Log-Analyse und Auswertung: loadtbs-2.1 & loadtbs-3.0 HILFE!
loadtbs-2.1 & loadtbs-3.0 HILFE! Hallo meine Guten! Ich habe mir heute Morgen ein kleines unscheinbares Programm installiert und einen Haufen versteckter trojaner eingefangen. Die meisten Sachen konnte ich über Systemsteuerung löschen, jedoch ist noch loadtbs-2.1 präsent. Ob die anderen Schädlinge noch auf dem System sind - keine Ahnung. Zwar habe ich einige Foreneinträge zu loadtbs-2.1 & loadtbs-3.0 gefunden, die Lösungen für die Probleme waren auf die jeweiligen User zugeschnitten. Wenn es Euch nicht all zu viel was ausmacht, wäre ich euch sehr dankbar für die Hilfe.
loadtbs-2.1 & loadtbs-3.0 HILFE! Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
loadtbs-2.1 & loadtbs-3.0 HILFE! Hallo Matthias,
__________________an dieser Stelle schonmal vielen Dank für Deine schnelle Rückantwort! Geändert von risdim (23.02.2014 um 21:42 Uhr) |
loadtbs-2.1 & loadtbs-3.0 HILFE! Servus, Schritt 1 Downloade Dir bitte
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Downloade Dir bitte ![]()
Schritt 4 Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/
Bitte poste mit deiner nächsten Antwort
loadtbs-2.1 & loadtbs-3.0 HILFE! Hallo! Also, Schritt 1: Beim Ausführen des Löschvorganges nachdem der Balken abgelaufen ist, bricht das Programm ab und sämtliche Windowsfunktionen/-Programme werden abgeschaltet. Nach Neustart alles PRIMA.
loadtbs-2.1 & loadtbs-3.0 HILFE! Servus, hab ja auch noch nicht gesagt, dass wir schon fertig sind. Wir spüren die letzten Reste auf, damit wir sie später entfernen können: Kontrollscan mit FRST Führe wie zuvor beschrieben einen Scan mit FRST aus. Setze dazu eine Haken bei Addition.txt rechts unten und klicke auf Scan. Es werden wieder zwei Logdateien erzeugt. Poste mir diese. Gibt es noch Probleme mit Malware? Wenn ja, welche? Wie läuft der Rechner derzeit?
loadtbs-2.1 & loadtbs-3.0 HILFE! Guten Abend! hier die logdaten:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-02-2014 01 Ran by Dima (administrator) on DIMAPC on 25-02-2014 20:31:22 Running from C:\Users\Dima\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Marvell) C:\Program Files (x86)\Marvell\storage\svc\mvraidsvc.exe (Apache Software Foundation) C:\Program Files (x86)\Marvell\storage\Apache2\bin\httpd.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Aqua Computer) C:\Program Files (x86)\Aqua Computer\aquasuite\SetClockService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Apache Software Foundation) C:\Program Files (x86)\Marvell\storage\Apache2\bin\httpd.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe (Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Aqua Computer GmbH & Co. KG) C:\Program Files (x86)\Aqua Computer\aquasuite\aquasuite.exe (Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Razer USA Ltd.) C:\Program Files (x86)\Razer\Tarantula\razerhid.exe () C:\Program Files (x86)\Razer\Copperhead\razerhid.exe (Dropbox, Inc.) C:\Users\Dima\AppData\Roaming\Dropbox\bin\Dropbox.exe (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe () C:\Program Files (x86)\Marvell\storage\tray\MarvellTray.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonTaskbar.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Creative Technology Ltd) C:\Windows\SysWOW64\Ctxfihlp.exe () C:\Program Files (x86)\Drakonia Configurator\hid.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Razer Inc.) C:\Program Files (x86)\Razer\Copperhead\razerofa.exe () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe () C:\Program Files (x86)\Razer\Tarantula\razertra.exe (Creative Technology Ltd) C:\Windows\SysWOW64\CTXFISPI.EXE (Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor) HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2012-10-15] (Saitek) HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2012-10-15] (Saitek) HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation) HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation) HKLM-x32\...\Run: [Tarantula] - C:\Program Files (x86)\Razer\Tarantula\razerhid.exe [159744 2007-05-07] (Razer USA Ltd.) HKLM-x32\...\Run: [Copperhead] - C:\Program Files (x86)\Razer\Copperhead\razerhid.exe [135168 2009-11-19] () HKLM-x32\...\Run: [VirtualCloneDrive] - C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [89456 2011-03-07] (Elaborate Bytes AG) HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264 2012-04-17] () HKLM-x32\...\Run: [Reader Application Helper] - C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-03-18] (Sony Corporation) HKLM-x32\...\Run: [MSUTray] - C:\Program Files (x86)\Marvell\storage\tray\MarvellTray.exe [1213952 2012-06-13] () HKLM-x32\...\Run: [AllShareAgent] - C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [285072 2012-03-01] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508256 2012-04-23] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.) HKLM-x32\...\Run: [CTxfiHlp] - CTXFIHLP.EXE HKLM-x32\...\Run: [GamingMouse] - C:\Program Files (x86)\Drakonia Configurator\hid.exe [248832 2013-10-29] () HKLM-x32\...