|
Log-Analyse und Auswertung: versehentlich zip-anhang einer email geöffnet und .exe ausgeführtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.02.2014, 03:43 | #1 |
| versehentlich zip-anhang einer email geöffnet und .exe ausgeführt einen schönen guten tag, leider habe ich aus dummheit einen email-anhang ("clients.045-264.zip") geöffnet und das entpackte .exe ausgeführt. nun bin ich mir leider nicht sicher, ob ich mir etwas eingefangen habe. bislang konnte ich keine ungewohnten symptome feststellen. für einen kurzen blick auf folgendes logfile wäre ich sehr dankbar. Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 13-February-2014 Tool run by maddin on 14.02.2014 at 2:32:05,03. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: D:\Temp\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 14.02.2014 02:32:24 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\maddin\AppData\Local\Software deleted "C:\Users\maddin\AppData\Roaming\kock" deleted "C:\Users\maddin\AppData\Roaming\xmldm" deleted "C:\Users\maddin\AppData\Roaming\FreePDF" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\maddin\AppData\Local\Temp ==== 2014-02-12 20:44:37 F00F3F47062646F900AA327B1D5CA3A1 166912 ----a-w- C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe ====== Java Cache ===== 2014-02-10 21:56:08 3699C586D409D9321E7F5723A48BD59A 8924 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\34d52bc0-177c3d57 2014-02-10 22:02:14 5E1B59D4862D63C597EA1C1742962C95 19166 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\3a90453-5e4cc1fe 2014-02-10 21:56:09 550011EB0B59C3290CC967BC294A3EC6 16070 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\44d52fe0-784eaaae 2014-02-10 21:56:08 65C0853659D0B24F7C88EE2E749E31D5 10843 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\cad9aa1-58e2a035 2014-02-10 22:01:12 ADD2C33D1DA5F76DAD52CE6118A36D59 16417 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\229dcfa4-37107e06 2014-02-10 21:56:09 890462FBC3F94ED780C54EA7696115F0 409714 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\42e9fba7-2779916d 2014-02-10 21:56:07 EA550C3048C9DC750DD9101C3A933E5A 241410 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\3f646bc4-40a1fcaa 2014-02-10 21:56:08 A1C4ABF69B70006EB9CF3455FEACADD6 183196 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\16b572af-4d8008ca 2014-02-10 21:56:09 F5F7ABB943B52839DBF7FBF0D7227FB5 175421 ----a-w- C:\Users\maddin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\816c546-3637db8e ====== C:\Windows\SysWOW64 ===== 2014-02-13 02:00:41 3D485254E43EF4E4F707346B5731EA9A 454656 ----a-w- C:\Windows\SysWOW64\vbscript.dll 2014-02-13 02:00:22 B8F28AAC003060E3B125D2447CFC19E2 164864 ----a-w- C:\Windows\SysWOW64\msrating.dll 2014-02-13 02:00:22 B5B3334F177CED627C2D7FE38235B6B1 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 02:00:22 85AC8EB265EDCAD86D651D45C5E3AB83 440832 ----a-w- C:\Windows\SysWOW64\ieui.dll 2014-02-13 02:00:21 C9D1131E2163CE932DF3EAAF0EEA3673 524288 ----a-w- C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 02:00:21 6A06EB11F1E5BDAA795DAE7838F9FE20 43008 ----a-w- C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 02:00:20 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 02:00:20 5DD49C02D059C1E6E47A8FB4A076C9B1 703488 ----a-w- C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 02:00:20 408805B8083896DC95E6340F4016BEBD 61952 ----a-w- C:\Windows\SysWOW64\iesetup.dll 2014-02-13 02:00:20 260D6B421E5551E8BA75D16B5CA90D9A 51200 ----a-w- C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 02:00:20 0F739443669F3A48F1B2325995117BFE 553472 ----a-w- C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 02:00:20 0E7B7C9F483300F9FF97C6A1E4BC4F57 32768 ----a-w- C:\Windows\SysWOW64\iernonce.dll 2014-02-13 02:00:19 9C89246184979A070B0C6CCF61C68136 1820160 ----a-w- C:\Windows\SysWOW64\wininet.dll 2014-02-13 02:00:19 5D9DC6332A4FC66388B09BBE7CF53750 1156096 ----a-w- C:\Windows\SysWOW64\urlmon.dll 2014-02-13 02:00:19 40E68599FE3A10F816217D3789FCE74E 1964032 ----a-w- C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 02:00:19 34CBED7698D557DDB43F8732FBC2ACB9 2168320 ----a-w- C:\Windows\SysWOW64\iertutil.dll 2014-02-13 02:00:18 79FA7D8B488F90EDE325963379A6F738 11266048 ----a-w- C:\Windows\SysWOW64\ieframe.dll 2014-02-13 02:00:17 C863E5A2417DF0F2A31ED32C3B2CB23F 17103872 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-02-13 02:00:17 99280392987A1A96C756A9F38C4CE396 4244480 ----a-w- C:\Windows\SysWOW64\jscript9.dll 2014-02-12 22:31:30 E4561704CBFA193761743E5AF746C669 1237504 ----a-w- C:\Windows\SysWOW64\msxml3.dll 2014-02-12 22:31:30 17B06F23237FCD731FA2E10ECD6EDFE1 2048 ----a-w- C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 22:30:55 D96106CF60505734B14F6AE80AAA4B07 1987584 ----a-w- C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 22:30:55 14800BD31701A5047AC3145BB1E698AE 3419136 ----a-w- C:\Windows\SysWOW64\d2d1.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-02-13 02:00:41 F67C7D80745379DC4C5332EFFE5AC696 548864 ----a-w- C:\Windows\Sysnative\vbscript.dll 2014-02-13 02:00:22 94C59DD02BC7EA0E421055B9946CA861 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-02-13 02:00:22 1D1D7F52EC84294859642A4309FE648E 195584 ----a-w- C:\Windows\Sysnative\msrating.dll 2014-02-13 02:00:21 FD08F8BA2437A85F500EFFE3FD3158A6 33792 ----a-w- C:\Windows\Sysnative\iernonce.dll 2014-02-13 02:00:21 E77092C38028EB0A5C461B3436E0A6D5 4096 ----a-w- C:\Windows\Sysnative\ieetwcollectorres.dll 2014-02-13 02:00:21 CDE728C8FB1D6E132CED44835FA44C87 627200 ----a-w- C:\Windows\Sysnative\msfeeds.dll 2014-02-13 02:00:21 99ED8FBAFD325550D07A32664D9E3CC8 53760 ----a-w- C:\Windows\Sysnative\jsproxy.dll 2014-02-13 02:00:21 63B5E990896BA81D604032A48CC80A5C 574976 ----a-w- C:\Windows\Sysnative\ieui.dll 2014-02-13 02:00:21 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\Sysnative\ie4uinit.exe 2014-02-13 02:00:20 FCFAEDF0AA1A78A1875FDB798598408B 48640 ----a-w- C:\Windows\Sysnative\ieetwproxystub.dll 2014-02-13 02:00:20 F348B2D0983C91392632B4291C517AA4 817664 ----a-w- C:\Windows\Sysnative\ieapfltr.dll 2014-02-13 02:00:20 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\Sysnative\ieetwcollector.exe 2014-02-13 02:00:20 D016F5092E4FFC41147E8555A71D2DDE 23170048 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-02-13 02:00:20 C1E2C16D58D76323800C3EE5E2C5095A 66048 ----a-w- C:\Windows\Sysnative\iesetup.dll 2014-02-13 02:00:20 3906C9640406FC0FC00A324947C74893 708608 ----a-w- C:\Windows\Sysnative\jscript9diag.dll 2014-02-13 02:00:20 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\Sysnative\ieUnatt.exe 2014-02-13 02:00:19 83296DE8CFFEADA636DCC1AB2E3BF643 2041856 ----a-w- C:\Windows\Sysnative\inetcpl.cpl 2014-02-13 02:00:19 6300AD525D639CECBB3D144B6D7B30F9 2765824 ----a-w- C:\Windows\Sysnative\iertutil.dll 2014-02-13 02:00:19 263B6E451526A90FF8B1CEC759F22956 2334208 ----a-w- C:\Windows\Sysnative\wininet.dll 2014-02-13 02:00:19 22874047B810B5B174C68ACD7C0B6510 1393664 ----a-w- C:\Windows\Sysnative\urlmon.dll 2014-02-13 02:00:18 DB02F4D37E5F7F07A0D0F9FAA68249EE 13051392 ----a-w- C:\Windows\Sysnative\ieframe.dll 2014-02-13 02:00:17 5922EEA922D3AD686342F866CAEE851F 5768704 ----a-w- C:\Windows\Sysnative\jscript9.dll 2014-02-12 22:31:30 CD2C20CC3B385A32701F78C0ACBBE9F3 2048 ----a-w- C:\Windows\Sysnative\msxml3r.dll 2014-02-12 22:31:30 0D298133C359AB8CB9EB4FA178BF3947 1882112 ----a-w- C:\Windows\Sysnative\msxml3.dll 2014-02-12 22:30:55 E8710B5DDA963E6BA198DF5FB209E72A 2565120 ----a-w- C:\Windows\Sysnative\d3d10warp.dll 2014-02-12 22:30:55 C676E5EA388AF7C4C031F56F9B42E362 3928064 ----a-w- C:\Windows\Sysnative\d2d1.dll ====== C:\Windows\Sysnative\drivers ===== 2014-01-15 17:51:06 F7FFDF2A1D19A76A87759126B244C816 53248 ----a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-01-15 17:51:06 D7322DA647332AB0FA3809555BB04325 325120 ----a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-01-15 17:51:06 C1A8966E0D09BFB501045105B30D86F2 25600 ----a-w- C:\Windows\Sysnative\drivers\usbohci.sys 2014-01-15 17:51:06 91D3C92A44FC682DD791147604E79152 99840 ----a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-01-15 17:51:06 2E682DCE4319A90E02A327F8A427544A 30720 ----a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-01-15 17:51:06 245FE7FC634D6A993E682E0A9EBA4ABB 343040 ----a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-01-15 17:51:06 1A13DCABD19D093B4D3949CE33EF1FA1 7808 ----a-w- C:\Windows\Sysnative\drivers\usbd.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2014-02-04 23:21:31 -------- d-----w- C:\PROGRA~2\Mozilla Thunderbird ======= C: ===== ====== C:\Users\maddin\AppData\Roaming ====== ====== C:\Users\maddin ====== ====== C: exe-files == 2014-02-13 02:00:21 9E8F9FDD407DDE997965EEFD9E635CCF 469504 ----a-w- C:\Program Files (x86)\Internet Explorer\ieinstal.exe 2014-02-13 02:00:21 27516B54E116D5EF8B0129B5C829A87C 218624 ----a-w- C:\Windows\System32\ie4uinit.exe 2014-02-13 02:00:20 E129D34089E70215B65EA611F802FA9A 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe 2014-02-13 02:00:20 AFAB9B381886ABE3490689B7633A858F 482816 ----a-w- C:\Program Files\Internet Explorer\ieinstal.exe 2014-02-13 02:00:20 7D6B20C69CC8EECB8F31D4FAF913BBE8 112128 ----a-w- C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 02:00:20 338415F2E9A188875B6E43B5269620B0 139264 ----a-w- C:\Windows\System32\ieUnatt.exe 2014-02-13 02:00:19 C6E1178294BDEAB1CACF50427688DF05 806104 ----a-w- C:\Program Files\Internet Explorer\iexplore.exe 2014-02-13 02:00:19 4263F6C131E513CEA1AE82B5B81A4E1A 808152 ----a-w- C:\Program Files (x86)\Internet Explorer\iexplore.exe 2014-02-12 20:44:37 F00F3F47062646F900AA327B1D5CA3A1 166912 ----a-w- C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1421330230-1166473182-2705663632-1001\Software\Microsoft\Windows\CurrentVersion\Run] "CAEC.tmp"="C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "IMSS"="C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" "SwitchBoard"="C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" "AdobeCS5ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe -launchedbylogin" "FreePDF Assistant"="C:\Program Files (x86)\FreePDF_XP\fpassist.exe" "CorelDRAW Graphics Suite 11b"="C:\Program Files (x86)\Corel\Corel Graphics 11\Register\registration.exe /title=CorelDRAW Graphics Suite 11 /date=112411 serial=DR11WBL-2155594-HXE" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CAEC.tmp"="C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "IntelPROSet"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe /tf Intel PROSet/Wireless" "DBRMTray"="C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe" "NVHotkey"="rundll32.exe C:\Windows\system32\nvHotkey.dll,Start" "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "DBRMTray"="C:\Dell\DBRM\Reminder\TrayApp.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeAAMUpdater-1.0] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AdobeAAMUpdater-1.0" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Apoint] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Apoint" "hkey"="HKLM" "command"="C:\\Program Files\\DellTPad\\Apoint.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CanonMyPrinter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CanonMyPrinter" "hkey"="HKLM" "command"="C:\\Program Files\\Canon\\MyPrinter\\BJMyPrt.exe /logon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CnwiDeviceAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CnwiDeviceAgent" "hkey"="HKLM" "command"="C:\\Program Files\\Canon\\imagePROGRAFStatusMonitor\\cnwida.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dell Webcam Central] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Dell Webcam Central" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Dell Webcam\\Dell Webcam Central\\WebcamDell2.exe\" /mode2" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Desktop Disc Tool] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Desktop Disc Tool" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Roxio\\OEM\\Roxio Burn\\RoxioBurnLauncher.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\FreeFallProtection] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="FreeFallProtection" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\STMicroelectronics\\AccelerometerP11\\FF_Protection.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PDVD9LanguageShortcut] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVD9LanguageShortcut" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\CyberLink\\PowerDVD9\\Language\\Language.