|
Plagegeister aller Art und deren Bekämpfung: Ordner erstellen sich von selbst. Virus?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.03.2014, 18:37 | #1 |
| Ordner erstellen sich von selbst. Virus? Guten Tag zusammen, auf einer meiner Partitionen finde ich immer wieder seltsame Ordner, mit Namen wie "f39493g5355i348w883..." oder ähnlichem. Ich habe keine Ahnung wie sowas zustande kommt, hat da jemand einen Verdacht? Wäre um Hilfe dankbar. |
09.03.2014, 20:00 | #2 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus? hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
10.03.2014, 21:02 | #3 | |
| Ordner erstellen sich von selbst. Virus? Ok erledigt.
__________________Die FRST.txt: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-03-2014 01 Ran by Felix (administrator) on FELIX-PC on 10-03-2014 20:58:42 Running from C:\Users\Felix\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums ==================== Processes (Whitelisted) ================= (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Octoshape ApS) C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Spotify Ltd) C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Felix\AppData\Roaming\Spotify\spotify.exe () C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Dropbox, Inc.) C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe () C:\Program Files (x86)\AVG Secure Search\vprot.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\COMODO\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\COMODO\GeekBuddy\unit.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (BioWare) E:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\loggingserver.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [9577680 2012-11-08] (COMODO) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [37888 2010-01-13] (Nullsoft, Inc.) HKLM-x32\...\Run: [avast5] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [3396624 2011-01-13] (AVAST Software) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.) HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG Secure Search\vprot.exe [2539544 2014-03-03] () HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641664 2012-04-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-02-20] () HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [tvncontrol] - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Octoshape Streaming Services] - C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [70936 2009-01-08] (Octoshape ApS) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Spotify Web Helper] - C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-16] (Spotify Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Spotify] - C:\Users\Felix\AppData\Roaming\Spotify\spotify.exe [6118400 2014-01-16] (Spotify Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-09] () HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\MountPoints2: {1714c11a-61ae-11df-b39c-00241d821094} - G:\setup.exe AppInit_DLLs: C:\Windows\system32\guard64.dll => C:\Windows\system32\guard64.dll [390392 2012-11-08] (COMODO) AppInit_DLLs-x32: C:\Windows\SysWOW64\guard32.dll => C:\Windows\SysWOW64\guard32.dll [301264 2012-11-08] (COMODO) Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://isearch.avg.com/?cid=&mid=&lang=&ds=&pr=&d=&v=&sap=hp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5C4725DD35DECA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={0F404FD7-C580-4660-B04A-78E337DE22F4}&mid=098d6f0080cd47d08927d16d5b66f967-25a8d5d775611c681fc9c33c713afa95ad7b16fa&lang=&ds=&pr=&d=&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} SearchScopes: HKCU - {67407DAF-88D3-44F4-9281-FC310DA84039} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://isearch.avg.com/search?cid={0F404FD7-C580-4660-B04A-78E337DE22F4}&mid=098d6f0080cd47d08927d16d5b66f967-25a8d5d775611c681fc9c33c713afa95ad7b16fa&lang=&ds=&pr=&d=&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.0.0.248\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\18.0.0.248\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.0\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.0\\npsitesafety.dll (AVG Technologies) FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Felix\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus Pop-up Addon - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351\Extensions\adblockpopups@jessehakanen.net.xpi [2013-11-14] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15] FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\18.0.0.248 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\18.0.0.248 [2014-03-03] FF HKCU\...\Firefox\Extensions: [firejump@firejump.net] - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\q9wy2oqr.default\extensions\firejump@firejump.net ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-04-05] (Advanced Micro Devices, Inc.) R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2011-01-13] (AVAST Software) R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) R2 cmdagent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2828408 2012-11-08] (COMODO) R2 DAUpdaterSvc; E:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare) R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) R2 vToolbarUpdater18.0.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [1759768 2014-03-03] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [20560 2011-01-13] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [62032 2011-01-13] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [29264 2011-01-13] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [273488 2011-01-13] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [51792 2011-01-13] (AVAST Software) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-03-03] (AVG Technologies) S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [22736 2012-11-08] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [584056 2012-11-08] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [38144 2012-11-08] (COMODO) S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [25704 2012-08-13] () R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [94288 2012-11-08] (COMODO) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-17] () S3 zlportio; C:\Program Files (x86)\UltraStar\zlportio.sys [4016 2001-09-22] (SpecoSoft) U3 ah8psk1s; C:\Windows\System32\Drivers\ah8psk1s.sys [0 ] (Microsoft Corporation) S3 ALSysIO; \??