\Run: [VolPanel] - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [237693 2009-02-03] (Creative Technology Ltd) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\Run: [CtxfiReg] - CTXFIREG.exe /FAIL1 HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [17145992 2012-02-15] (Skype Technologies S.A.) HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\Run: [GameCenterMailRu] - "C:\Users\Dima\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe" -autostart HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\Run: [OfficeSyncProcess] - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office14\GROOVEMN.EXE HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\MountPoints2: L - L:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\MountPoints2: {0f299b28-5e02-11e1-990e-806e6f6e6963} - D:\Run.exe HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\MountPoints2: {275a688c-ca9e-11e2-9dda-50e54940205f} - L:\SETUP.EXE HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\MountPoints2: {46a5262e-9d57-11e2-a169-50e54940205f} - O:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\MountPoints2: {46a52655-9d57-11e2-a169-50e54940205f} - O:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-2443769886-4202561317-2966623681-1000\...\MountPoints2: {aba5000a-86a4-11e2-bb0b-50e54940205f} - O:\HTC_Sync_Manager_PC.exe Startup: C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Dima\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {1D84CB7C-4D7D-4ab1-BBA7-C14982B68FEF} URL = hxxp://www.google.com/cse?cx=partner-pub-3794288947762788%3A7941509802&ie=UTF-8&sa=Search&siteurl=www.google.com%2Fcse%2Fhome%3Fcx%3Dpartner-pub-3794288947762788%3A7941509802&q={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {E705A591-DA3C-4228-B0D5-A356DBA42FBF} hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Dima\AppData\Roaming\Mozilla\Firefox\C:\ProgramData\Kaspersky Lab\SafeBrowser\S-1-5-21-2443769886-4202561317-2966623681-1000\FireFox FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @sony.com/ReaderDesktop - C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @mail.ru/GameCenter - C:\Users\Dima\AppData\Local\Mail.Ru\GameCenter\NPDetector.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2012-09-30] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2012-09-30] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2012-09-30] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2012-09-30] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2012-09-30] ==================== Services (Whitelisted) ================= S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MSUWebService; C:\Program Files (x86)\Marvell\storage\Apache2\bin\httpd.exe [24645 2011-11-22] (Apache Software Foundation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [87040 2012-03-23] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2012-06-07] () R2 SetClockService; C:\Program Files (x86)\Aqua Computer\aquasuite\SetClockService.exe [241152 2008-09-19] (Aqua Computer) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] () S3 copperhd; C:\Windows\System32\drivers\copperhd.sys [14336 2009-11-10] (Razer (Asia-Pacific) Pte Ltd) S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-04-22] (EnTech Taiwan) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-19] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-04-24] (Kaspersky Lab ZAO) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 Mv_Process; c:\windows\syswow64\mv_process.sys [14376 2011-11-22] () R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation) R3 RAMDiskVE; C:\Windows\System32\Drivers\RAMDiskVE.sys [63696 2010-09-22] () S3 SaiK1713; C:\Windows\System32\DRIVERS\SaiK1713.sys [180544 2012-09-20] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [24680 2012-10-15] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52200 2012-10-15] (Saitek) S3 SaiU1713; C:\Windows\System32\DRIVERS\SaiU1713.sys [47168 2012-09-20] (Saitek) R3 TarFltr; C:\Windows\System32\drivers\UsbFltr.sys [49664 2007-04-11] (Razer USA Ltd.) R2 WinRing0_1_2_0; C:\Users\Dima\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries25.gadget\WinRing0x64.sys [14544 2012-02-23] (OpenLibSys.org) S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-04-24] (Kaspersky Lab ZAO) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-25 20:31 - 2014-02-25 20:31 - 00022085 _____ () C:\Users\Dima\Desktop\FRST.txt 2014-02-25 20:23 - 2014-02-25 20:23 - 00000000 ____D () C:\Users\Dima\Desktop\FRST-OlderVersion 2014-02-24 22:20 - 2014-02-24 22:20 - 00000253 _____ () C:\Users\Dima\Desktop\Скачать Worms Antology (1996-2013RUSENGMULTIRePack) игру бесплатно.URL 2014-02-24 21:05 - 2014-02-25 20:29 - 00000028 _____ () C:\Users\Dima\AppData\Roaming\Network Meter_Usage.ini 2014-02-24 21:05 - 2014-02-24 20:58 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-24 20:59 - 2014-02-24 21:06 - 00011708 _____ () C:\zoek-results.log 2014-02-24 20:58 - 2014-02-24 21:04 - 00000000 ____D () C:\zoek_backup 2014-02-24 20:58 - 2014-02-24 20:58 - 01284608 _____ () C:\Users\Dima\Desktop\zoek.exe 2014-02-24 20:46 - 2014-02-24 20:46 - 00001119 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-24 20:46 - 2014-02-24 20:46 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Malwarebytes 