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl9] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RemoteControl9" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\CyberLink\\PowerDVD9\\PDVD9Serv.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RoxWatchTray] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RoxWatchTray" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Roxio Shared\\OEM\\12.0\\SharedCOM\\RoxWatchTray12OEM.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\CineForm Status.lnk" "backup"="C:\\Windows\\pss\\CineForm Status.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~2\\CineForm\\Tools\\GOPROC~1.EXE " "item"="CineForm Status" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GV LicenseManager.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\GV LicenseManager.lnk" "backup"="C:\\Windows\\pss\\GV LicenseManager.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~2\\GRASSV~1\\GVLICE~1\\APPMAI~1.EXE " "item"="GV LicenseManager" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^imagePROGRAF Status Monitor.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\imagePROGRAF Status Monitor.lnk" "backup"="C:\\Windows\\pss\\imagePROGRAF Status Monitor.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~1\\Canon\\IMAGEP~1\\cnwism.exe /w" "item"="imagePROGRAF Status Monitor" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AESTFilters] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Canon imagePROGRAF Status Monitor] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Credential Vault Host Control Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\Credential Vault Host Storage] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RoxMediaDB12OEM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\RoxWatch12] ==== Startup Folders ====================== 2012-03-22 17:18:15 834 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk 2012-03-22 17:18:15 2026 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell System Manager.lnk 2012-03-22 17:18:15 1353 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Spyder3Utility.lnk ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-ms2p5-maddin" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\SysNative\tasks\{0C4D7B98-6EBB-4731-ADAA-C91447093380}" [D:\Temp\Delpart.exe] "C:\Windows\SysNative\tasks\{2FE67FED-22CF-4EC7-8D6D-A466E4A80B3E}" [C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe] "C:\Windows\SysNative\tasks\{D3D457AC-3188-4F74-BF49-9367FBD5CCA1}" [D:\Temp\Delpart.exe] "C:\Windows\SysNative\tasks\{DC334E4C-3EA2-4AF3-88BC-94B721D8EC8A}" [C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions ====================== ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} ==== Firefox Plugins ====================== Profilepath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default 4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://g.uk.msn.com/USREL/8" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{49606DC7-976D-4030-A74E-9FB5C842FA68}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://g.uk.msn.com/USREL/8" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {49606DC7-976D-4030-A74E-9FB5C842FA68} Unknown Url="Not_Found" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1421330230-1166473182-2705663632-1001\Software\Microsoft\Internet Explorer\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\maddin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\maddin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\maddin\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\maddin\AppData\Local\Mozilla\Firefox\Profiles\xcc0q5jk.default\Cache emptied successfully ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2 folders=5 345 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\maddin\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\maddin\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 14.02.2014 at 2:41:20,27 ====================== sorry, mein erster beitrag, ich bitte um nachsicht, falls ich was falsch gemacht habe. danke und gruß martin |
14.02.2014, 06:26 | #2 |
/// the machine /// TB-Ausbilder | versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
14.02.2014, 08:43 | #3 |
| versehentlich zip-anhang einer email geöffnet und .exe ausgeführt guten morgen,
__________________danke für die schnelle antwort. hier die beiden logfiles: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01 Ran by maddin (administrator) on MS2P5 on 14-02-2014 08:37:54 Running from D:\Temp Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Dell Inc.) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe (Intel Corporation) C:\Windows\system32\IProsetMonitor.exe (CANON INC.) C:\Windows\system32\cnwiols6.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe (O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe () c:\Windows\SysWOW64\srvany.exe (O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.) HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1934608 2010-12-23] (Intel(R) Corporation) HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation) HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [335976 2011-08-03] (NVIDIA Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [CorelDRAW Graphics Suite 11b] - C:\Program Files (x86)\Corel\Corel Graphics 11\Register\registration.exe /title="CorelDRAW Graphics Suite 11" /date=112411 serial=DR11WBL-2155594-HXE HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\RunOnce: [DBRMTray] - C:\Dell\DBRM\Reminder\TrayApp.exe [7168 2010-02-05] (Microsoft) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.) HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\Run: [AdobeBridge] - [X] HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\Run: [CAEC.tmp] - C:\Users\maddin\AppData\Local\Temp\CAEC.tmp.exe <===== ATTENTION HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: G - G:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {1d21dd65-4547-11e3-857e-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {1d21dd68-4547-11e3-857e-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {22e3c9fb-e1ec-11e0-aa0c-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {22e3c9fe-e1ec-11e0-aa0c-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {2c49e9a9-d9dd-11e0-ab33-d067e535e73a} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {30e281d1-e614-11e0-b39d-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {30e281fe-e614-11e0-b39d-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {5149e011-30fa-11e3-bcfd-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {5543e75e-e158-11e0-9a49-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {5543e76e-e158-11e0-9a49-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {6385fb0d-e0a7-11e0-9a28-247703030988} - F:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {6385fb0f-e0a7-11e0-9a28-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {6385fb14-e0a7-11e0-9a28-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {7d345f3a-d399-11e0-ab52-d067e535e73a} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {7d345f3e-d399-11e0-ab52-d067e535e73a} - G:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {a44b1a51-dfa8-11e0-99bd-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {b639d855-6982-11e3-849e-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {b639d85a-6982-11e3-849e-247703030988} - G:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {c6193b4e-d657-11e0-ab3f-247703030988} - F:\AutoRun.exe HKU\S-1-5-21-1421330230-1166473182-2705663632-1001\...\MountPoints2: {f85593fd-3313-11e3-bc0a-247703030988} - F:\AutoRun.exe AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [240232 2011-08-03] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201320 2011-08-03] (NVIDIA Corporation) Lsa: [Authentication Packages] msv1_0 wvauth ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USREL/8 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/USREL/8 SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-30] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-22] ==================== Services (Whitelisted) ================= S4 Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [713488 2009-10-09] (CANON INC) R2 iPFDeviceAgentService; C:\Windows\system32\cnwiols6.exe [210944 2008-12-08] (CANON INC.) R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] () S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () R2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2012-06-29] (Grass Valley K.K.) S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-14 08:37 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST 2014-02-14 03:10 - 2014-02-14 03:11 - 00000000 ____D () C:\AdwCleaner 2014-02-14 02:40 - 2014-02-14 02:32 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-14 02:32 - 2014-02-14 02:41 - 00023557 _____ () C:\zoek-results.log 2014-02-14 02:30 - 2014-02-14 03:01 - 00000000 ____D () C:\zoek_backup 2014-02-13 03:00 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 03:00 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 03:00 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 03:00 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 03:00 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 03:00 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 03:00 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 03:00 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 03:00 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 03:00 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 03:00 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 03:00 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 03:00 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 03:00 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 03:00 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 03:00 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 03:00 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 03:00 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 03:00 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 03:00 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 03:00 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 03:00 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 03:00 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 03:00 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 03:00 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 03:00 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 03:00 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 03:00 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 03:00 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 03:00 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 03:00 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 03:00 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 03:00 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 03:00 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 03:00 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 03:00 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 03:00 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 03:00 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 03:00 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 03:00 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 03:00 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 23:31 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 23:31 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 23:31 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 23:31 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 23:30 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 23:30 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 23:30 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 23:30 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk 2014-02-05 00:21 - 2014-02-05 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 18:51 - 2013-11-27 02:42 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 18:51 - 2013-11-27 02:42 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 18:51 - 2013-11-27 02:42 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 18:51 - 2013-11-27 02:42 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 18:51 - 2013-11-27 02:42 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 18:51 - 2013-11-27 02:42 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 18:51 - 2013-11-27 02:42 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 18:50 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-02-14 08:37 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST 2014-02-14 08:37 - 2010-11-21 07:50 - 00697082 _____ () C:\Windows\system32\perfh007.dat 