26 - 00001062 _____ () C:\Users\Administrator\Desktop\mbam.txt 2014-02-21 09:26 - 2014-02-19 21:08 - 00000000 ____D () C:\Qoobox 2014-02-21 09:14 - 2014-02-21 09:14 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Administrator\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-21 09:13 - 2014-02-21 09:13 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-20 13:08 - 2009-07-14 05:33 - 00296920 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-20 06:45 - 2014-02-20 06:45 - 00001300 _____ () C:\Users\Administrator\Desktop\foobar2000 - Verknüpfung.lnk 2014-02-20 06:35 - 2014-02-20 06:35 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\OpenOffice 2014-02-20 06:34 - 2014-02-20 06:34 - 00000000 ____D () C:\Program Files\OpenOffice 4 2014-02-20 06:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2014-02-20 05:20 - 2014-02-17 02:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-20 05:20 - 2010-11-20 22:48 - 00006780 _____ () C:\Windows\PFRO.log 2014-02-19 21:18 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default 2014-02-19 21:18 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public 2014-02-19 21:17 - 2014-02-19 21:08 - 00000000 ____D () C:\Windows\erdnt 2014-02-19 21:17 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFixsaddsa.exe 2014-02-19 21:09 - 2014-02-19 21:09 - 05183254 _____ (Swearware) C:\Users\Administrator\Desktop\ComboFix(2).exe 2014-02-19 21:08 - 2014-02-19 21:07 - 05183254 ____R (Swearware) C:\Users\Administrator\Desktop\ComboFix.exe 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\NVIDIA 2014-02-19 19:42 - 2014-02-19 19:42 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2014-02-19 15:57 - 2014-02-19 10:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent 2014-02-19 12:48 - 2014-02-19 10:07 - 00000000 ____D () C:\Users\Administrator\Downloads\Life of Pi (2012) [3D] [HSBS] 2014-02-19 12:33 - 2014-02-19 10:13 - 00000000 ____D () C:\Users\Administrator\Downloads\John Carter (2012) [1080p] [3D] [HSBS] 2014-02-19 11:56 - 2014-02-19 10:06 - 00000000 ____D () C:\Users\Administrator\Downloads\Dredd (2012) [3D] [HSBS] 2014-02-19 11:48 - 2014-02-19 10:11 - 00000000 ____D () C:\Users\Administrator\Downloads\Green Lantern (2011) [3D] [1080p] 2014-02-19 10:36 - 2014-02-19 10:05 - 00000000 ____D () C:\Users\Administrator\Downloads\The Green Hornet 3D (2011) [1080p] [3D] [HSBS] 2014-02-19 03:14 - 2009-07-14 04:20 - 00000000 ___RD () C:\Program Files (x86) 2014-02-18 03:38 - 2014-02-18 02:34 - 00001080 _____ () C:\Windows\system32\settingsbkup.sfm 2014-02-18 03:38 - 2014-02-18 02:34 - 00001080 _____ () C:\Windows\system32\settings.sfm 2014-02-17 18:26 - 2014-02-17 18:26 - 193831120 _____ () C:\Windows\MEMORY.DMP 2014-02-17 18:26 - 2014-02-17 18:26 - 00157584 _____ () C:\Windows\Minidump\021714-24757-01.dmp 2014-02-17 18:26 - 2014-02-17 18:26 - 00000000 ____D () C:\Windows\Minidump 2014-02-17 17:34 - 2014-02-17 02:46 - 00000000 ____D () C:\ProgramData\Creative 2014-02-17 03:31 - 2014-02-17 03:31 - 00000000 ____D () C:\Users\Administrator\AppData\Local\DDMSettings 2014-02-17 03:30 - 2014-02-17 03:30 - 00000000 ____D () C:\Program Files\AC3Filter 2014-02-17 03:28 - 2014-02-17 03:28 - 00000000 ____D () C:\Program Files\Common Files\DivX Shared 2014-02-17 03:28 - 2014-02-17 03:27 - 00000000 ____D () C:\ProgramData\DivX 2014-02-17 03:28 - 2014-02-17 03:27 - 00000000 ____D () C:\Program Files\DivX 2014-02-17 02:18 - 2014-02-17 02:18 - 00000000 ____D () C:\Program Files\Common Files\Creative Labs Shared 2014-02-17 02:18 - 2014-02-17 02:16 - 00000000 ____D () C:\Program Files\Creative 2014-02-17 02:18 - 2014-02-15 19:16 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-02-17 02:17 - 2014-02-17 02:17 - 00445016 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2014-02-17 02:17 - 2014-02-17 02:17 - 00000087 ___RH () C:\Windows\ctfile.rfc 2014-02-17 02:17 - 2014-02-17 02:17 - 00000000 ____D () C:\Program Files\OpenAL 2014-02-17 02:17 - 2014-02-17 02:16 - 00000000 ____D () C:\Windows\system32\Data 2014-02-17 02:16 - 2014-02-17 02:16 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2014-02-17 02:08 - 2014-02-17 02:08 - 00000000 ____D () C:\ProgramData\Mozilla 2014-02-17 01:17 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-02-17 01:01 - 2014-02-17 01:01 - 00380416 _____ () C:\Users\Administrator\Desktop\Gmer-19357.exe 2014-02-17 01:01 - 2014-02-17 01:01 - 00000000 _____ () C:\Users\Administrator\defogger_reenable 2014-02-17 01:01 - 2014-02-15 19:22 - 00000000 ____D () C:\Users\Administrator 2014-02-17 01:00 - 2014-02-17 01:00 - 00050477 _____ () C:\Users\Administrator\Desktop\Defogger.exe 2014-02-17 00:39 - 2014-02-17 00:39 - 00000000 ____D () C:\Windows\pss 2014-02-17 00:38 - 2014-02-17 00:35 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-16 04:18 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-15 21:46 - 2014-02-15 20:03 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Thunderbird 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Macromedia 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe 2014-02-15 20:36 - 2014-02-15 20:36 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Macromedia 2014-02-15 20:34 - 2014-02-15 20:34 - 00000000 ____D () C:\Windows\system32\Macromed 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Thunderbird 2014-02-15 20:05 - 2014-02-15 20:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Media Player Classic 2014-02-15 20:03 - 2014-02-15 20:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\altThunderbird 2014-02-15 19:57 - 2014-02-15 19:53 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Users\Administrator\AppData\Local\NVIDIA 2014-02-15 19:54 - 2014-02-15 19:54 - 00000000 ____D () C:\Program Files\AGEIA Technologies 2014-02-15 19:54 - 2014-02-15 19:46 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-15 19:53 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help 2014-02-15 19:51 - 2014-02-15 19:23 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla 2014-02-15 19:51 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-02-15 19:48 - 2014-02-15 19:48 - 00000000 ____D () C:\Program Files\Microsoft.NET 2014-02-15 19:43 - 2014-02-15 19:43 - 00000000 ____D () C:\Users\Administrator\Desktop\Windows_Loader_v2.2.1 2014-02-15 19:23 - 2014-02-15 19:23 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla 2014-02-15 19:22 - 2014-02-15 19:22 - 00000020 ___SH () C:\Users\Administrator\ntuser.ini 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Startmenü 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Netzwerkumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Druckumgebung 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Musik 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\Documents\Eigene Bilder 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:22 - 2014-02-15 19:22 - 00000000 _SHDL () C:\Users\Administrator\AppData\Local\Verlauf 2014-02-15 19:18 - 2014-02-15 19:18 - 00001326 _____ () C:\Users\ich\Desktop\firefox - Verknüpfung.lnk 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Roaming\Mozilla 2014-02-15 19:18 - 2014-02-15 19:18 - 00000000 ____D () C:\Users\ich\AppData\Local\Mozilla 2014-02-15 19:17 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Public\Libraries 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\Users\ich\Desktop\TL-WN722N_V1_Driver 2014-02-15 19:15 - 2014-02-15 19:15 - 00000000 ____D () C:\ProgramData\TP-LINK 2014-02-15 19:15 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\restore 2014-02-15 19:11 - 2014-02-15 19:11 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-02-15 19:08 - 2014-02-15 19:08 - 00001432 _____ () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-15 19:08 - 2014-02-15 19:07 - 00000000 ____D () C:\Users\ich 2014-02-15 19:07 - 2014-02-15 19:07 - 00000020 ___SH () C:\Users\ich\ntuser.ini 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\ich\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Startmenü 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 _SHDL () C:\ProgramData\Dokumente 2014-02-15 19:07 - 2014-02-15 19:07 - 00000000 ____D () C:\Users\ich\AppData\Local\VirtualStore 2014-02-15 19:07 - 2014-02-15 18:51 - 00000000 ____D () C:\Windows\Panther 2014-02-15 19:07 - 2013-01-13 13:15 - 00000000 ____D () C:\Recovery 2014-02-15 19:07 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-15 19:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\Recovery 2014-02-15 19:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-02-15 19:07 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Windows NT 2014-02-15 18:57 - 2014-02-15 18:54 - 00001355 _____ () C:\Windows\TSSysprep.log 2014-02-15 18:55 - 2014-02-15 18:55 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2014-02-15 18:54 - 2010-11-21 01:55 - 00000000 ____D () C:\Windows\CSC 2014-02-15 18:54 - 