2014-02-24 20:46 - 2014-02-24 20:46 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-24 20:46 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-24 20:45 - 2014-02-24 20:45 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Dima\Desktop\mbam-setup- 2014-02-24 20:39 - 2014-02-24 20:39 - 00000000 ____D () C:\Windows\ERUNT 2014-02-24 20:38 - 2014-02-24 20:38 - 01037734 _____ (Thisisu) C:\Users\Dima\Desktop\JRT.exe 2014-02-23 20:54 - 2014-02-25 20:31 - 00000000 ____D () C:\FRST 2014-02-23 20:52 - 2014-02-25 20:23 - 02156032 _____ (Farbar) C:\Users\Dima\Desktop\FRST64.exe 2014-02-23 20:40 - 2014-02-23 20:40 - 00000251 _____ () C:\Users\Dima\Desktop\loadtbs-2.1 & loadtbs-3.0 HILFE! - Trojaner-Board.URL 2014-02-23 20:20 - 2014-02-24 21:02 - 00000000 ____D () C:\Users\Dima\Desktop\maleware 2014-02-23 20:20 - 2014-02-24 20:29 - 00000000 ____D () C:\AdwCleaner 2014-02-23 20:20 - 2014-02-23 20:20 - 01241834 _____ () C:\Users\Dima\Desktop\adwcleaner.exe 2014-02-23 19:57 - 2014-02-23 19:57 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-23 19:56 - 2014-02-23 19:56 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-02-23 14:07 - 2014-02-23 14:07 - 00003090 _____ () C:\Windows\System32\Tasks\{945A0842-BA42-4AB2-B885-07E8DB301A3C} 2014-02-23 12:32 - 2014-02-23 12:32 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mirillis 2014-02-23 12:21 - 2014-02-23 12:51 - 00000000 ____D () C:\Users\Dima\Desktop\Neuer Ordner 2014-02-23 12:19 - 2014-02-23 12:20 - 00000000 ____D () C:\Program Files\Unlocker 2014-02-23 12:19 - 2014-02-23 12:19 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2014-02-23 12:09 - 2014-02-25 20:29 - 00182640 _____ () C:\Windows\PFRO.log 2014-02-23 03:09 - 2014-02-25 20:30 - 00002870 _____ () C:\Windows\Tray.log 2014-02-23 01:00 - 2014-02-25 20:29 - 00003360 _____ () C:\Windows\setupact.log 2014-02-22 14:45 - 2014-02-25 20:30 - 05724041 _____ () C:\Windows\backend.log 2014-02-21 22:49 - 2014-02-21 22:49 - 00000000 ____D () C:\Users\Dima\Documents\MightAndMagicXLegacy 2014-02-18 22:29 - 2014-02-18 22:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-02-18 22:29 - 2014-02-08 17:18 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-02-18 22:27 - 2014-02-08 19:34 - 31432480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 23683360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 17715784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 15740232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 12324640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-18 22:27 - 2014-02-08 19:34 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433489.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433489.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00875296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00844576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-02-18 22:27 - 2014-02-08 19:34 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-02-18 22:27 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-02-18 22:27 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-02-18 22:27 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2014-02-15 12:01 - 2014-02-15 12:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-12 22:40 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 22:40 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 22:40 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 22:40 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 22:40 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 22:40 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 22:40 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 22:40 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 22:40 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 22:40 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 22:40 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 22:40 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 22:40 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 22:40 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 22:40 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 22:40 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 22:40 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 22:40 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 22:40 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-12 22:40 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 22:40 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 22:40 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 22:40 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 22:40 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 22:40 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-12 22:40 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-12 22:40 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-12 22:40 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 22:40 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 22:40 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 22:40 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 22:40 