2014-02-14 08:37 - 2010-11-21 07:50 - 00148346 _____ () C:\Windows\system32\perfc007.dat 2014-02-14 08:37 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-14 08:36 - 2011-08-24 17:32 - 01747097 _____ () C:\Windows\WindowsUpdate.log 2014-02-14 08:33 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-14 08:33 - 2009-07-14 05:51 - 00232039 _____ () C:\Windows\setupact.log 2014-02-14 03:19 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-14 03:19 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-14 03:11 - 2014-02-14 03:10 - 00000000 ____D () C:\AdwCleaner 2014-02-14 03:01 - 2014-02-14 02:30 - 00000000 ____D () C:\zoek_backup 2014-02-14 02:41 - 2014-02-14 02:32 - 00023557 _____ () C:\zoek-results.log 2014-02-14 02:41 - 2010-11-21 04:47 - 00028706 _____ () C:\Windows\PFRO.log 2014-02-14 02:32 - 2014-02-14 02:40 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-13 03:04 - 2011-02-11 18:45 - 01591234 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk 2014-02-10 23:02 - 2013-03-22 14:55 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-02-06 13:16 - 2014-02-13 03:00 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 03:00 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 03:00 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 03:00 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 03:00 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 03:00 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 03:00 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 03:00 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 03:00 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 03:00 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 03:00 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 03:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 03:00 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 03:00 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 03:00 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 03:00 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 10:26 - 2011-09-11 14:19 - 00000000 ____D () C:\Users\maddin\AppData\Local\FreePDF_XP 2014-02-05 09:30 - 2012-10-15 14:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-05 08:11 - 2014-02-05 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-01 23:46 - 2011-08-31 01:16 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\IrfanView 2014-01-31 23:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-28 00:21 - 2011-11-20 00:11 - 00012288 _____ () C:\Users\maddin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-26 09:17 - 2013-10-21 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-26 09:11 - 2013-06-25 17:19 - 00000000 ____D () C:\Program Files (x86)\Java 2014-01-16 08:33 - 2009-07-14 05:45 - 05131376 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-16 03:01 - 2013-08-14 06:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-16 03:00 - 2011-09-04 13:42 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\maddin\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 11:55 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-02-2014 01 Ran by maddin at 2014-02-14 08:38:06 Running from D:\Temp Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) AccelerometerP11 (x32 Version: 2.00.10.22 - STMicroelectronics) Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Hidden Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden Adobe Community Help (x32 Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Flash Player 10 ActiveX (x32 Version: 10.3.181.23 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS5 (x32 Version: 12.0 - Adobe Systems Incorporated) BioAPI Framework (Version: 1.0.2 - Dell Inc.) Hidden Canon Inkjet Printer Driver Add-On Module V2.00 (Version: - ) Canon My Printer (x32 Version: - ) Canon RAW Codec (x32 Version: 1.8.0.68 - Canon Inc.) Canon Utilities EOS Utility (x32 Version: 2.11.2.0 - Canon Inc.) Canon Utilities Picture Style Editor (x32 Version: 1.10.1.0 - Canon Inc.) CanoScan Toolbox Ver4.9 (x32 Version: - ) Color Efex Pro 3.0 Complete (x32 Version: 3.1.1.0 - Nik Software, Inc.) Color Efex Pro 4 (x32 Version: 4.0.0.2 - Nik Software, Inc.) CorelDRAW Home & Student Suite X6 - BR (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Capture (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Common (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Connect (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Custom Data (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - CZ (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - DE (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Draw (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - EN (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - ES (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Extra Content (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Filters (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - FontNav (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - FR (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - IPM (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - IT (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - NL (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - PHOTO-PAINT (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - PL (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Redist (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - RU (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Setup Files (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - VideoBrowser (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Writing Tools (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 (x32 Version: 16.1.0.843 - Corel Corporation) Custom (Version: 12.34.56.789 - Wave Systems Corp.) Hidden CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.) CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery Manager (Version: 1.3.1 - Dell Inc.) Dell ControlVault Host Components Installer 64 bit (Version: 2.0.20.159 - Broadcom Corporation) Hidden Dell Data Protection | Access (Version: 01.01.00.085 - Wave Systems Corp) Hidden Dell Data Protection | Access (x32 Version: 2.0.00000.085 - Dell Inc.) Dell Data Protection | Access | Drivers (x32 Version: 1.00.011 - Dell Inc.) Dell Data Protection | Access | Middleware (x32 Version: 1.00.005 - Dell Inc.) Dell Edoc Viewer (Version: 1.0.0 - Dell Inc) Dell System Manager (Version: 1.6.00000 - Dell Inc.) Dell Touchpad (Version: 7.1208.101.118 - ALPS ELECTRIC CO., LTD.) Dell Webcam Central (x32 Version: 1.40.28 - Creative Technology Ltd) DellAccess (Version: 01.01.00.053 - Wave Systems Corp.) Hidden Dfine 2.0 (x32 Version: 2.1.0.7 - Nik Software, Inc.) DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden EDIUS (x32 Version: 6.51 - Grass Valley K.K.) EDIUS Codec Option 6.51 (x32 Version: 6.51 - Grass Valley K.K.) EDIUS DVD Menu Style 1.00 (x32 Version: 1.00 - Grass Valley K.K.) EMBASSY Security Center (Version: 04.03.00.067 - Wave Systems Corp.) Hidden FreePDF (Remove only) (x32 Version: - ) Gemalto (Version: 01.64.01.0010 - Wave Systems Corp) Hidden GoPro CineForm Studio 1.2.1 (x32 Version: 1.2.1 - CineForm, Inc & GoPro, Inc.) GPL Ghostscript (Version: 9.04 - Artifex Software Inc.) GV LicenseManager 1.01 (x32 Version: 1.01 - Grass Valley K.K.) HDR Efex Pro (x32 Version: 1.2.0.0 - Nik Software, Inc.) HDR Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.) Helicon Focus 5.2.9 (x32 Version: - Helicon Soft Ltd.) imagePROGRAF Status Monitor (x32 Version: 4.30 - Canon) Intel PROSet Wireless (Version: - ) Hidden Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation) Intel(R) Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel) Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel) Hidden Intel(R) Processor Graphics (x32 Version: 8.15.10.2266 - Intel Corporation) Intel(R) PROSet/Wireless WiFi-Software (Version: 14.00.20110 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008 - Intel Corporation) iPF6300 Media Configuration Tool (x32 Version: 4.02.02 - Canon) IrfanView (remove only) (x32 Version: 4.28 - Irfan Skiljan) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Business 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (x32 Version: 4.0.50401.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Mobile Partner (x32 Version: 11.300.05.03.40 - Huawei Technologies Co.,Ltd) Mozilla Firefox 10.0.2 (x86 de) (x32 Version: 10.0.2 - Mozilla) Mozilla Maintenance Service (x32 Version: 24.3.0 - Mozilla) Mozilla Thunderbird 24.3.0 (x86 de) (x32 Version: 24.3.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) No23 Recorder (x32 Version: 2.1.0.3 - No23) No23 Recorder (x32 Version: 2.1.0.3 - No23) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Controller-Treiber 285.62 (Version: 285.62 - NVIDIA Corporation) NVIDIA Grafiktreiber 280.26 (Version: 280.26 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.2.24.0 (Version: 1.2.24.0 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.46.235 - NVIDIA Corporation) Hidden NVIDIA nView 136.02 (Version: 136.02 - NVIDIA Corporation) NVIDIA nView Desktop Manager (Version: 6.14.10.13594 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation) NVIDIA Systemsteuerung 280.26 (Version: 280.26 - NVIDIA Corporation) Hidden O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) Hidden PC-CCID (Version: 2.0.0 - Gemalto) Hidden PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden PDF-XChange Viewer (Version: 2.5.197.0 - Tracker Software Products Ltd.) PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden Preboot Manager (Version: 03.03.00.049 - Wave Systems Corp.) Hidden Private Information Manager (Version: 07.01.00.007 - Wave Systems Corp.) Hidden proDAD Mercalli 2.0 (x32 Version: 2.0.105.1 - proDAD GmbH) PTGui Pro 9.1.3 (x32 Version: - New House Internet Services B.V.) QuickTime Alternative 1.81 (x32 Version: 1.81 - ) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden RedMon - Redirection Port Monitor (Version: - ) Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden Roxio Burn (x32 Version: 1.8 - Roxio) Hidden Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden Roxio Creator Starter (x32 Version: 12.1.77.0 - Roxio) Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Samsung ML-371x Series (x32 Version: 1.27 (16.01.2013) - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (x32 Version: 1.01.00.04 - Samsung Electronics Co., Ltd.) Sharpener Pro 3.0 (x32 Version: 3.0.0.5 - Nik Software, Inc.) Silver Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.) Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden SPBA 5.9 (Version: 5.9.4.6686 - UPEK Inc.) Hidden Spyder3Elite (x32 Version: - ) Spyder3Studio SR (x32 Version: - ) Trusted Drive Manager (Version: 4.0.0.512 - Wave Systems Corp.) Hidden Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation) Upek Touchchip Fingerprint Reader (Version: 1.2.004 - Dell Inc.) Hidden Viveza 2 (x32 Version: 2.0.0.4 - Nik Software, Inc.) Wave Infrastructure Installer (Version: 07.66.40.0008 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.014 - Wave Systems Corp) Hidden WIDCOMM Bluetooth Software (Version: 6.3.0.7900 - Broadcom Corporation) Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 ) (Version: 03/07/2012 - GoPro) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dell Inc. PBADRV System (09/11/2009 1.0.1.6) (Version: 09/11/2009 1.0.1.6 - Dell Inc.) Xvid Video Codec (x32 Version: 1.3.2 - Xvid Team) ==================== Restore Points ========================= 14-01-2014 16:15:30 Windows Update 16-01-2014 02:00:10 Windows Update 24-01-2014 08:53:37 Geplanter Prüfpunkt 25-01-2014 00:07:16 Windows Update 26-01-2014 08:10:55 Installed Java 7 Update 51 28-01-2014 17:23:36 Windows Update 01-02-2014 09:22:25 Windows Update 07-02-2014 20:49:41 Windows Update 11-02-2014 07:30:39 Windows Update 13-02-2014 02:00:11 Windows Update 14-02-2014 01:32:20 zoek.exe restore point ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {323FA560-8206-4AE6-8ADD-7D835D50C4B9} - System32\Tasks\{0C4D7B98-6EBB-4731-ADAA-C91447093380} => D:\Temp\Delpart.exe Task: {B3EEABE8-B3B6-4649-B2B9-5C4E76514513} - System32\Tasks\{DC334E4C-3EA2-4AF3-88BC-94B721D8EC8A} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe Task: {B8F007C2-DE44-4FA8-A7FB-ECFC52D3FED0} - System32\Tasks\AdobeAAMUpdater-1.0-ms2p5-maddin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {DADBFA70-8776-487C-9ED3-31B4521C6AB8} - System32\Tasks\{D3D457AC-3188-4F74-BF49-9367FBD5CCA1} => D:\Temp\Delpart.exe Task: {DCE1F4B1-68A1-4173-8549-4811D2E7AC61} - System32\Tasks\{2FE67FED-22CF-4EC7-8D6D-A466E4A80B3E} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe ==================== Loaded Modules (whitelisted) ============= 2010-12-23 19:33 - 2010-12-23 19:33 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-02-08 07:41 - 2011-02-08 07:41 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2008-12-05 10:05 - 2008-12-11 17:40 - 08119870 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe 2008-12-11 17:43 - 2008-12-11 17:29 - 00131072 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CSensor.dll 2008-12-11 17:43 - 2008-12-11 17:28 - 00331776 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CGamma.dll 2014-02-05 00:21 - 2014-02-05 00:21 - 03019376 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2014-02-05 00:21 - 2014-02-05 00:21 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2014-02-05 00:21 - 2014-02-05 00:21 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2011-09-01 19:13 - 2012-02-23 10:44 - 01911768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-10-21 22:14 - 2013-10-21 22:14 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\ProgramData\Temp:054203E4 AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: AESTFilters => 2 MSCONFIG\Services: Canon imagePROGRAF Status Monitor => 2 MSCONFIG\Services: Credential Vault Host Control Service => 2 MSCONFIG\Services: Credential Vault Host Storage => 2 MSCONFIG\Services: RoxMediaDB12OEM => 3 MSCONFIG\Services: RoxWatch12 => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk => C:\Windows\pss\CineForm Status.