2009-07-14 05:34 - 00002790 _____ () C:\Windows\DtcInstall.log 2014-02-15 18:51 - 2009-07-14 05:57 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG 2014-02-15 18:51 - 2009-07-14 05:52 - 00028672 _____ () C:\Windows\system32\config\BCD-Template 2014-02-11 18:25 - 2014-02-11 18:25 - 00000000 ____D () C:\RegBackup 2014-02-11 18:08 - 2014-02-11 18:08 - 00003288 ____N () C:\bootsqm.dat 2014-02-01 19:32 - 2013-01-13 16:35 - 00000000 ____D () C:\backup Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\catchme.dll C:\Users\Administrator\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-15 18:53 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-02-2014 Ran by Administrator at 2014-02-23 13:32:37 Running from C:\Users\Administrator\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== AC3Filter 2.6.0b (Version: 2.6.0b - Alexander Vigovsky) Adobe Flash Player 12 Plugin (Version: 12.0.0.70 - Adobe Systems Incorporated) Creative Audio-Systemsteuerung (Version: 3.00 - Creative Technology Limited) Creative Software AutoUpdate (Version: 1.41 - Creative Technology Limited) Eigenschaften von Creative Sound Blaster (Version: 1.03 - Creative Technology Limited) ESET Online Scanner v3 (Version: - ) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden Microsoft LifeCam (Version: 3.60.253.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (Version: 24.3.0 - Mozilla) Mozilla Thunderbird 24.3.0 (x86 de) (Version: 24.3.0 - Mozilla) NVIDIA GeForce Experience 1.8.1 (Version: 1.8.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 332.21 (Version: 332.21 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 10.11.15 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.19 (Version: 1.2.19 - NVIDIA Corporation) OpenAL (Version: - ) OpenOffice 4.0.1 (Version: 4.01.9714 - Apache Software Foundation) SHIELD Streaming (Version: 1.6.85 - NVIDIA Corporation) Hidden TL-WN721N/TL-WN722N Driver (Version: 1.0.0 - TP-LINK) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden ==================== Restore Points ========================= 15-02-2014 18:15:53 Installed TP-LINK Wireless Configuration Utility and Driver 15-02-2014 18:16:09 Gerätetreiber-Paketinstallation: Atheros Communications Inc. Netzwerkadapter 15-02-2014 18:24:59 Windows Update 15-02-2014 18:47:37 Windows Update 17-02-2014 01:16:34 Gerätetreiber-Paketinstallation: Creative Audio-, Video- und Gamecontroller 17-02-2014 01:17:33 Installiert Creative Audio Control Panel 17-02-2014 01:18:12 Installiert Creative Sound Blaster Properties 17-02-2014 01:18:29 Installiert Creative Software AutoUpdate 19-02-2014 20:10:13 ComboFix created restore point 20-02-2014 05:32:14 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 20-02-2014 05:33:50 OpenOffice 4.0.1 wird installiert 23-02-2014 10:15:00 DirectX wurde installiert ==================== Hosts content: ========================== 2009-07-14 03:04 - 2014-02-19 21:16 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {45CAF716-2FD3-4A14-80EC-75B97AC3A7DE} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-23] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Microsoft_Hardware_Launch_rundll32_exe.job => C:\Windows\system32\rundll32.exeJurl.dll ==================== Loaded Modules (whitelisted) ============= 2014-02-15 19:53 - 2013-12-19 19:37 - 00107296 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2014-02-17 02:16 - 2007-09-13 18:05 - 00002560 _____ () C:\Windows\CTXFIGER.DLL 2013-11-15 01:48 - 2013-11-15 01:48 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2013-11-15 01:49 - 2013-11-15 01:49 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2014-02-17 02:17 - 2009-06-29 10:54 - 00164864 _____ () C:\Windows\SYSTEM32\APOMngr.DLL 2014-01-09 02:10 - 2013-12-12 23:19 - 00142848 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll 2014-01-09 02:10 - 2013-11-05 02:12 - 00890592 _____ () C:\Program Files (x86)\Steam\libavutil-52.dll 2013-03-12 17:10 - 2014-02-11 03:34 - 00751616 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2013-01-13 14:01 - 2014-02-20 00:07 - 01135296 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2013-01-13 14:01 - 2014-01-11 00:33 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2013-01-13 14:01 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll 2013-01-13 14:01 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll 2013-01-13 14:01 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll 2013-12-10 16:52 - 2014-02-17 02:08 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-02-23 04:02 - 2014-02-23 04:02 - 16265096 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: RTL8187_Wireless Description: RTL8187_Wireless Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (02/23/2014 11:16:17 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: setupstb.exe, Version: 3.60.253.0, Zeitstempel: 0x4cfea7b3 Name des fehlerhaften Moduls: setupstb.exe, Version: 3.60.253.0, Zeitstempel: 0x4cfea7b3 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00073699 ID des fehlerhaften Prozesses: 0xadc Startzeit der fehlerhaften Anwendung: 0xsetupstb.exe0 Pfad der fehlerhaften Anwendung: setupstb.exe1 Pfad des fehlerhaften Moduls: setupstb.exe2 Berichtskennung: setupstb.exe3 Error: (02/23/2014 11:14:59 AM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {ba9c4b4e-b88c-40e4-b470-40b5528004a4} Error: (02/23/2014 11:12:55 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: LifeCam.exe, Version: 3.60.253.0, Zeitstempel: 0x4cfea77f Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7b8f0 Ausnahmecode: 0xe0434f4d Fehleroffset: 0x0000b760 ID des fehlerhaften Prozesses: 0xa10 Startzeit der fehlerhaften Anwendung: 0xLifeCam.exe0 Pfad der fehlerhaften Anwendung: LifeCam.exe1 Pfad des fehlerhaften Moduls: LifeCam.exe2 Berichtskennung: LifeCam.exe3 Error: (02/23/2014 10:46:08 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/23/2014 04:02:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/22/2014 06:24:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/22/2014 10:35:58 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/21/2014 09:57:08 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 27.0.1.5156, Zeitstempel: 0x52fc0faa Name des fehlerhaften Moduls: xul.dll, Version: 27.0.1.5156, Zeitstempel: 0x52fc0f79 Ausnahmecode: 0xc0000005 Fehleroffset: 0x001560c7 ID des fehlerhaften Prozesses: 0xd40 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (02/21/2014 09:37:36 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Microsoft Office Sessions: ========================= Error: (02/23/2014 11:16:17 AM) (Source: Application Error)(User: ) Description: setupstb.exe3.60.253.04cfea7b3setupstb.exe3.60.253.04cfea7b3c000000500073699adc01cf30800e963570C:\Users\ADMINI~1\AppData\Local\Temp\LifeCamSetup\setupstb.exeC:\Users\ADMINI~1\AppData\Local\Temp\LifeCamSetup\setupstb.exe87c15b8e-9c73-11e3-857c-0018f3e01f7f Error: (02/23/2014 11:14:59 AM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {ba9c4b4e-b88c-40e4-b470-40b5528004a4} Error: (02/23/2014 11:12:55 AM) (Source: Application Error)(User: ) Description: LifeCam.exe3.60.253.04cfea77fKERNELBASE.dll6.1.7601.175144ce7b8f0e0434f4d0000b760a1001cf307fce0c69f1C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exeC:\Windows\system32\KERNELBASE.dll0f60fe27-9c73-11e3-857c-0018f3e01f7f Error: (02/23/2014 10:46:08 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/23/2014 04:02:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/22/2014 06:24:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/22/2014 10:35:58 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/21/2014 09:57:08 PM) (Source: Application Error)(User: ) Description: firefox.exe27.0.1.515652fc0faaxul.dll27.0.1.515652fc0f79c0000005001560c7d4001cf2ee0363db0d8C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dllb9942a5b-9b3a-11e3-b0a7-0018f3e01f7f Error: (02/21/2014 09:37:36 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 2047.12 MB Available physical RAM: 949.85 MB Total Pagefile: 4094.23 MB Available Pagefile: 2566.25 MB Total Virtual: 2047.88 MB Available Virtual: 1889.33 MB ==================== Drives ================================ Drive c: (Lokaler Datenträger) (Fixed) (Total:232.79 GB) (Free:67.11 GB) NTFS Drive d: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 13BA13B9) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von kokaindino (23.02.2014 um 13:33 Uhr) |
24.02.2014, 16:32 | #24 |
/// the machine /// TB-Ausbilder | DHCP Dienst lässt sich nicht starten Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu DHCP Dienst lässt sich nicht starten |
abhängigkeit, afd.sys, arten, datei, dienst, drivers, ellung, fehler, funktionieren, gestartet, inter, interne, manuell, meldung, nicht starten, ordner, problem, regsvr32, starte, starten, systemwiederherstellung, treiber, versuch, versucht, windowsupdate |