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 22:40 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-12 22:40 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 22:40 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 22:40 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 22:40 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 22:40 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 22:40 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 22:40 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 22:40 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 17:43 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 17:43 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 17:43 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 17:43 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 17:43 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 17:43 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 17:43 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 17:43 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 17:43 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 17:43 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 17:43 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 17:43 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 17:43 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 17:43 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 17:43 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 17:43 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 17:43 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 17:43 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 17:43 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 17:43 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 17:43 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 17:43 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 17:43 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 17:43 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 17:43 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 17:43 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 17:43 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 17:43 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2014-02-10 23:25 - 2012-03-14 13:34 - 05113625 _____ () C:\Users\Dima\Desktop\rozhdestvenskiy_yu_t_nemecko_russkiy_slovar_po_psihologii_s.djvu 2014-02-08 12:43 - 2014-02-08 20:57 - 00010619 _____ () C:\Users\Dima\Desktop\STR-KRR.xlsx 2014-01-29 21:16 - 2010-02-16 14:22 - 00218432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx 2014-01-29 21:16 - 2010-02-16 14:22 - 00126800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswinsck.ocx 2014-01-29 21:16 - 2010-02-16 14:22 - 00100160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\picclp32.ocx 2014-01-29 21:16 - 2007-02-01 19:11 - 00344064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2014-01-29 21:16 - 2007-01-30 22:04 - 00339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll 2014-01-29 21:16 - 2005-01-20 19:25 - 00054784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvci70.dll 2014-01-29 21:16 - 2002-01-05 05:40 - 00487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp70.dll 2014-01-29 21:16 - 2001-08-23 00:00 - 01355776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvbvm50.dll 2014-01-29 21:16 - 1996-01-12 03:00 - 00722192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vb40032.dll 2014-01-29 21:16 - 1993-07-23 19:31 - 00210944 _____ () C:\Windows\SysWOW64\msvcrt10.dll 2014-01-29 21:15 - 2011-01-12 13:36 - 01054208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71u.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71deu.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71ita.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71fra.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71esp.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71enu.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71kor.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71jpn.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71cht.dll 2014-01-29 21:15 - 2011-01-12 13:25 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71chs.dll 2014-01-29 21:15 - 2011-01-12 13:19 - 01060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2014-01-29 21:15 - 2011-01-12 12:53 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl71.dll 2014-01-29 21:15 - 2010-02-16 14:22 - 00252240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatlst.ocx 2014-01-29 21:15 - 2010-02-16 14:22 - 00222528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx 2014-01-29 21:15 - 2010-02-16 14:22 - 00215880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mci32.ocx 2014-01-29 21:15 - 2010-02-16 14:22 - 00178512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmask32.ocx 2014-01-29 21:15 - 2010-02-16 14:22 - 00136008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx 2014-01-29 21:15 - 2010-02-16 14:22 - 00119616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomm32.ocx 2014-01-29 21:15 - 2006-08-26 00:28 - 01017344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70u.