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GV LicenseManager.lnk => C:\Windows\pss\GV LicenseManager.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^imagePROGRAF Status Monitor.lnk => C:\Windows\pss\imagePROGRAF Status Monitor.lnk.CommonStartup MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CnwiDeviceAgent => C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: FreeFallProtection => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe MSCONFIG\startupreg: PDVD9LanguageShortcut => "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" MSCONFIG\startupreg: RemoteControl9 => "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/14/2014 08:33:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2014 03:12:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2014 02:41:12 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2014 05:48:03 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2014 03:11:33 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2014 00:30:51 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (02/12/2014 10:08:34 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (02/12/2014 09:36:19 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/12/2014 08:11:05 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/11/2014 04:24:10 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (02/14/2014 08:34:25 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (02/14/2014 08:33:24 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (02/14/2014 03:13:40 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (02/14/2014 03:12:39 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (02/14/2014 02:42:12 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (02/14/2014 02:41:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (02/14/2014 02:37:50 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/14/2014 02:37:49 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/14/2014 02:37:49 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/14/2014 02:37:49 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Microsoft Office Sessions: ========================= Error: (02/14/2014 08:33:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2014 03:12:40 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/14/2014 02:41:12 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2014 05:48:03 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2014 03:11:33 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/13/2014 00:30:51 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (02/12/2014 10:08:34 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (02/12/2014 09:36:19 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/12/2014 08:11:05 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/11/2014 04:24:10 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 22% Total physical RAM: 8148.9 MB Available physical RAM: 6278.09 MB Total Pagefile: 16295.98 MB Available Pagefile: 14252.97 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:225.67 GB) (Free:156.96 GB) NTFS Drive d: (Daten) (Fixed) (Total:238.47 GB) (Free:121.92 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 238 GB) (Disk ID: D1E3F7F7) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=13 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=226 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: D1E3F7C8) Partition 1: (Not Active) - (Size=238 GB) - (Type=07 NTFS) ==================== End Of Log ============================ was mir aufgefallen ist: vom zeitzunkt meiner unüberlegten aktion her ist das "CAEC.tmp.exe" verdächtig ! vielleicht hilft die information. danke und gruß martin Geändert von DeppoDepp (14.02.2014 um 09:05 Uhr) |
15.02.2014, 09:32 | #4 |
/// the machine /// TB-Ausbilder | versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.02.2014, 11:25 | #5 |
| versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hallo und danke für die antwort, hier das logfile. es gab keine fehlermeldungen. Combofix Logfile: Code:
ATTFilter ComboFix 14-02-14.01 - maddin 15.02.2014 11:10:37.1.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8149.6090 [GMT 1:00] ausgeführt von:: c:\users\maddin\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\windows\SysWow64\cseDVH.dll . . ((((((((((((((((((((((( Dateien erstellt von 2014-01-15 bis 2014-02-15 )))))))))))))))))))))))))))))) . . 2014-02-14 14:35 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D73B5779-DAB3-4075-B25F-373F10A43BEE}\mpengine.dll 2014-02-14 07:37 . 2014-02-14 07:38 -------- d-----w- C:\FRST 2014-02-14 02:10 . 2014-02-14 02:11 -------- d-----w- C:\AdwCleaner 2014-02-14 01:40 . 2014-02-15 10:13 -------- d-----w- c:\users\maddin\AppData\Local\Temp 2014-02-14 01:40 . 2014-02-14 01:32 24064 ----a-w- c:\windows\zoek-delete.exe 2014-02-14 01:30 . 2014-02-14 02:01 -------- d-----w- C:\zoek_backup 2014-02-12 22:31 . 2013-12-06 02:30 2048 ----a-w- c:\windows\system32\msxml3r.dll 2014-02-12 22:31 . 2013-12-06 02:30 1882112 ----a-w- c:\windows\system32\msxml3.dll 2014-02-12 22:31 . 2013-12-06 02:02 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll 2014-02-12 22:31 . 2013-12-06 02:02 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll 2014-02-12 22:30 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2014-02-12 22:30 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2014-02-12 22:30 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2014-02-12 22:30 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll 2014-02-04 23:21 . 2014-02-05 07:11 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-01-16 02:00 . 2011-09-04 12:42 86054176 ----a-w- c:\windows\system32\MRT.exe 2013-12-18 20:09 . 2013-06-25 16:19 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-12-18 05:13 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe 2013-11-27 01:42 . 2014-01-15 17:51 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys 2013-11-27 01:42 . 2014-01-15 17:51 99840 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2013-11-27 01:42 . 2014-01-15 17:51 325120 ----a-w- c:\windows\system32\drivers\usbport.sys 2013-11-27 01:42 . 2014-01-15 17:51 53248 ----a-w- c:\windows\system32\drivers\usbehci.sys 2013-11-27 01:42 . 2014-01-15 17:51 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys 2013-11-27 01:42 . 2014-01-15 17:51 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2013-11-27 01:42 . 2014-01-15 17:51 7808 ----a-w- c:\windows\system32\drivers\usbd.sys 2013-11-26 10:32 . 2014-01-15 17:50 3156480 ----a-w- c:\windows\system32\win32k.sys 2013-11-20 00:57 . 2013-11-20 00:57 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-11-20 00:57 . 2013-11-20 00:57 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-11-20 00:57 . 2013-11-20 00:57 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2013-11-20 00:57 . 2013-11-20 00:57 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2013-11-20 00:57 . 2013-11-20 00:57 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-11-20 00:57 . 2013-11-20 00:57 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2013-11-20 00:57 . 2013-11-20 00:57 337408 ----a-w- c:\windows\SysWow64\html.iec 2013-11-20 00:57 . 2013-11-20 00:57 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-11-20 00:57 . 2013-11-20 00:57 235008 ----a-w- c:\windows\system32\elshyph.dll 2013-11-20 00:57 . 2013-11-20 00:57 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2013-11-20 00:57 . 2013-11-20 00:57 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-11-20 00:57 . 2013-11-20 00:57 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2013-11-20 00:57 . 2013-11-20 00:57 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-11-20 00:57 . 2013-11-20 00:57 942592 ----a-w- c:\windows\system32\jsIntl.dll 2013-11-20 00:57 . 2013-11-20 00:57 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-11-20 00:57 . 2013-11-20 00:57 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2013-11-20 00:57 . 2013-11-20 00:57 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2013-11-20 00:57 . 2013-11-20 00:57 84992 ----a-w- c:\windows\system32\mshtmled.dll 2013-11-20 00:57 . 2013-11-20 00:57 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2013-11-20 00:57 . 2013-11-20 00:57 81408 ----a-w- c:\windows\system32\icardie.dll 2013-11-20 00:57 . 2013-11-20 00:57 774144 ----a-w- c:\windows\system32\jscript.dll 2013-11-20 00:57 . 2013-11-20 00:57 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-11-20 00:57 . 2013-11-20 00:57 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-11-20 00:57 . 2013-11-20 00:57 62464 ----a-w- c:\windows\system32\pngfilt.dll 2013-11-20 00:57 . 2013-11-20 00:57 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2013-11-20 00:57 . 2013-11-20 00:57 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2013-11-20 00:57 . 2013-11-20 00:57 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-11-20 00:57 . 2013-11-20 00:57 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-11-20 00:57 . 2013-11-20 00:57 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-11-20 00:57 . 2013-11-20 00:57 48128 ----a-w- c:\windows\system32\imgutil.dll 2013-11-20 00:57 . 2013-11-20 00:57 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2013-11-20 00:57 . 2013-11-20 00:57 413696 ----a-w- c:\windows\system32\html.iec 2013-11-20 00:57 . 2013-11-20 00:57 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-20 00:57 . 2013-11-20 00:57 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-11-20 00:57 . 2013-11-20 00:57 30208 ----a-w- c:\windows\system32\licmgr10.dll 2013-11-20 00:57 . 2013-11-20 00:57 296960 ----a-w- c:\windows\system32\dxtrans.dll 2013-11-20 00:57 . 2013-11-20 00:57 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2013-11-20 00:57 . 2013-11-20 00:57 247808 ----a-w- c:\windows\system32\msls31.dll 2013-11-20 00:57 . 2013-11-20 00:57 243200 ----a-w- c:\windows\system32\webcheck.dll 2013-11-20 00:57 . 2013-11-20 00:57 235520 ----a-w- c:\windows\system32\url.dll 2013-11-20 00:57 . 2013-11-20 00:57 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-11-20 00:57 . 2013-11-20 00:57 147968 ----a-w- c:\windows\system32\occache.dll 2013-11-20 00:57 . 2013-11-20 00:57 143872 ----a-w- c:\windows\system32\wextract.exe 2013-11-20 00:57 . 2013-11-20 00:57 13824 ----a-w- c:\windows\system32\mshta.exe 2013-11-20 00:57 . 2013-11-20 00:57 135680 ----a-w- c:\windows\system32\iepeers.dll 2013-11-20 00:57 . 2013-11-20 00:57 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2013-11-20 00:57 . 2013-11-20 00:57 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2013-11-20 00:57 . 2013-11-20 00:57 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-11-20 00:57 . 2013-11-20 00:57 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-11-20 00:57 . 2013-11-20 00:57 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-11-20 00:57 . 2013-11-20 00:57 105984 ----a-w- c:\windows\system32\iesysprep.dll 2013-11-20 00:57 . 2013-11-20 00:57 101376 ----a-w- c:\windows\system32\inseng.dll 2013-11-20 00:57 . 2013-11-20 00:57 878080 ----a-w- c:\windows\system32\advapi32.dll 2013-11-20 00:57 . 