\C:\Users\Felix\AppData\Local\Temp\ALSysIO64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-10 20:53 - 2014-03-10 20:58 - 00015910 _____ () C:\Users\Felix\Desktop\FRST.txt 2014-03-10 20:50 - 2014-03-10 20:51 - 00002998 _____ () C:\Users\Felix\Downloads\Addition.txt 2014-03-10 20:49 - 2014-03-10 20:58 - 00000000 ____D () C:\FRST 2014-03-10 20:48 - 2014-03-10 20:48 - 02157056 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe 2014-03-10 20:45 - 2014-03-10 20:45 - 563095782 _____ () C:\Users\Felix\Downloads\The.Kings.of.Summer.2013.720p.BluRay.x264.YIFY.mp4.part 2014-03-10 20:45 - 2014-03-10 20:45 - 00000000 _____ () C:\Users\Felix\Downloads\The.Kings.of.Summer.2013.720p.BluRay.x264.YIFY.mp4 2014-03-03 19:21 - 2014-03-03 19:22 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-02-22 15:41 - 2014-03-05 19:27 - 00001090 _____ () C:\Windows\PFRO.log 2014-02-21 20:36 - 2014-02-21 20:36 - 17858952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-02-15 17:33 - 2014-02-15 17:33 - 00001966 _____ () C:\Users\Public\Desktop\Deeper Dungeons.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00001956 _____ () C:\Users\Public\Desktop\Dungeon Keeper Gold.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00000000 ____D () C:\GOG Games 2014-02-15 00:27 - 2014-02-15 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-12 17:25 - 2014-03-10 20:28 - 00003584 _____ () C:\Windows\setupact.log 2014-02-12 17:25 - 2014-02-12 17:25 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-12 08:47 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 08:47 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 08:47 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 08:47 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 08:47 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 08:47 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 08:47 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 08:47 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 08:47 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 08:47 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 08:47 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 08:47 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 08:47 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 08:47 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 08:47 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 08:47 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 08:47 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 08:47 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 08:47 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-12 08:47 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 08:47 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 08:47 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 08:47 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 08:47 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 08:47 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-12 08:47 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-12 08:47 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-12 08:47 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 08:47 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 08:47 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 08:47 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 08:47 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 08:47 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-12 08:47 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 08:47 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 08:47 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 08:47 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 08:47 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 08:47 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 08:47 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 08:47 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 07:45 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 07:45 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 07:45 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 07:45 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 07:45 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 07:45 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 07:45 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 07:45 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 07:45 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 07:45 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 07:45 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 07:45 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 07:45 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 07:45 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 07:45 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 07:45 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 07:45 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 07:45 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 07:45 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 07:45 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 07:44 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 07:44 