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ita.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70fra.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70esp.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70deu.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70enu.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70kor.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70jpn.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70cht.dll 2014-01-29 21:15 - 2006-08-26 00:15 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70chs.dll 2014-01-29 21:15 - 2006-08-26 00:07 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70.dll 2014-01-29 21:15 - 2006-08-25 23:17 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl70.dll 2014-01-29 21:15 - 2006-04-10 13:41 - 01066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl32.ocx 2014-01-29 19:04 - 2014-01-29 19:04 - 01192533 _____ () C:\Windows\unins000.exe 2014-01-29 19:04 - 2014-01-29 19:04 - 00018226 _____ () C:\Windows\unins000.dat 2014-01-29 19:04 - 2014-01-29 19:04 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\MingGuan 2014-01-29 19:04 - 2014-01-29 19:04 - 00000000 ____D () C:\Program Files (x86)\Drakonia Configurator 2014-01-29 15:40 - 2014-01-29 19:04 - 00000000 ____D () C:\Program Files (x86)\Drakonia Black ==================== One Month Modified Files and Folders ======= 2014-02-25 20:31 - 2014-02-25 20:31 - 00022085 _____ () C:\Users\Dima\Desktop\FRST.txt 2014-02-25 20:31 - 2014-02-23 20:54 - 00000000 ____D () C:\FRST 2014-02-25 20:31 - 2012-09-05 15:27 - 00117632 _____ () C:\Windows\SysWOW64\za_mv_raid.ev 2014-02-25 20:31 - 2012-09-05 15:26 - 00000112 _____ () C:\Windows\seqlog 2014-02-25 20:31 - 2012-02-23 11:26 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Skype 2014-02-25 20:31 - 2011-11-22 04:08 - 00173056 _____ () C:\Windows\SysWOW64\freqdb.db 2014-02-25 20:30 - 2014-02-23 03:09 - 00002870 _____ () C:\Windows\Tray.log 2014-02-25 20:30 - 2014-02-22 14:45 - 05724041 _____ () C:\Windows\backend.log 2014-02-25 20:30 - 2012-09-05 15:27 - 00000040 _____ () C:\Windows\SysWOW64\za_mv_seqnum.ev 2014-02-25 20:30 - 2012-09-05 15:26 - 00114846 _____ () C:\Windows\SysWOW64\mvaccelerator.log 2014-02-25 20:30 - 2012-06-06 09:17 - 00000000 ____D () C:\Users\Dima\AppData\Local\Htc 2014-02-25 20:30 - 2012-04-10 20:52 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Dropbox 2014-02-25 20:30 - 2012-02-23 12:04 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-02-25 20:29 - 2014-02-24 21:05 - 00000028 _____ () C:\Users\Dima\AppData\Roaming\Network Meter_Usage.ini 2014-02-25 20:29 - 2014-02-23 12:09 - 00182640 _____ () C:\Windows\PFRO.log 2014-02-25 20:29 - 2014-02-23 01:00 - 00003360 _____ () C:\Windows\setupact.log 2014-02-25 20:29 - 2013-09-10 22:32 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-25 20:29 - 2012-02-23 15:17 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-25 20:29 - 2012-02-23 10:42 - 02087232 _____ () C:\Windows\WindowsUpdate.log 2014-02-25 20:29 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-25 20:27 - 2012-03-30 07:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-25 20:25 - 2012-04-02 11:42 - 01602692 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-25 20:25 - 2009-07-14 18:58 - 00702942 _____ () C:\Windows\system32\perfh007.dat 2014-02-25 20:25 - 2009-07-14 18:58 - 00150582 _____ () C:\Windows\system32\perfc007.dat 2014-02-25 20:25 - 2009-07-14 06:13 - 01650230 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-25 20:23 - 2014-02-25 20:23 - 00000000 ____D () C:\Users\Dima\Desktop\FRST-OlderVersion 2014-02-25 20:23 - 2014-02-23 20:52 - 02156032 _____ (Farbar) C:\Users\Dima\Desktop\FRST64.exe 2014-02-25 20:00 - 2013-03-15 15:24 - 00116339 _____ () C:\Users\Dima\Network_Meter_Data.js 2014-02-25 19:50 - 2012-02-23 15:17 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-25 19:29 - 2009-07-14 05:45 - 00025200 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-25 19:29 - 2009-07-14 05:45 - 00025200 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-24 22:20 - 2014-02-24 22:20 - 00000253 _____ () C:\Users\Dima\Desktop\Скачать Worms Antology (1996-2013RUSENGMULTIRePack) игру бесплатно.URL 2014-02-24 21:06 - 2014-02-24 20:59 - 00011708 _____ () C:\zoek-results.log 2014-02-24 21:04 - 2014-02-24 20:58 - 00000000 ____D () C:\zoek_backup 2014-02-24 21:02 - 2014-02-23 20:20 - 00000000 ____D () C:\Users\Dima\Desktop\maleware 2014-02-24 20:58 - 2014-02-24 21:05 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-02-24 20:58 - 2014-02-24 20:58 - 01284608 _____ () C:\Users\Dima\Desktop\zoek.exe 2014-02-24 20:46 - 2014-02-24 20:46 - 00001119 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-24 20:46 - 2014-02-24 20:46 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Malwarebytes 2014-02-24 20:46 - 2014-02-24 20:46 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-02-24 20:45 - 2014-02-24 20:45 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Dima\Desktop\mbam-setup- 2014-02-24 20:39 - 2014-02-24 20:39 - 00000000 ____D () C:\Windows\ERUNT 2014-02-24 20:38 - 2014-02-24 20:38 - 01037734 _____ (Thisisu) C:\Users\Dima\Desktop\JRT.exe 2014-02-24 20:29 - 2014-02-23 20:20 - 00000000 ____D () C:\AdwCleaner 2014-02-23 21:32 - 2012-04-10 16:31 - 00003608 _____ () C:\Windows\System32\Tasks\Launch HTC Sync Loader 2014-02-23 21:31 - 2012-02-23 13:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-02-23 21:30 - 2012-02-23 21:50 - 00000000 ____D () C:\Program Files (x86)\HD Tune Pro 2014-02-23 21:29 - 2012-02-23 15:12 - 00000000 ____D () C:\Program Files (x86)\ABBYY Lingvo 12 2014-02-23 21:28 - 2012-02-23 10:55 - 00128320 _____ () C:\Users\Dima\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-23 21:27 - 2009-07-14 05:45 - 00455792 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-02-23 21:26 - 2012-09-20 12:22 - 00000000 ____D () C:\Program Files\Microsoft Office 2014-02-23 21:26 - 2012-02-23 13:25 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-02-23 21:26 - 2009-07-14 19:18 - 00000000 ____D () C:\Windows\ShellNew 2014-02-23 21:26 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-02-23 21:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-02-23 21:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-02-23 21:26 - 2009-07-14 03:34 - 00000387 _____ () C:\Windows\win.ini 2014-02-23 21:21 - 2012-02-23 15:00 - 00000000 ____D () C:\Users\Dima\AppData\Local\ABBYY 2014-02-23 21:21 - 2012-02-23 13:57 - 00000000 ____D () C:\ProgramData\ABBYY 2014-02-23 21:21 - 2012-02-23 11:05 - 00000000 ____D () C:\gamez 2014-02-23 20:45 - 2012-02-23 13:54 - 00000000 ____D () C:\Users\Dima\AppData\Local\Mirillis 2014-02-23 20:40 - 2014-02-23 20:40 - 00000251 _____ () C:\Users\Dima\Desktop\loadtbs-2.1 & loadtbs-3.0 HILFE! - Trojaner-Board.URL 2014-02-23 20:20 - 2014-02-23 20:20 - 01241834 _____ () C:\Users\Dima\Desktop\adwcleaner.exe 2014-02-23 19:58 - 2012-02-24 15:42 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2014-02-23 19:58 - 2012-02-24 15:42 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-02-23 19:57 - 2014-02-23 19:57 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-02-23 19:56 - 2014-02-23 19:56 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-02-23 19:51 - 2013-05-18 00:48 - 00001072 _____ () C:\Windows\system32\settingsbkup.sfm 2014-02-23 19:51 - 2013-05-18 00:48 - 00001072 _____ () C:\Windows\system32\settings.sfm 2014-02-23 14:07 - 2014-02-23 14:07 - 00003090 _____ () C:\Windows\System32\Tasks\{945A0842-BA42-4AB2-B885-07E8DB301A3C} 2014-02-23 14:01 - 2013-05-17 21:12 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Creative 2014-02-23 14:01 - 2012-09-04 12:45 - 00000000 ____D () C:\Program Files\Autodesk 2014-02-23 13:34 - 2012-02-23 16:06 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Opera 2014-02-23 13:34 - 2012-02-23 16:06 - 00000000 ____D () C:\Users\Dima\AppData\Local\Opera 2014-02-23 13:34 - 2012-02-23 16:06 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-02-23 13:09 - 2013-10-14 20:16 - 00000000 ____D () C:\Program Files (x86)\Futuremark 2014-02-23 13:09 - 2012-02-23 10:51 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-02-23 13:07 - 2012-02-23 10:42 - 00001431 _____ () C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-02-23 12:51 - 2014-02-23 12:21 - 00000000 ____D () C:\Users\Dima\Desktop\Neuer Ordner 2014-02-23 12:47 - 2013-11-03 22:30 - 00000000 ____D () C:\Users\Dima\Desktop\pics 2014-02-23 12:32 - 2014-02-23 12:32 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mirillis 2014-02-23 12:24 - 2012-02-22 16:22 - 00000000 ____D () C:\Users\Dima\Desktop\new 2014 album 2014-02-23 12:21 - 2013-07-26 21:30 - 00000000 ____D () C:\Users\Dima\Desktop\dokumenten 2014-02-23 12:21 - 2012-02-23 10:42 - 00000000 ____D () C:\Users\Dima 2014-02-23 12:20 - 2014-02-23 12:19 - 00000000 ____D () C:\Program Files\Unlocker 2014-02-23 12:19 - 2014-02-23 12:19 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2014-02-23 12:08 - 2012-05-11 22:52 - 00000000 ____D () C:\Program Files (x86)\DivX 2014-02-23 12:08 - 2012-05-11 22:51 - 00000000 ____D () C:\ProgramData\DivX 2014-02-21 22:49 - 2014-02-21 22:49 - 00000000 ____D () C:\Users\Dima\Documents\MightAndMagicXLegacy 2014-02-21 22:49 - 2013-09-07 21:58 - 00000000 ____D () C:\ProgramData\Orbit 2014-02-21 22:21 - 2012-02-24 15:42 - 00281152 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-02-21 19:27 - 2012-03-30 07:41 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 19:27 - 2012-03-30 07:41 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-21 19:27 - 2012-02-23 11:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-18 22:29 - 2014-02-18 22:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-02-18 22:29 - 2013-09-10 21:56 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-02-17 22:38 - 2013-07-13 10:47 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 22:38 - 2012-02-23 11:15 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 23:34 - 2012-04-25 07:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-15 16:44 - 2012-02-23 15:17 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-15 16:44 - 2012-02-23 15:17 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-15 12:22 - 2012-02-23 10:42 - 00000000 ___RD () C:\Users\Dima\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-02-15 12:01 - 2014-02-15 12:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-15 10:45 - 2014-01-06 12:05 - 00011317 _____ () C:\Users\Dima\AppData\Roaming\PStrip.bak 2014-02-15 03:34 - 2014-01-06 12:05 - 00011649 _____ () C:\Users\Dima\AppData\Roaming\PStrip.bk! 2014-02-14 22:53 - 2014-01-07 17:31 - 00011632 _____ () C:\Users\Dima\AppData\Roaming\PStrip.bko 2014-02-13 20:46 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-02-08 20:57 - 2014-02-08 12:43 - 00010619 _____ () C:\Users\Dima\Desktop\STR-KRR.xlsx 2014-02-08 19:34 - 2014-02-18 22:27 - 31432480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 23683360 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 17715784 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 15740232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 12324640 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-08 19:34 - 2014-02-18 22:27 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 03142432 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 02956576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 02782496 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 02410784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433489.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433489.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00892192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00875296 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00863520 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00844576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00832424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-02-08 19:34 - 2014-02-18 22:27 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-02-08 19:34 - 2013-11-26 22:52 - 02713728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-02-08 19:34 - 2013-09-10 22:43 - 00061216 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-02-08 19:34 - 2013-09-10 22:43 - 00053024 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 18257576 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 14669032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 03090184 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 00947296 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 00148528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2014-02-08 19:34 - 2013-04-19 22:30 - 00024544 _____ () C:\Windows\system32\nvinfo.pb 2014-02-08 18:42 - 2013-09-10 21:57 - 06712608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-08 18:42 - 2013-09-10 21:57 - 03498272 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-02-08 18:42 - 2013-09-10 21:57 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-08 18:42 - 2013-09-10 21:57 - 00923936 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-08 18:42 - 2013-09-10 21:57 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-08 18:42 - 2013-09-10 21:57 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-08 17:18 - 2014-02-18 22:29 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-02-06 13:16 - 2014-02-12 22:40 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-06 12:30 - 2014-02-12 22:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-06 12:30 - 2014-02-12 22:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-06 12:12 - 2014-02-12 22:40 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-06 12:07 - 2014-02-12 22:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-06 12:06 - 2014-02-12 22:40 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-06 11:57 - 2014-02-12 22:40 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-06 11:56 - 2014-02-12 22:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-06 11:52 - 2014-02-12 22:40 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-06 11:49 - 2014-02-12 22:40 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-06 11:48 - 2014-02-12 22:40 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-06 11:48 - 2014-02-12 22:40 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-06 11:38 - 2014-02-12 22:40 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-06 11:32 - 2014-02-12 22:40 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-06 11:20 - 2014-02-12 22:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-06 11:17 - 2014-02-12 22:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-06 11:11 - 2014-02-12 22:40 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-06 11:01 - 2014-02-12 22:40 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-06 11:00 - 2014-02-12 22:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-06 10:57 - 2014-02-12 22:40 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-06 10:57 - 2014-02-12 22:40 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-06 10:52 - 2014-02-12 22:40 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-06 10:52 - 2014-02-12 22:40 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-06 10:50 - 2014-02-12 22:40 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-06 10:49 - 2014-02-12 22:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-06 10:47 - 2014-02-12 22:40 