2013-11-20 00:57 859648 ----a-w- c:\windows\system32\tdh.dll 2013-11-20 00:57 . 2013-11-20 00:57 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2013-11-20 00:57 . 2013-11-20 00:57 640512 ----a-w- c:\windows\SysWow64\advapi32.dll 2013-11-20 00:57 . 2013-11-20 00:57 619520 ----a-w- c:\windows\SysWow64\tdh.dll 2013-11-20 00:57 . 2013-11-20 00:57 5549504 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-11-20 00:57 . 2013-11-20 00:57 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2013-11-20 00:57 . 2013-11-20 00:57 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-11-20 00:57 . 2013-11-20 00:57 3969472 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-11-20 00:57 . 2013-11-20 00:57 3914176 ----a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-11-20 00:57 . 2013-11-20 00:57 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2013-11-20 00:57 . 2013-11-20 00:57 243712 ----a-w- c:\windows\system32\wow64.dll 2013-11-20 00:57 . 2013-11-20 00:57 2048 ----a-w- c:\windows\SysWow64\user.exe 2013-11-20 00:57 . 2013-11-20 00:57 1732032 ----a-w- c:\windows\system32\ntdll.dll 2013-11-20 00:57 . 2013-11-20 00:57 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2013-11-20 00:57 . 2013-11-20 00:57 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll 2013-11-20 00:57 . 2013-11-20 00:57 327168 ----a-w- c:\windows\system32\mswsock.dll 2013-11-20 00:57 . 2013-11-20 00:57 231424 ----a-w- c:\windows\SysWow64\mswsock.dll 2013-11-20 00:57 . 2013-11-20 00:57 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-11-20 00:57 . 2013-11-20 00:57 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-11-20 00:57 . 2013-11-20 00:57 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160] "IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2011-01-17 112152] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432] "FreePDF Assistant"="c:\program files (x86)\FreePDF_XP\fpassist.exe" [2011-02-23 371200] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-2-8 1136928] Dell System Manager.lnk - c:\program files\Dell\Dell System Manager\DCPSysMgr.exe [2011-1-20 1552240] Spyder3Utility.lnk - c:\program files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe [2008-12-5 8119870] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "DisableCAD"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer4"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys;c:\windows\SYSNATIVE\DRIVERS\btwampfl.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys;c:\windows\SYSNATIVE\DRIVERS\netvsc60.sys [x] R3 O2MDFRDR;O2MDFRDR;c:\windows\system32\drivers\O2MDFw7x64.sys;c:\windows\SYSNATIVE\drivers\O2MDFw7x64.sys [x] R3 Spyder3;Datacolor Spyder3;c:\windows\system32\DRIVERS\Spyder3.sys;c:\windows\SYSNATIVE\DRIVERS\Spyder3.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys;c:\windows\SYSNATIVE\DRIVERS\VMBusVideoM.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x] R4 Canon imagePROGRAF Status Monitor;Canon imagePROGRAF Status Monitor;c:\program files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe;c:\program files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [x] R4 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [x] R4 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [x] R4 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x] R4 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x] S1 cdrblock;cdrblock;c:\windows\system32\DRIVERS\cdrblock.sys;c:\windows\SYSNATIVE\DRIVERS\cdrblock.sys [x] S2 dcpsysmgrsvc;Dell System Manager Service;c:\program files\Dell\Dell System Manager\DCPSysMgrSvc.exe;c:\program files\Dell\Dell System Manager\DCPSysMgrSvc.exe [x] S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x] S2 iPFDeviceAgentService;iPF Device Agent Service;c:\windows\system32\cnwiols6.exe;c:\windows\SYSNATIVE\cnwiols6.exe [x] S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x] S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\nlssrv32.exe;c:\windows\SysWOW64\nlssrv32.exe [x] S2 O2SDIOAssist;O2SDIOAssist;c:\windows\SysWOW64\srvany.exe;c:\windows\SysWOW64\srvany.exe [x] S2 ZcfgSvc7;Intel(R) PROSet/Wireless ZeroConfig Service;c:\program files\Intel\WiFi\bin\ZCfgSvc7.exe;c:\program files\Intel\WiFi\bin\ZCfgSvc7.exe [x] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x] S3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys;c:\windows\SYSNATIVE\Drivers\cvusbdrv.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 O2MDRRDR;O2MDRRDR;c:\windows\system32\DRIVERS\O2MDRw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\O2MDRw7x64.sys [x] S3 O2SDJRDR;O2SDJRDR;c:\windows\system32\DRIVERS\o2sdjw7x64.sys;c:\windows\SYSNATIVE\DRIVERS\o2sdjw7x64.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay] @="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}" [HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}] 2010-10-16 21:17 138608 ----a-w- c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay] @="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}" [HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}] 2010-10-16 21:17 138608 ----a-w- c:\program files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-07 525312] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-14 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-14 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-14 418328] "IntelPROSet"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-23 1934608] "DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2011-03-08 227328] "NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-08-03 335976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default\ FF - prefs.js: browser.startup.homepage - www.google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKLM-Run-<NO NAME> - (no file) Wow6432Node-HKLM-Run-CorelDRAW Graphics Suite 11b - c:\program files (x86)\Corel\Corel Graphics 11\Register\registration.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\DRIVERS\o2flash.exe c:\windows\sysWOW64\SDIOAssist.exe c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-02-15 11:16:07 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-02-15 10:16 . Vor Suchlauf: 14 Verzeichnis(se), 167.808.430.080 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 167.072.436.224 Bytes frei . - - End Of File - - B9CEB3D238BF390DDC4C214AC9274597 gruß martin |
16.02.2014, 07:12 | #6 |
/// the machine /// TB-Ausbilder | versehentlich zip-anhang einer email geöffnet und .exe ausgeführt Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> versehentlich zip-anhang einer email geöffnet und .exe ausgeführt |
16.02.2014, 20:16 | #7 |
| versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hallo, hier die logfiles ! Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.02.16.02 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16518 maddin :: MS2P5 [Administrator] 16.02.2014 11:11:00 mbam-log-2014-02-16 (11-11-00).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 243491 Laufzeit: 1 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v3.018 - Bericht erstellt am 16/02/2014 um 11:40:36 # Updated 28/01/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : maddin - MS2P5 # Gestartet von : C:\Users\maddin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 -\\ Mozilla Firefox v10.0.2 (de) [ Datei : C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1372 octets] - [14/02/2014 03:10:24] AdwCleaner[R1].txt - [920 octets] - [16/02/2014 11:21:13] AdwCleaner[R2].txt - [979 octets] - [16/02/2014 11:39:40] AdwCleaner[S0].txt - [1433 octets] - [14/02/2014 03:11:40] AdwCleaner[S1].txt - [901 octets] - [16/02/2014 11:40:36] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [960 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.1 (02.04.2014:1) OS: Windows 7 Professional x64 Ran by maddin on 16.02.2014 at 19:57:06,25 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\maddin\AppData\Roaming\mozilla\firefox\profiles\xcc0q5jk.default\minidumps [41 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 16.02.2014 at 20:00:56,56 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01 Ran by maddin (administrator) on MS2P5 on 16-02-2014 20:04:00 Running from C:\Users\maddin\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Dell Inc.) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe (Intel Corporation) C:\Windows\system32\IProsetMonitor.exe (CANON INC.) C:\Windows\system32\cnwiols6.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe (O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe () c:\Windows\SysWOW64\srvany.exe (O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.) HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1934608 2010-12-23] (Intel(R) Corporation) HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation) HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [335976 2011-08-03] (NVIDIA Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [240232 2011-08-03] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201320 2011-08-03] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USREL/8 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-30] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-22] ==================== Services (Whitelisted) ================= S4 Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [713488 2009-10-09] (CANON INC) R2 iPFDeviceAgentService; C:\Windows\system32\cnwiols6.exe [210944 2008-12-08] (CANON INC.) R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] () S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () R2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2012-06-29] (Grass Valley K.K.) S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-16 20:04 - 2014-02-16 20:04 - 00010804 _____ () C:\Users\maddin\Desktop\FRST.txt 2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt 2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt 2014-02-16 11:20 - 2014-02-16 20:03 - 00002977 _____ () C:\Users\maddin\Desktop\post.txt 2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe 2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-16 11:05 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt 2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt 2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt 2014-02-15 11:10 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-15 11:10 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-15 11:10 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-15 11:09 - 2014-02-15 11:16 - 00000000 ____D () C:\Qoobox 2014-02-15 11:09 - 2014-02-15 11:15 - 00000000 ____D () C:\Windows\erdnt 2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe 2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt 2014-02-14 08:37 - 2014-02-16 20:04 - 00000000 ____D () C:\FRST 2014-02-14 08:37 - 2014-02-14 08:38 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt 2014-02-14 08:36 - 2014-02-14 08:36 - 02152960 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe 2014-02-14 03:10 - 2014-02-16 11:40 - 00000000 ____D () C:\AdwCleaner 2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe 2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip 2014-02-14 02:40 - 2014-02-14 02:32 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-14 02:32 - 2014-02-14 02:41 - 00023557 _____ () C:\zoek-results.log 2014-02-14 02:30 - 2014-02-14 03:01 - 00000000 ____D () C:\zoek_backup 2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe 2014-02-13 03:00 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 03:00 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 03:00 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 03:00 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 03:00 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 03:00 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 03:00 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 03:00 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 03:00 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 03:00 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 03:00 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 03:00 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 03:00 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 03:00 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 03:00 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 03:00 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 03:00 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 03:00 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 03:00 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 03:00 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 03:00 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 