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 07:44 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 07:44 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll ==================== One Month Modified Files and Folders ======= 2014-03-10 20:58 - 2014-03-10 20:53 - 00015910 _____ () C:\Users\Felix\Desktop\FRST.txt 2014-03-10 20:58 - 2014-03-10 20:49 - 00000000 ____D () C:\FRST 2014-03-10 20:58 - 2011-05-20 20:39 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-03-10 20:53 - 2009-07-14 05:45 - 00014752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-10 20:53 - 2009-07-14 05:45 - 00014752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-10 20:51 - 2014-03-10 20:50 - 00002998 _____ () C:\Users\Felix\Downloads\Addition.txt 2014-03-10 20:48 - 2014-03-10 20:48 - 02157056 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe 2014-03-10 20:45 - 2014-03-10 20:45 - 563095782 _____ () C:\Users\Felix\Downloads\The.Kings.of.Summer.2013.720p.BluRay.x264.YIFY.mp4.part 2014-03-10 20:45 - 2014-03-10 20:45 - 00000000 _____ () C:\Users\Felix\Downloads\The.Kings.of.Summer.2013.720p.BluRay.x264.YIFY.mp4 2014-03-10 20:36 - 2012-04-04 09:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-10 20:34 - 2010-03-03 13:12 - 01498036 _____ () C:\Windows\WindowsUpdate.log 2014-03-10 20:30 - 2013-06-03 21:16 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2014-03-10 20:30 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-10 20:29 - 2012-05-03 17:48 - 00000000 ___RD () C:\Users\Felix\Dropbox 2014-03-10 20:29 - 2012-05-03 17:44 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Dropbox 2014-03-10 20:29 - 2012-03-30 20:13 - 00000000 ____D () C:\Users\Felix\AppData\Local\Spotify 2014-03-10 20:29 - 2012-03-30 20:12 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Spotify 2014-03-10 20:28 - 2014-02-12 17:25 - 00003584 _____ () C:\Windows\setupact.log 2014-03-09 18:01 - 2010-03-19 22:41 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Winamp 2014-03-09 13:59 - 2011-01-29 21:08 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\uTorrent 2014-03-09 12:41 - 2009-07-14 18:58 - 00664618 _____ () C:\Windows\system32\perfh007.dat 2014-03-09 12:41 - 2009-07-14 18:58 - 00134786 _____ () C:\Windows\system32\perfc007.dat 2014-03-09 12:41 - 2009-07-14 06:13 - 01527550 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-05 19:27 - 2014-02-22 15:41 - 00001090 _____ () C:\Windows\PFRO.log 2014-03-03 19:22 - 2014-03-03 19:21 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-03-03 19:22 - 2013-05-27 07:23 - 00003702 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2014-03-03 19:21 - 2012-09-04 14:12 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-03-03 19:21 - 2012-04-25 10:13 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search 2014-02-28 23:02 - 2013-02-14 14:26 - 00002043 _____ () C:\Users\Public\Desktop\GeekBuddy.lnk 2014-02-28 08:29 - 2010-05-16 13:38 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Skype 2014-02-23 17:36 - 2011-01-26 19:44 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\vlc 2014-02-21 20:36 - 2014-02-21 20:36 - 17858952 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-02-21 20:36 - 2012-04-04 09:55 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-02-21 20:36 - 2012-04-04 09:55 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-02-21 20:36 - 2011-05-25 19:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-02-17 03:03 - 2013-08-04 22:18 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 03:01 - 2010-03-03 13:35 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 17:33 - 2014-02-15 17:33 - 00001966 _____ () C:\Users\Public\Desktop\Deeper Dungeons.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00001956 _____ () C:\Users\Public\Desktop\Dungeon Keeper Gold.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00000000 ____D () C:\GOG Games 2014-02-15 17:13 - 2013-08-02 06:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-15 00:27 - 2014-02-15 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-12 17:25 - 2014-02-12 17:25 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-10 18:04 - 2014-01-03 07:59 - 00430080 _____ (Farbar) C:\Windows\mod_frst.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-02 14:00 ==================== End Of Log ============================ Und die Addition.txt: Zitat:
|
11.03.2014, 13:46 | #4 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus? Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.03.2014, 19:04 | #5 | ||
| Ordner erstellen sich von selbst. Virus? So alles klar: Malwarebites: Zitat:
AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.021 - Bericht erstellt am 12/03/2014 um 23:00:13 # Aktualisiert 10/03/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Felix - FELIX-PC # Gestartet von : C:\Users\Felix\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\AVG Secure Search Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Program Files (x86)\Common Files\Spigot Ordner Gelöscht : C:\Users\Felix\AppData\Local\AVG Secure Search Ordner Gelöscht : C:\Users\Felix\AppData\LocalLow\AVG Secure Search Ordner Gelöscht : C:\Users\Felix\AppData\LocalLow\pdfforge Ordner Gelöscht : C:\Users\Felix\AppData\Roaming\dvdvideosoftiehelpers Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [firejump@firejump.net] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\S Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader32736_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader32736_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_utorrent_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_utorrent_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\IGearSettings Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar Schlüssel Gelöscht : HKLM\Software\Freeze.com Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D85FFE92-BF14-4E9B-BCCD-E5C16069E65F}_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v27.0.1 (de) [ Datei : C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351\prefs.js ] ************************* AdwCleaner[R0].txt - [8993 octets] - [12/03/2014 22:59:40] AdwCleaner[S0].txt - [8410 octets] - [12/03/2014 23:00:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8470 octets] ########## JRT.txt (am anfang gab es ein paar Fehlermeldungen): Zitat:
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-03-2014 01 Ran by Felix (administrator) on FELIX-PC on 13-03-2014 19:03:43 Running from C:\Users\Felix\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Octoshape ApS) C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Spotify Ltd) C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe () C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Dropbox, Inc.) C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\COMODO\GeekBuddy\unit_manager.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\COMODO\GeekBuddy\unit.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (BioWare) E:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [9577680 2012-11-08] (COMODO) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [37888 2010-01-13] (Nullsoft, Inc.) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641664 2012-04-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-02-20] () HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [tvncontrol] - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Octoshape Streaming Services] - C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [70936 2009-01-08] (Octoshape ApS) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Spotify Web Helper] - C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-16] (Spotify Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Spotify] - C:\Users\Felix\AppData\Roaming\Spotify\spotify.exe [6118400 2014-01-16] (Spotify Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-09] () HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\MountPoints2: {1714c11a-61ae-11df-b39c-00241d821094} - G:\setup.exe AppInit_DLLs: C:\Windows\system32\guard64.dll => C:\Windows\system32\guard64.dll [390392 2012-11-08] (COMODO) AppInit_DLLs-x32: C:\Windows\SysWOW64\guard32.dll => C:\Windows\SysWOW64\guard32.dll [301264 2012-11-08] (COMODO) Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5C4725DD35DECA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKCU - {67407DAF-88D3-44F4-9281-FC310DA84039} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Felix\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus Pop-up Addon - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351\Extensions\adblockpopups@jessehakanen.net.xpi [2013-11-14] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-04-05] (Advanced Micro Devices, Inc.) R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) R2 cmdagent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2828408 2012-11-08] (COMODO) R2 DAUpdaterSvc; E:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare) R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) S2 vToolbarUpdater18.0.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-03-03] (AVG Technologies) S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [22736 2012-11-08] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [584056 2012-11-08] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [38144 2012-11-08] (COMODO) S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [25704 2012-08-13] () R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [94288 2012-11-08] (COMODO) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-17] () S3 zlportio; C:\Program Files (x86)\UltraStar\zlportio.sys [4016 2001-09-22] (SpecoSoft) U3 aqztyvy3; C:\Windows\System32\Drivers\aqztyvy3.sys [0 ] (Microsoft Corporation) S3 ALSysIO; \??\C:\Users\Felix\AppData\Local\Temp\ALSysIO64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-13 08:58 - 2014-03-13 08:58 - 00000771 _____ () C:\Users\Felix\Desktop\JRT.txt 2014-03-13 07:54 - 2014-03-13 07:54 - 00000000 ____D () C:\Program Files\7-Zip 2014-03-13 07:53 - 2014-03-13 07:53 - 01376768 _____ () C:\Users\Felix\Downloads\7z920-x64.msi 2014-03-13 07:48 - 2014-03-13 07:48 - 00512784 _____ (AVAST Software) C:\Users\Felix\Downloads\avastclear_9.0.2013.exe 2014-03-12 23:10 - 2014-03-12 23:10 - 00000000 ____D () C:\Windows\ERUNT 2014-03-12 23:09 - 2014-03-12 23:09 - 01037734 _____ (Thisisu) C:\Users\Felix\Desktop\JRT.exe 2014-03-12 23:08 - 2014-03-12 23:08 - 00008570 _____ () C:\Users\Felix\Desktop\AdwCleaner[S0].txt 2014-03-12 22:59 - 2014-03-12 23:00 - 00000000 ____D () C:\AdwCleaner 2014-03-12 21:29 - 2014-03-12 21:29 - 01949184 _____ () C:\Users\Felix\Desktop\adwcleaner.exe 2014-03-12 21:04 - 2014-03-12 21:04 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-12 21:04 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-12 21:03 - 2014-03-12 21:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Felix\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-10 20:53 - 2014-03-13 19:03 - 00011777 _____ () C:\Users\Felix\Desktop\FRST.txt 2014-03-10 20:50 - 2014-03-10 20:51 - 00002998 _____ () C:\Users\Felix\Downloads\Addition.txt 2014-03-10 20:49 - 2014-03-13 19:03 - 00000000 ____D () C:\FRST 2014-03-10 20:48 - 2014-03-10 20:48 - 02157056 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe 2014-02-22 15:41 - 2014-03-12 21:33 - 00001654 _____ () C:\Windows\PFRO.log 2014-02-15 17:33 - 2014-02-15 17:33 - 00001966 _____ () C:\Users\Public\Desktop\Deeper Dungeons.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00001956 _____ () C:\Users\Public\Desktop\Dungeon Keeper Gold.