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-06 10:46 - 2014-02-12 22:40 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-06 10:25 - 2014-02-12 22:40 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-06 10:25 - 2014-02-12 22:40 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-06 10:24 - 2014-02-12 22:40 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-06 10:22 - 2014-02-12 22:40 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-06 10:13 - 2014-02-12 22:40 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-06 10:09 - 2014-02-12 22:40 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-06 10:03 - 2014-02-12 22:40 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-06 09:55 - 2014-02-12 22:40 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-06 09:41 - 2014-02-12 22:40 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-06 09:40 - 2014-02-12 22:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-06 09:36 - 2014-02-12 22:40 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-06 09:34 - 2014-02-12 22:40 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-05 18:52 - 2013-09-10 21:57 - 03573739 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-02 13:08 - 2012-10-19 21:49 - 00014692 _____ () C:\Users\Dima\Desktop\Ausgaben.xlsx 2014-01-30 17:26 - 2012-02-23 12:58 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\App Launcher Gadget 2014-01-29 21:16 - 2012-02-29 22:15 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-01-29 19:04 - 2014-01-29 19:04 - 01192533 _____ () C:\Windows\unins000.exe 2014-01-29 19:04 - 2014-01-29 19:04 - 00018226 _____ () C:\Windows\unins000.dat 2014-01-29 19:04 - 2014-01-29 19:04 - 00000000 ____D () C:\Users\Dima\AppData\Roaming\MingGuan 2014-01-29 19:04 - 2014-01-29 19:04 - 00000000 ____D () C:\Program Files (x86)\Drakonia Configurator 2014-01-29 19:04 - 2014-01-29 15:40 - 00000000 ____D () C:\Program Files (x86)\Drakonia Black Files to move or delete: ==================== C:\Users\Dima\Network_Meter_Data.js ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-19 19:14 ==================== End Of Log ============================ --- --- --- Bis auf das der Rechner langsamer startet als sonst, nichts Auffäliges. Erwarte weitere Anweisungen! |
loadtbs-2.1 & loadtbs-3.0 HILFE! Servus, Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 2 h) dauern. Im Anschluss daran räumen wir auf und ich gebe dir noch ein paar Tipps mit auf den Weg.
Schritt 2 Downloade dir die passende Version von HitmanPro auf deinen Desktop: HitmanPro - 32 Bit | HitmanPro - 64 Bit.
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte ![]()
Bitte poste mit deiner nächsten Antwort
loadtbs-2.1 & loadtbs-3.0 HILFE! Hier nun die Ergebnisse: Mir ist aufgefallen, dass allshare die neuen Videofiles nicht mehr einbezieht und diese, obwohl in windows-explorer vorhanden, nicht im Programm zu sehen sind. Wenn ich den rechner auf Anweisung von instllierten Programmen befreit habe, versuche ich das Programm neu zu installieren, evtl. klappts dann. Ist etwas was mir direkt aufgefallen ist. Mal gucken ob noch etwas krum läuft, der Dauertest zeigts dann.
loadtbs-2.1 & loadtbs-3.0 HILFE! Servus, ggf. musst du das genannte Programm neu installieren. Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern.
Schritt 2 Deinstalliere bitte deine aktuelle Version von Adobe Reader Start--> Systemsteuerung--> Software / Programme deinstallieren--> Adobe Reader und lade dir die neue Version von Hier herunter- Entferne den Hacken für den McAfee SecurityScan bzw. Google Chrome. Schritt 3 Die Reihenfolge ist hier entscheidend.
Schritt 4 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
loadtbs-2.1 & loadtbs-3.0 HILFE! Also nach der ganzen Bereinigung kann ich folgendes Statement abgeben: das System hat jetzt einen Haufen Ordner, die ich nicht entfernen kann Zugriff verweigert!??? was soll das? Windows startet gefühlt dreimal länger als vorher mit "schädlicher" Software. Ich brauche keine zusätzliche Software, ich wollte die wenigen Programme entfernen und nichts mehr.
![]() | #12 | |||
loadtbs-2.1 & loadtbs-3.0 HILFE! Servus,
![]() Bitte dazu mal folgendes durchführen: Klicke auf Start > Computer Wähle links oben Organisieren > Ordner- und Suchoptionen Klicke auf den Tab Ansicht Setze einen Haken bei
Lade dir ![]()
Der nächste Neustart könnte noch etwas länger dauern, dann sollte es aber wieder flüssiger gehen. Zitat:
![]() Wir haben die wenigen schädlichen Programme entfernt (Adware). Wenn du DelFix (wie in meinem All-Clean Baustein gepostet) ausführst, werden alle Bereinigungs-Tools, die wir verwendet haben, automatisch entfernt. Sollte dann immer noch Reste unserer Tools vorhanden sein, dann kannst du mir das mitteilen, dann kümmern wir uns darum. ![]() Ich bin froh, dass wir helfen konnten ![]() In diesem Forum kannst du eine kurze Rückmeldung zur Bereinigung abgeben, sofern du das möchtest: Lob, Kritik und Wünsche Klicke dazu auf den Button "NEUES THEMA" und poste ein kleines Feedback. Vielen Dank! ![]() Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen, schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen. |
![]() |