03:00 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 03:00 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 03:00 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 03:00 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 03:00 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 03:00 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 03:00 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 03:00 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 03:00 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 03:00 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 03:00 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 03:00 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 03:00 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 03:00 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 03:00 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 03:00 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 03:00 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 03:00 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 03:00 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 03:00 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 23:31 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 23:31 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 23:31 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 23:31 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 23:30 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 23:30 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 23:30 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 23:30 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk 2014-02-05 00:21 - 2014-02-05 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log ==================== One Month Modified Files and Folders ======= 2014-02-16 20:04 - 2014-02-16 20:04 - 00010804 _____ () C:\Users\maddin\Desktop\FRST.txt 2014-02-16 20:04 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST 2014-02-16 20:03 - 2014-02-16 11:20 - 00002977 _____ () C:\Users\maddin\Desktop\post.txt 2014-02-16 20:01 - 2010-11-21 07:50 - 00697082 _____ () C:\Windows\system32\perfh007.dat 2014-02-16 20:01 - 2010-11-21 07:50 - 00148346 _____ () C:\Windows\system32\perfc007.dat 2014-02-16 20:01 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-16 20:01 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-16 20:01 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt 2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-02-16 19:57 - 2011-08-24 17:32 - 01919183 _____ () C:\Windows\WindowsUpdate.log 2014-02-16 19:54 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-16 19:54 - 2009-07-14 05:51 - 00232767 _____ () C:\Windows\setupact.log 2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt 2014-02-16 11:40 - 2014-02-14 03:10 - 00000000 ____D () C:\AdwCleaner 2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe 2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-16 03:01 - 2013-08-14 06:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-16 03:00 - 2011-09-04 13:42 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt 2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt 2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt 2014-02-15 11:16 - 2014-02-15 11:09 - 00000000 ____D () C:\Qoobox 2014-02-15 11:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-15 11:15 - 2014-02-15 11:09 - 00000000 ____D () C:\Windows\erdnt 2014-02-15 11:14 - 2010-11-21 04:47 - 00029252 _____ () C:\Windows\PFRO.log 2014-02-15 11:14 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-15 11:13 - 2009-07-14 03:34 - 74186752 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 44040192 _____ () C:\Windows\system32\config\components.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 21757952 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe 2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt 2014-02-14 08:38 - 2014-02-14 08:37 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt 2014-02-14 08:36 - 2014-02-14 08:36 - 02152960 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe 2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe 2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip 2014-02-14 03:01 - 2014-02-14 02:30 - 00000000 ____D () C:\zoek_backup 2014-02-14 02:41 - 2014-02-14 02:32 - 00023557 _____ () C:\zoek-results.log 2014-02-14 02:32 - 2014-02-14 02:40 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe 2014-02-13 03:04 - 2011-02-11 18:45 - 01591234 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk 2014-02-10 23:02 - 2013-03-22 14:55 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-02-06 13:16 - 2014-02-13 03:00 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 03:00 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 03:00 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 03:00 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 03:00 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 03:00 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 03:00 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 03:00 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 03:00 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 03:00 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 03:00 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 03:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 03:00 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 03:00 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 03:00 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 03:00 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 10:26 - 2011-09-11 14:19 - 00000000 ____D () C:\Users\maddin\AppData\Local\FreePDF_XP 2014-02-05 09:30 - 2012-10-15 14:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-05 08:11 - 2014-02-05 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-01 23:46 - 2011-08-31 01:16 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\IrfanView 2014-01-31 23:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-28 00:21 - 2011-11-20 00:11 - 00012288 _____ () C:\Users\maddin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-26 09:17 - 2013-10-21 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-26 09:11 - 2013-06-25 17:19 - 00000000 ____D () C:\Program Files (x86)\Java Some content of TEMP: ==================== C:\Users\maddin\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 11:55 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-02-2014 01 Ran by maddin at 2014-02-16 20:04:15 Running from C:\Users\maddin\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov) AccelerometerP11 (x32 Version: 2.00.10.22 - STMicroelectronics) Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Hidden Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden Adobe Community Help (x32 Version: 3.0.0.400 - Adobe Systems Incorporated) Adobe Flash Player 10 ActiveX (x32 Version: 10.3.181.23 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS5 (x32 Version: 12.0 - Adobe Systems Incorporated) BioAPI Framework (Version: 1.0.2 - Dell Inc.) Hidden Canon Inkjet Printer Driver Add-On Module V2.00 (Version: - ) Canon My Printer (x32 Version: - ) Canon RAW Codec (x32 Version: 1.8.0.68 - Canon Inc.) Canon Utilities EOS Utility (x32 Version: 2.11.2.0 - Canon Inc.) Canon Utilities Picture Style Editor (x32 Version: 1.10.1.0 - Canon Inc.) CanoScan Toolbox Ver4.9 (x32 Version: - ) Color Efex Pro 3.0 Complete (x32 Version: 3.1.1.0 - Nik Software, Inc.) Color Efex Pro 4 (x32 Version: 4.0.0.2 - Nik Software, Inc.) CorelDRAW Home & Student Suite X6 - BR (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Capture (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Common (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Connect (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Custom Data (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - CZ (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - DE (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Draw (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - EN (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - ES (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Extra Content (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Filters (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - FontNav (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - FR (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - IPM (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - IT (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - NL (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - PHOTO-PAINT (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - PL (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Redist (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - RU (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Setup Files (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - VideoBrowser (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 - Writing Tools (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 (x32 Version: 16.1 - Corel Corporation) Hidden CorelDRAW Home & Student Suite X6 (x32 Version: 16.1.0.843 - Corel Corporation) Custom (Version: 12.34.56.789 - Wave Systems Corp.) Hidden CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.) CyberLink PowerDVD 9.5 (x32 Version: 9.5.1.3225 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Backup and Recovery Manager (Version: 1.3.1 - Dell Inc.) Dell ControlVault Host Components Installer 64 bit (Version: 2.0.20.159 - Broadcom Corporation) Hidden Dell Data Protection | Access (Version: 01.01.00.085 - Wave Systems Corp) Hidden Dell Data Protection | Access (x32 Version: 2.0.00000.085 - Dell Inc.) Dell Data Protection | Access | Drivers (x32 Version: 1.00.011 - Dell Inc.) Dell Data Protection | Access | Middleware (x32 Version: 1.00.005 - Dell Inc.) Dell Edoc Viewer (Version: 1.0.0 - Dell Inc) Dell System Manager (Version: 1.6.00000 - Dell Inc.) Dell Touchpad (Version: 7.1208.101.118 - ALPS ELECTRIC CO., LTD.) Dell Webcam Central (x32 Version: 1.40.28 - Creative Technology Ltd) DellAccess (Version: 01.01.00.053 - Wave Systems Corp.) Hidden Dfine 2.0 (x32 Version: 2.1.0.7 - Nik Software, Inc.) DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden EDIUS (x32 Version: 6.51 - Grass Valley K.K.) EDIUS Codec Option 6.51 (x32 Version: 6.51 - Grass Valley K.K.) EDIUS DVD Menu Style 1.00 (x32 Version: 1.00 - Grass Valley K.K.) EMBASSY Security Center (Version: 04.03.00.067 - Wave Systems Corp.) Hidden FreePDF (Remove only) (x32 Version: - ) Gemalto (Version: 01.64.01.0010 - Wave Systems Corp) Hidden GoPro CineForm Studio 1.2.1 (x32 Version: 1.2.1 - CineForm, Inc & GoPro, Inc.) GPL Ghostscript (Version: 9.04 - Artifex Software Inc.) GV LicenseManager 1.01 (x32 Version: 1.01 - Grass Valley K.K.) HDR Efex Pro (x32 Version: 1.2.0.0 - Nik Software, Inc.) HDR Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.) Helicon Focus 5.2.9 (x32 Version: - Helicon Soft Ltd.) imagePROGRAF Status Monitor (x32 Version: 4.30 - Canon) Intel PROSet Wireless (Version: - ) Hidden Intel(R) Control Center (x32 Version: 1.2.1.1007 - Intel Corporation) Intel(R) Identity Protection Technology 1.1.2.0 (x32 Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144 - Intel Corporation) Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel) Intel(R) Network Connections 15.7.176.1 (Version: 15.7.176.1 - Intel) Hidden Intel(R) Processor Graphics (x32 Version: 8.15.10.2266 - Intel Corporation) Intel(R) PROSet/Wireless WiFi-Software (Version: 14.00.20110 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008 - Intel Corporation) iPF6300 Media Configuration Tool (x32 Version: 4.02.02 - Canon) IrfanView (remove only) (x32 Version: 4.28 - Irfan Skiljan) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 24 (64-bit) (Version: 6.0.240 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Business 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (x32 Version: 4.0.50401.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Mobile Partner (x32 Version: 11.300.05.03.40 - Huawei Technologies Co.,Ltd) Mozilla Firefox 10.0.2 (x86 de) (x32 Version: 10.0.2 - Mozilla) Mozilla Maintenance Service (x32 Version: 24.3.0 - Mozilla) Mozilla Thunderbird 24.3.0 (x86 de) (x32 Version: 24.3.