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00000000 ____D () C:\GOG Games 2014-02-15 00:27 - 2014-02-15 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-12 17:25 - 2014-03-13 07:41 - 00004032 _____ () C:\Windows\setupact.log 2014-02-12 17:25 - 2014-02-12 17:25 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-12 08:47 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-02-12 08:47 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-02-12 08:47 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-02-12 08:47 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-02-12 08:47 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-02-12 08:47 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-02-12 08:47 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-02-12 08:47 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-02-12 08:47 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-02-12 08:47 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-02-12 08:47 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-02-12 08:47 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-02-12 08:47 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-02-12 08:47 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-02-12 08:47 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-02-12 08:47 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-02-12 08:47 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-02-12 08:47 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-02-12 08:47 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-02-12 08:47 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-02-12 08:47 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-02-12 08:47 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-02-12 08:47 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-02-12 08:47 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-02-12 08:47 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-02-12 08:47 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-02-12 08:47 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-02-12 08:47 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-02-12 08:47 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-02-12 08:47 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-02-12 08:47 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-02-12 08:47 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-02-12 08:47 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-02-12 08:47 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-02-12 08:47 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-02-12 08:47 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-02-12 08:47 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-02-12 08:47 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-02-12 08:47 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-12 08:47 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-02-12 08:47 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-02-12 07:45 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-02-12 07:45 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-02-12 07:45 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-02-12 07:45 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-02-12 07:45 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-02-12 07:45 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-02-12 07:45 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-02-12 07:45 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-02-12 07:45 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-02-12 07:45 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-02-12 07:45 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-02-12 07:45 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-02-12 07:45 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-02-12 07:45 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-02-12 07:45 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-02-12 07:45 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-02-12 07:45 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-02-12 07:45 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-02-12 07:45 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-02-12 07:45 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-02-12 07:45 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-02-12 07:44 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2014-02-12 07:44 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2014-02-12 07:44 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2014-02-12 07:44 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll ==================== One Month Modified Files and Folders ======= 2014-03-13 19:04 - 2014-03-10 20:53 - 00011777 _____ () C:\Users\Felix\Desktop\FRST.txt 2014-03-13 19:03 - 2014-03-10 20:49 - 00000000 ____D () C:\FRST 2014-03-13 19:01 - 2011-05-20 20:39 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-03-13 18:51 - 2012-04-04 09:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-13 18:51 - 2010-03-03 13:12 - 01742883 _____ () C:\Windows\WindowsUpdate.log 2014-03-13 08:58 - 2014-03-13 08:58 - 00000771 _____ () C:\Users\Felix\Desktop\JRT.txt 2014-03-13 07:54 - 2014-03-13 07:54 - 00000000 ____D () C:\Program Files\7-Zip 2014-03-13 07:53 - 2014-03-13 07:53 - 01376768 _____ () C:\Users\Felix\Downloads\7z920-x64.msi 2014-03-13 07:51 - 2010-04-10 17:15 - 00000000 _____ () C:\Windows\SysWOW64\config.nt 2014-03-13 07:51 - 2010-04-10 17:14 - 00000000 ____D () C:\ProgramData\Alwil Software 2014-03-13 07:50 - 2009-07-14 05:45 - 00014752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-13 07:50 - 2009-07-14 05:45 - 00014752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-13 07:48 - 2014-03-13 07:48 - 00512784 _____ (AVAST Software) C:\Users\Felix\Downloads\avastclear_9.0.2013.exe 2014-03-13 07:45 - 2012-03-30 20:12 