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) No23 Recorder (x32 Version: 2.1.0.3 - No23) No23 Recorder (x32 Version: 2.1.0.3 - No23) Hidden NTRU TCG Software Stack (Version: 2.1.34 - Security Innovation) Hidden NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Controller-Treiber 285.62 (Version: 285.62 - NVIDIA Corporation) NVIDIA Grafiktreiber 280.26 (Version: 280.26 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.2.24.0 (Version: 1.2.24.0 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.46.235 - NVIDIA Corporation) Hidden NVIDIA nView 136.02 (Version: 136.02 - NVIDIA Corporation) NVIDIA nView Desktop Manager (Version: 6.14.10.13594 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.11.0621 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.11.0621 (Version: 9.11.0621 - NVIDIA Corporation) NVIDIA Systemsteuerung 280.26 (Version: 280.26 - NVIDIA Corporation) Hidden O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.23 - O2Micro International LTD.) Hidden PC-CCID (Version: 2.0.0 - Gemalto) Hidden PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden PDF-XChange Viewer (Version: 2.5.197.0 - Tracker Software Products Ltd.) PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden Preboot Manager (Version: 03.03.00.049 - Wave Systems Corp.) Hidden Private Information Manager (Version: 07.01.00.007 - Wave Systems Corp.) Hidden proDAD Mercalli 2.0 (x32 Version: 2.0.105.1 - proDAD GmbH) PTGui Pro 9.1.3 (x32 Version: - New House Internet Services B.V.) QuickTime Alternative 1.81 (x32 Version: 1.81 - ) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden RedMon - Redirection Port Monitor (Version: - ) Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden Roxio Burn (x32 Version: 1.8 - Roxio) Hidden Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden Roxio Creator Starter (x32 Version: 12.1.77.0 - Roxio) Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Samsung ML-371x Series (x32 Version: 1.27 (16.01.2013) - Samsung Electronics Co., Ltd.) Samsung Printer Live Update (x32 Version: 1.01.00.04 - Samsung Electronics Co., Ltd.) Sharpener Pro 3.0 (x32 Version: 3.0.0.5 - Nik Software, Inc.) Silver Efex Pro 2 (x32 Version: 2.0.0.0 - Nik Software, Inc.) Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden SPBA 5.9 (Version: 5.9.4.6686 - UPEK Inc.) Hidden Spyder3Elite (x32 Version: - ) Spyder3Studio SR (x32 Version: - ) Trusted Drive Manager (Version: 4.0.0.512 - Wave Systems Corp.) Hidden Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1 - Microsoft Corporation) Upek Touchchip Fingerprint Reader (Version: 1.2.004 - Dell Inc.) Hidden Viveza 2 (x32 Version: 2.0.0.4 - Nik Software, Inc.) Wave Infrastructure Installer (Version: 07.66.40.0008 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.014 - Wave Systems Corp) Hidden WIDCOMM Bluetooth Software (Version: 6.3.0.7900 - Broadcom Corporation) Windows Driver Package - GoPro (WinUSB) Universal Serial Bus devices (03/07/2012 ) (Version: 03/07/2012 - GoPro) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dell Inc. PBADRV System (09/11/2009 1.0.1.6) (Version: 09/11/2009 1.0.1.6 - Dell Inc.) Xvid Video Codec (x32 Version: 1.3.2 - Xvid Team) ==================== Restore Points ========================= 16-01-2014 02:00:10 Windows Update 24-01-2014 08:53:37 Geplanter Prüfpunkt 25-01-2014 00:07:16 Windows Update 26-01-2014 08:10:55 Installed Java 7 Update 51 28-01-2014 17:23:36 Windows Update 01-02-2014 09:22:25 Windows Update 07-02-2014 20:49:41 Windows Update 11-02-2014 07:30:39 Windows Update 13-02-2014 02:00:11 Windows Update 14-02-2014 01:32:20 zoek.exe restore point 16-02-2014 02:00:10 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2014-02-15 11:14 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {323FA560-8206-4AE6-8ADD-7D835D50C4B9} - System32\Tasks\{0C4D7B98-6EBB-4731-ADAA-C91447093380} => D:\Temp\Delpart.exe Task: {B3EEABE8-B3B6-4649-B2B9-5C4E76514513} - System32\Tasks\{DC334E4C-3EA2-4AF3-88BC-94B721D8EC8A} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe Task: {B8F007C2-DE44-4FA8-A7FB-ECFC52D3FED0} - System32\Tasks\AdobeAAMUpdater-1.0-ms2p5-maddin => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {DADBFA70-8776-487C-9ED3-31B4521C6AB8} - System32\Tasks\{D3D457AC-3188-4F74-BF49-9367FBD5CCA1} => D:\Temp\Delpart.exe Task: {DCE1F4B1-68A1-4173-8549-4811D2E7AC61} - System32\Tasks\{2FE67FED-22CF-4EC7-8D6D-A466E4A80B3E} => C:\Program Files (x86)\Corel\Corel Graphics 11\Programs\CorelDrw.exe ==================== Loaded Modules (whitelisted) ============= 2010-12-23 19:33 - 2010-12-23 19:33 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-02-08 07:41 - 2011-02-08 07:41 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2008-12-05 10:05 - 2008-12-11 17:40 - 08119870 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe 2008-12-11 17:43 - 2008-12-11 17:29 - 00131072 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CSensor.dll 2008-12-11 17:43 - 2008-12-11 17:28 - 00331776 _____ () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\CGamma.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Windows:nlsPreferences AlternateDataStreams: C:\ProgramData\Temp:054203E4 AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: AESTFilters => 2 MSCONFIG\Services: Canon imagePROGRAF Status Monitor => 2 MSCONFIG\Services: Credential Vault Host Control Service => 2 MSCONFIG\Services: Credential Vault Host Storage => 2 MSCONFIG\Services: RoxMediaDB12OEM => 3 MSCONFIG\Services: RoxWatch12 => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^CineForm Status.lnk => C:\Windows\pss\CineForm Status.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GV LicenseManager.lnk => C:\Windows\pss\GV LicenseManager.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^imagePROGRAF Status Monitor.lnk => C:\Windows\pss\imagePROGRAF Status Monitor.lnk.CommonStartup MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" MSCONFIG\startupreg: Apoint => C:\Program Files\DellTPad\Apoint.exe MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CnwiDeviceAgent => C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwida.exe MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: FreeFallProtection => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe MSCONFIG\startupreg: PDVD9LanguageShortcut => "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" MSCONFIG\startupreg: RemoteControl9 => "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-02-15 11:13:24.204 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-02-15 11:13:24.157 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 19% Total physical RAM: 8148.9 MB Available physical RAM: 6561.81 MB Total Pagefile: 16295.98 MB Available Pagefile: 14602.16 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:225.67 GB) (Free:155.79 GB) NTFS Drive d: (Daten) (Fixed) (Total:238.47 GB) (Free:136.78 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 238 GB) (Disk ID: D1E3F7F7) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=13 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=226 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: D1E3F7C8) Partition 1: (Not Active) - (Size=238 GB) - (Type=07 NTFS) ==================== End Of Log ============================ martin |
17.02.2014, 14:26 | #8 |
/// the machine /// TB-Ausbilder | versehentlich zip-anhang einer email geöffnet und .exe ausgeführtESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.02.2014, 02:23 | #9 |
| versehentlich zip-anhang einer email geöffnet und .exe ausgeführt hallo, anbei wieder die logfiles. Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0e11bd4726aea14f85e923019de33e68 # engine=17111 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-02-18 12:57:06 # local_time=2014-02-18 01:57:06 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 300082 144314876 0 0 # scanned=235464 # found=0 # cleaned=0 # scan_time=3057 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Spyder3Elite Spyder3Studio SR Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Flash Player 10 Flash Player out of Date! Adobe Flash Player 11.9.900.117 Mozilla Firefox 10.0.2 Firefox out of Date! Mozilla Thunderbird (24.3.0) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-02-2014 Ran by maddin (administrator) on MS2P5 on 18-02-2014 02:04:27 Running from C:\Users\maddin\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Dell Inc.) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe (Intel Corporation) C:\Windows\system32\IProsetMonitor.exe (CANON INC.) C:\Windows\system32\cnwiols6.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe (O2Micro International) C:\Windows\system32\DRIVERS\o2flash.exe () c:\Windows\SysWOW64\srvany.exe (O2Micro.) c:\Windows\sysWOW64\SDIOAssist.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Dell Computer Corporation) C:\dell\DBRM\Reminder\DbrmTrayicon.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dell Inc.) C:\Program Files\Dell\Dell System Manager\DCPSysMgr.exe () C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-07] (IDT, Inc.) HKLM\...\Run: [IntelPROSet] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1934608 2010-12-23] (Intel(R) Corporation) HKLM\...\Run: [DBRMTray] - C:\Dell\DBRM\Reminder\DbrmTrayIcon.exe [227328 2011-03-08] (Dell Computer Corporation) HKLM\...\Run: [NVHotkey] - C:\Windows\system32\nvHotkey.dll [335976 2011-08-03] (NVIDIA Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [IMSS] - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [112152 2011-01-17] (Intel Corporation) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [FreePDF Assistant] - C:\Program Files (x86)\FreePDF_XP\fpassist.exe [371200 2011-02-23] (shbox.de) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.) AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [240232 2011-08-03] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201320 2011-08-03] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/USREL/8 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\maddin\AppData\Roaming\Mozilla\Firefox\Profiles\xcc0q5jk.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-06-30] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-02] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-22] ==================== Services (Whitelisted) ================= S4 Canon imagePROGRAF Status Monitor; C:\Program Files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [713488 2009-10-09] (CANON INC) R2 iPFDeviceAgentService; C:\Windows\system32\cnwiols6.exe [210944 2008-12-08] (CANON INC.) R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] () S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1629696 2010-07-13] () R2 ZcfgSvc7; C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe [992256 2010-12-23] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== R1 cdrblock; C:\Windows\System32\DRIVERS\cdrblock.sys [37704 2012-06-29] (Grass Valley K.K.) S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-18 02:04 - 2014-02-18 02:04 - 00010913 _____ () C:\Users\maddin\Desktop\FRST.txt 2014-02-18 02:04 - 2014-02-18 02:04 - 00000000 ____D () C:\Users\maddin\Desktop\FRST-OlderVersion 2014-02-18 02:03 - 2014-02-18 02:03 - 00000938 _____ () C:\Users\maddin\Desktop\checkup.txt 2014-02-18 02:00 - 2014-02-18 02:00 - 00987425 _____ () C:\Users\maddin\Desktop\SecurityCheck.exe 2014-02-18 01:03 - 2014-02-18 01:03 - 02347384 _____ (ESET) C:\Users\maddin\Desktop\esetsmartinstaller_enu.exe 2014-02-16 20:04 - 2014-02-16 20:04 - 00030582 _____ () C:\Users\maddin\Desktop\FRST_2014_02_16.txt 2014-02-16 20:04 - 2014-02-16 20:04 - 00025194 _____ () C:\Users\maddin\Desktop\Addition_2014_02_16.txt 2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt 2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt 2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe 2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-16 11:05 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt 2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt 2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt 2014-02-15 11:10 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-15 11:10 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-15 11:10 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-02-15 11:10 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-02-15 11:09 - 2014-02-15 11:16 - 00000000 ____D () C:\Qoobox 2014-02-15 11:09 - 2014-02-15 11:15 - 00000000 ____D () C:\Windows\erdnt 2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe 2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt 2014-02-14 08:37 - 2014-02-18 02:04 - 00000000 ____D () C:\FRST 2014-02-14 08:37 - 2014-02-14 08:38 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt 2014-02-14 08:36 - 2014-02-18 02:04 - 02152448 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe 2014-02-14 03:10 - 2014-02-16 11:40 - 00000000 ____D () C:\AdwCleaner 2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe 2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip 2014-02-14 02:40 - 2014-02-14 02:32 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-14 02:32 - 2014-02-14 02:41 - 00023557 _____ () C:\zoek-results.log 2014-02-14 02:30 - 2014-02-14 03:01 - 00000000 ____D () C:\zoek_backup 2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe 2014-02-13 03:00 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-13 03:00 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-13 03:00 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-13 03:00 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-13 03:00 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-13 03:00 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-13 03:00 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-13 03:00 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-13 03:00 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-13 03:00 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-13 03:00 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-13 03:00 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-13 03:00 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-13 03:00 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-13 03:00 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-13 03:00 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-13 03:00 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-13 03:00 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-13 03:00 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-13 03:00 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-13 03:00 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-13 03:00 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-13 03:00 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-13 03:00 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-13 03:00 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-13 03:00 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-13 03:00 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-13 03:00 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-13 03:00 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-13 03:00 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-13 03:00 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-13 03:00 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-13 03:00 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-13 03:00 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-13 03:00 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-13 03:00 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-13 03:00 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-13 03:00 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-13 03:00 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-13 03:00 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-13 03:00 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 23:31 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 23:31 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 23:31 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 23:31 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 23:30 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 23:30 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 23:30 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 23:30 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk 2014-02-05 00:21 - 2014-02-05 08:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log ==================== One Month Modified Files and Folders ======= 2014-02-18 02:04 - 2014-02-18 02:04 - 00010913 _____ () C:\Users\maddin\Desktop\FRST.txt 2014-02-18 02:04 - 2014-02-18 02:04 - 00000000 ____D () C:\Users\maddin\Desktop\FRST-OlderVersion 2014-02-18 02:04 - 2014-02-14 08:37 - 00000000 ____D () C:\FRST 2014-02-18 02:04 - 2014-02-14 08:36 - 02152448 _____ (Farbar) C:\Users\maddin\Desktop\FRST64.exe 2014-02-18 02:03 - 2014-02-18 02:03 - 00000938 _____ () C:\Users\maddin\Desktop\checkup.txt 2014-02-18 02:00 - 2014-02-18 02:00 - 00987425 _____ () C:\Users\maddin\Desktop\SecurityCheck.exe 2014-02-18 01:03 - 2014-02-18 01:03 - 02347384 _____ (ESET) C:\Users\maddin\Desktop\esetsmartinstaller_enu.exe 2014-02-18 01:00 - 2010-11-21 07:50 - 00697082 _____ () C:\Windows\system32\perfh007.dat 2014-02-18 01:00 - 2010-11-21 07:50 - 00148346 _____ () C:\Windows\system32\perfc007.dat 2014-02-18 01:00 - 2009-07-14 06:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-18 00:15 - 2011-08-24 17:32 - 01958051 _____ () C:\Windows\WindowsUpdate.log 2014-02-17 23:55 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-17 23:55 - 2009-07-14 05:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-17 23:48 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-17 23:48 - 2009-07-14 05:51 - 00233103 _____ () C:\Windows\setupact.log 2014-02-16 20:04 - 2014-02-16 20:04 - 00030582 _____ () C:\Users\maddin\Desktop\FRST_2014_02_16.txt 2014-02-16 20:04 - 2014-02-16 20:04 - 00025194 _____ () C:\Users\maddin\Desktop\Addition_2014_02_16.txt 2014-02-16 20:00 - 2014-02-16 20:00 - 00000759 _____ () C:\Users\maddin\Desktop\JRT.txt 2014-02-16 19:57 - 2014-02-16 19:57 - 00000000 ____D () C:\Windows\ERUNT 2014-02-16 11:41 - 2014-02-16 11:41 - 00001039 _____ () C:\Users\maddin\Desktop\AdwCleaner[S1].txt 2014-02-16 11:40 - 2014-02-14 03:10 - 00000000 ____D () C:\AdwCleaner 2014-02-16 11:18 - 2014-02-16 11:18 - 01037530 _____ (Thisisu) C:\Users\maddin\Desktop\JRT.exe 2014-02-16 11:06 - 2014-02-16 11:06 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00001079 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-16 11:05 - 2014-02-16 11:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-16 03:01 - 2013-08-14 06:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-16 03:00 - 2011-09-04 13:42 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 11:42 - 2014-02-15 11:42 - 00032236 _____ () C:\Users\maddin\Desktop\Addition_2014_02_15.txt 2014-02-15 11:42 - 2014-02-15 11:42 - 00027888 _____ () C:\Users\maddin\Desktop\FRST_2014_02_15.txt 2014-02-15 11:16 - 2014-02-15 11:16 - 00026272 _____ () C:\ComboFix.txt 2014-02-15 11:16 - 2014-02-15 11:09 - 00000000 ____D () C:\Qoobox 2014-02-15 11:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default 2014-02-15 11:15 - 2014-02-15 11:09 - 00000000 ____D () C:\Windows\erdnt 2014-02-15 11:14 - 2010-11-21 04:47 - 00029252 _____ () C:\Windows\PFRO.log 2014-02-15 11:14 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2014-02-15 11:13 - 2009-07-14 03:34 - 74186752 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 44040192 _____ () C:\Windows\system32\config\components.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 21757952 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2014-02-15 11:13 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2014-02-15 11:07 - 2014-02-15 11:07 - 05183211 ____R (Swearware) C:\Users\maddin\Desktop\ComboFix.exe 2014-02-14 08:38 - 2014-02-14 08:38 - 00032488 _____ () C:\Users\maddin\Desktop\Addition_2014_02_14.txt 2014-02-14 08:38 - 2014-02-14 08:37 - 00029381 _____ () C:\Users\maddin\Desktop\FRST_2014_02_14.txt 2014-02-14 03:09 - 2014-02-14 03:09 - 01166132 _____ () C:\Users\maddin\Desktop\adwcleaner.exe 2014-02-14 03:05 - 2014-02-14 03:05 - 04102163 _____ () C:\Users\maddin\Desktop\tdsskiller.zip 2014-02-14 03:01 - 2014-02-14 02:30 - 00000000 ____D () C:\zoek_backup 2014-02-14 02:41 - 2014-02-14 02:32 - 00023557 _____ () C:\zoek-results.log 2014-02-14 02:32 - 2014-02-14 02:40 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-14 02:30 - 2014-02-14 02:30 - 01283584 _____ () C:\Users\maddin\Desktop\zoek.exe 2014-02-13 03:04 - 2011-02-11 18:45 - 01591234 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-11 18:02 - 2014-02-11 18:02 - 00000146 _____ () C:\Users\maddin\Desktop\Dell Touchpad - Verknüpfung.lnk 2014-02-10 23:02 - 2013-03-22 14:55 - 00000072 _____ () C:\Users\Public\LMDebug.log 2014-02-06 13:16 - 2014-02-13 03:00 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-13 03:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-13 03:00 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-13 03:00 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-13 03:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-13 03:00 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-13 03:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-13 03:00 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-13 03:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-13 03:00 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-13 03:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-13 03:00 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-13 03:00 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-13 03:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-13 03:00 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-13 03:00 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-13 03:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-13 03:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-13 03:00 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-13 03:00 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-13 03:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-13 03:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-13 03:00 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-13 03:00 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-13 03:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-13 03:00 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-13 03:00 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-13 03:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-13 03:00 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-13 03:00 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-13 03:00 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-13 03:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-13 03:00 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-13 03:00 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-13 03:00 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-13 03:00 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-13 03:00 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-13 03:00 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 10:26 - 2011-09-11 14:19 - 00000000 ____D () C:\Users\maddin\AppData\Local\FreePDF_XP 2014-02-05 09:30 - 2012-10-15 14:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-05 08:11 - 2014-02-05 00:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-02-01 23:46 - 2011-08-31 01:16 - 00000000 ____D () C:\Users\maddin\AppData\Roaming\IrfanView 2014-01-31 23:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-01-28 00:21 - 2011-11-20 00:11 - 00012288 _____ () C:\Users\maddin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-01-26 09:17 - 2013-10-21 22:11 - 00000000 ____D () C:\ProgramData\Oracle 2014-01-26 09:11 - 2014-01-26 09:11 - 00005327 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-26 09:11 - 2013-06-25 17:19 - 00000000 ____D () C:\Program Files (x86)\Java Some content of TEMP: ==================== C:\Users\maddin\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-09 11:55 ==================== End Of Log ============================ aber ich wollte auf nummer sicher gehen, dass ich nichts eingefangen habe. frage: hältst du einen regcleaner für sinnvoll und wenn ja, kannst du einen speziellen empfehlen ? nur mal so zum aufräumen ? vielen dank für die ausdauernde unterstützung. gruß martin |
18.02.2014, 16:37 | #10 | |
/// the machine /// TB-Ausbilder | versehentlich zip-anhang einer email geöffnet und .exe ausgeführt Flash und Firefox updaten. Zitat:
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.02.2014, 17:46 | #11 |
| versehentlich zip-anhang einer email geöffnet und .exe ausgeführt so, alles erledigt, alles bestens. bleibt mir nur noch, mich für die sehr kompetente unterstützung zu bedanken. ich hoffe, ich muss eure hilfe nicht mehr so bald in anspruch nehmen. als bescheidenen dank habe ich mal 20.- gespendet. beste grüße martin |
19.02.2014, 15:35 | #12 |
/// the machine /// TB-Ausbilder | versehentlich zip-anhang einer email geöffnet und .exe ausgeführt Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu versehentlich zip-anhang einer email geöffnet und .exe ausgeführt |
administrator, adobe, appdata, desktop, email, explorer, falsch, firefox, folge, google, internet, internet explorer, java, logfile, mozilla, registry, rundll, rundll32.exe, scan, software, system, system32, temp, webcam, windows |