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Spotify 2014-03-13 07:43 - 2013-06-03 21:16 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2014-03-13 07:43 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-13 07:42 - 2012-05-03 17:48 - 00000000 ___RD () C:\Users\Felix\Dropbox 2014-03-13 07:42 - 2012-05-03 17:44 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Dropbox 2014-03-13 07:41 - 2014-02-12 17:25 - 00004032 _____ () C:\Windows\setupact.log 2014-03-12 23:10 - 2014-03-12 23:10 - 00000000 ____D () C:\Windows\ERUNT 2014-03-12 23:09 - 2014-03-12 23:09 - 01037734 _____ (Thisisu) C:\Users\Felix\Desktop\JRT.exe 2014-03-12 23:08 - 2014-03-12 23:08 - 00008570 _____ () C:\Users\Felix\Desktop\AdwCleaner[S0].txt 2014-03-12 23:00 - 2014-03-12 22:59 - 00000000 ____D () C:\AdwCleaner 2014-03-12 22:36 - 2012-04-04 09:55 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 22:36 - 2012-04-04 09:55 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 22:36 - 2011-05-25 19:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 21:33 - 2014-02-22 15:41 - 00001654 _____ () C:\Windows\PFRO.log 2014-03-12 21:29 - 2014-03-12 21:29 - 01949184 _____ () C:\Users\Felix\Desktop\adwcleaner.exe 2014-03-12 21:28 - 2012-07-12 20:34 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Vilu 2014-03-12 21:28 - 2012-03-13 13:49 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Url 2014-03-12 21:24 - 2010-03-19 22:41 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Winamp 2014-03-12 21:04 - 2014-03-12 21:04 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-12 21:03 - 2014-03-12 21:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Felix\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-11 21:37 - 2009-07-14 18:58 - 00664618 _____ () C:\Windows\system32\perfh007.dat 2014-03-11 21:37 - 2009-07-14 18:58 - 00134786 _____ () C:\Windows\system32\perfc007.dat 2014-03-11 21:37 - 2009-07-14 06:13 - 01527550 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-11 21:25 - 2011-01-29 21:08 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\uTorrent 2014-03-10 20:51 - 2014-03-10 20:50 - 00002998 _____ () C:\Users\Felix\Downloads\Addition.txt 2014-03-10 20:48 - 2014-03-10 20:48 - 02157056 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe 2014-03-10 20:29 - 2012-03-30 20:13 - 00000000 ____D () C:\Users\Felix\AppData\Local\Spotify 2014-03-03 19:22 - 2013-05-27 07:23 - 00003702 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2014-03-03 19:21 - 2012-09-04 14:12 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-02-28 23:02 - 2013-02-14 14:26 - 00002043 _____ () C:\Users\Public\Desktop\GeekBuddy.lnk 2014-02-28 08:29 - 2010-05-16 13:38 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Skype 2014-02-23 17:36 - 2011-01-26 19:44 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\vlc 2014-02-17 03:03 - 2013-08-04 22:18 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-17 03:01 - 2010-03-03 13:35 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-15 17:33 - 2014-02-15 17:33 - 00001966 _____ () C:\Users\Public\Desktop\Deeper Dungeons.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00001956 _____ () C:\Users\Public\Desktop\Dungeon Keeper Gold.lnk 2014-02-15 17:33 - 2014-02-15 17:33 - 00000000 ____D () C:\GOG Games 2014-02-15 17:13 - 2013-08-02 06:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-02-15 00:27 - 2014-02-15 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-02-12 17:25 - 2014-02-12 17:25 - 00000000 _____ () C:\Windows\setuperr.log Some content of TEMP: ==================== C:\Users\Felix\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-10 21:25 ==================== End Of Log ============================ Dankeschön! |
14.03.2014, 18:35 | #6 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus?ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Ordner erstellen sich von selbst. Virus? |
18.03.2014, 19:39 | #7 | |||
| Ordner erstellen sich von selbst. Virus? Alles klar, hab zwar drei Anläufe gebraucht, aber hier ist das log: Zitat:
Zitat:
Zitat:
Aber der EsetScan hat zwei Bedrohungen gefunden, was ist damit zu tun? |
19.03.2014, 14:42 | #8 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus? Das sind Fehlalarme. Frisches FRST log fehlt noch
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.03.2014, 08:28 | #9 |
| Ordner erstellen sich von selbst. Virus? Ups, copy+paste! So hier: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-03-2014 01 Ran by Felix (administrator) on FELIX-PC on 20-03-2014 08:26:40 Running from C:\Users\Felix\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (Octoshape ApS) C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Spotify Ltd) C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd) C:\Users\Felix\AppData\Roaming\Spotify\spotify.exe () C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Dropbox, Inc.) C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe () C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe () C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe () C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyHelper.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\COMODO\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.) C:\Program Files (x86)\COMODO\GeekBuddy\unit.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [9577680 2012-11-08] (COMODO) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [37888 2010-01-13] (Nullsoft, Inc.) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641664 2012-04-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [10752 2012-02-20] () HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [tvncontrol] - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Octoshape Streaming Services] - C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [70936 2009-01-08] (Octoshape ApS) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Spotify Web Helper] - C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-16] (Spotify Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [Spotify] - C:\Users\Felix\AppData\Roaming\Spotify\spotify.exe [6118400 2014-01-16] (Spotify Ltd) HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-09] () HKU\S-1-5-21-3168880282-2487564817-2207744468-1001\...\MountPoints2: {1714c11a-61ae-11df-b39c-00241d821094} - G:\setup.exe AppInit_DLLs: C:\Windows\system32\guard64.dll => C:\Windows\system32\guard64.dll [390392 2012-11-08] (COMODO) AppInit_DLLs-x32: C:\Windows\SysWOW64\guard32.dll => C:\Windows\SysWOW64\guard32.dll [301264 2012-11-08] (COMODO) Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk ShortcutTarget: OpenOffice.org 3.2.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5C4725DD35DECA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKCU - {67407DAF-88D3-44F4-9281-FC310DA84039} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=302398&p={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\Felix\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Felix\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdivx32.dll (DivX,Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF Plugin ProgramFiles/Appdata: C:\Users\Felix\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus Pop-up Addon - C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\tc0rd64k.default-1384460130351\Extensions\adblockpopups@jessehakanen.net.xpi [2013-11-14] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-15] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-02-15] ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-04-05] (Advanced Micro Devices, Inc.) R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) R2 cmdagent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2828408 2012-11-08] (COMODO) S2 DAUpdaterSvc; E:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare) R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) S2 vToolbarUpdater18.0.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [X] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices) R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50976 2014-03-03] (AVG Technologies) S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [22736 2012-11-08] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [584056 2012-11-08] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [38144 2012-11-08] (COMODO) S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [25704 2012-08-13] () R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [94288 2012-11-08] (COMODO) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-05-17] () S3 zlportio; C:\Program Files (x86)\UltraStar\zlportio.sys [4016 2001-09-22] (SpecoSoft) U3 a4yly5br; C:\Windows\System32\Drivers\a4yly5br.sys [0 ] (Microsoft Corporation) S3 ALSysIO; \??\C:\Users\Felix\AppData\Local\Temp\ALSysIO64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-18 19:07 - 2014-03-18 19:07 - 00987442 _____ () C:\Users\Felix\Desktop\SecurityCheck.exe 2014-03-16 13:03 - 2014-03-16 13:03 - 02347384 _____ (ESET) C:\Users\Felix\Downloads\esetsmartinstaller_enu.exe 2014-03-15 22:06 - 2014-03-15 22:09 - 191451243 _____ () C:\Users\Felix\Downloads\Modern.Family.S03E18.HDTV.x264-LOL.mp4 2014-03-15 19:54 - 2014-03-15 20:18 - 911929996 _____ () C:\Users\Felix\Downloads\Dallas.Buyers.Club.2013.720p.BluRay.x264.YIFY.mp4 2014-03-15 19:52 - 2014-03-15 19:55 - 183206706 _____ () C:\Users\Felix\Downloads\Modern.Family.S03E17.HDTV.XviD-2HD.avi 2014-03-13 08:58 - 2014-03-13 08:58 - 00000771 _____ () C:\Users\Felix\Desktop\JRT.txt 2014-03-13 07:54 - 2014-03-13 07:54 - 00000000 ____D () C:\Program Files\7-Zip 2014-03-13 07:53 - 2014-03-13 07:53 - 01376768 _____ () C:\Users\Felix\Downloads\7z920-x64.msi 2014-03-13 07:52 - 2014-03-01 07:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 07:52 - 2014-03-01 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 07:52 - 2014-03-01 06:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 07:52 - 2014-03-01 05:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 07:52 - 2014-03-01 05:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 07:52 - 2014-03-01 05:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 07:52 - 2014-03-01 05:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 07:52 - 2014-03-01 05:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 07:52 - 2014-03-01 05:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 07:52 - 2014-03-01 05:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 07:52 - 2014-03-01 05:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 07:52 - 2014-03-01 05:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 07:52 - 2014-03-01 05:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 07:52 - 2014-03-01 05:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 07:52 - 2014-03-01 05:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 07:52 - 2014-03-01 05:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 07:52 - 2014-03-01 05:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 07:52 - 2014-03-01 04:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 07:52 - 2014-03-01 04:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 07:52 - 2014-03-01 04:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 07:52 - 2014-03-01 04:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 07:52 - 2014-03-01 04:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 07:52 - 2014-03-01 04:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 07:52 - 2014-03-01 04:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 07:52 - 2014-03-01 04:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 07:52 - 2014-03-01 04:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 07:52 - 2014-03-01 04:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 07:52 - 2014-03-01 04:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 07:52 - 2014-03-01 04:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 07:52 - 2014-03-01 04:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 07:52 - 2014-03-01 04:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 07:52 - 2014-03-01 04:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 07:52 - 2014-03-01 04:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 07:52 - 2014-03-01 04:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 07:52 - 2014-03-01 03:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 07:52 - 2014-03-01 03:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 07:52 - 2014-03-01 03:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 07:52 - 2014-03-01 03:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 07:52 - 2014-03-01 03:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 07:52 - 2014-03-01 03:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 07:52 - 2014-02-07 02:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 07:52 - 2014-02-04 03:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 07:52 - 2014-02-04 03:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 07:52 - 2014-02-04 03:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 07:52 - 2014-02-04 03:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 07:52 - 2014-01-29 03:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 07:52 - 2014-01-29 03:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 07:52 - 2014-01-28 03:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-13 07:48 - 2014-03-13 07:48 - 00512784 _____ (AVAST Software) C:\Users\Felix\Downloads\avastclear_9.0.2013.exe 2014-03-12 23:10 - 2014-03-12 23:10 - 00000000 ____D () C:\Windows\ERUNT 2014-03-12 23:09 - 2014-03-12 23:09 - 01037734 _____ (Thisisu) C:\Users\Felix\Desktop\JRT.exe 2014-03-12 23:08 - 2014-03-12 23:08 - 00008570 _____ () C:\Users\Felix\Desktop\AdwCleaner[S0].txt 2014-03-12 22:59 - 2014-03-12 23:00 - 00000000 ____D () C:\AdwCleaner 2014-03-12 21:29 - 2014-03-12 21:29 - 01949184 _____ () C:\Users\Felix\Desktop\adwcleaner.exe 2014-03-12 21:04 - 2014-03-12 21:04 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-12 21:04 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-12 21:03 - 2014-03-12 21:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Felix\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-10 20:53 - 2014-03-20 08:26 - 00012318 _____ () C:\Users\Felix\Desktop\FRST.txt 2014-03-10 20:50 - 2014-03-10 20:51 - 00002998 _____ () C:\Users\Felix\Downloads\Addition.txt 2014-03-10 20:49 - 2014-03-20 08:26 - 00000000 ____D () C:\FRST 2014-03-10 20:48 - 2014-03-10 20:48 - 02157056 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe 2014-02-22 15:41 - 2014-03-19 08:12 - 00002472 _____ () C:\Windows\PFRO.log ==================== One Month Modified Files and Folders ======= 2014-03-20 08:26 - 2014-03-10 20:53 - 00012318 _____ () C:\Users\Felix\Desktop\FRST.txt 2014-03-20 08:26 - 2014-03-10 20:49 - 00000000 ____D () C:\FRST 2014-03-20 08:25 - 2012-05-03 17:48 - 00000000 ___RD () C:\Users\Felix\Dropbox 2014-03-20 08:25 - 2012-05-03 17:44 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Dropbox 2014-03-20 08:25 - 2012-03-30 20:12 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Spotify 2014-03-20 08:24 - 2014-02-12 17:25 - 00004592 _____ () C:\Windows\setupact.log 2014-03-20 08:24 - 2013-06-03 21:16 - 00000350 _____ () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2014-03-20 08:24 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-19 23:31 - 2011-05-20 20:39 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-03-19 23:31 - 2010-03-03 13:12 - 01351992 _____ () C:\Windows\WindowsUpdate.log 2014-03-19 23:28 - 2013-08-04 22:18 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-19 23:28 - 2010-03-03 13:35 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-19 23:01 - 2011-01-29 21:08 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\uTorrent 2014-03-19 22:36 - 2012-04-04 09:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-03-19 08:20 - 2009-07-14 05:45 - 00014752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-19 08:20 - 2009-07-14 05:45 - 00014752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-19 08:12 - 2014-02-22 15:41 - 00002472 _____ () C:\Windows\PFRO.log 2014-03-18 22:00 - 2010-03-19 22:41 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Winamp 2014-03-18 21:57 - 2012-03-30 20:13 - 00000000 ____D () C:\Users\Felix\AppData\Local\Spotify 2014-03-18 19:07 - 2014-03-18 19:07 - 00987442 _____ () C:\Users\Felix\Desktop\SecurityCheck.exe 2014-03-16 22:24 - 2010-05-16 13:38 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Skype 2014-03-16 13:05 - 2009-07-14 18:58 - 00664618 _____ () C:\Windows\system32\perfh007.dat 2014-03-16 13:05 - 2009-07-14 18:58 - 00134786 _____ () C:\Windows\system32\perfc007.dat 2014-03-16 13:05 - 2009-07-14 06:13 - 01527550 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-03-16 13:03 - 2014-03-16 13:03 - 02347384 _____ (ESET) C:\Users\Felix\Downloads\esetsmartinstaller_enu.exe 2014-03-15 22:09 - 2014-03-15 22:06 - 191451243 _____ () C:\Users\Felix\Downloads\Modern.Family.S03E18.HDTV.x264-LOL.mp4 2014-03-15 20:18 - 2014-03-15 19:54 - 911929996 _____ () C:\Users\Felix\Downloads\Dallas.Buyers.Club.2013.720p.BluRay.x264.YIFY.mp4 2014-03-15 19:55 - 2014-03-15 19:52 - 183206706 _____ () C:\Users\Felix\Downloads\Modern.Family.S03E17.HDTV.XviD-2HD.avi 2014-03-14 19:06 - 2009-07-14 05:45 - 00293424 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 19:05 - 2010-04-10 17:14 - 00000000 ____D () C:\Program Files\Alwil Software 2014-03-13 08:58 - 2014-03-13 08:58 - 00000771 _____ () C:\Users\Felix\Desktop\JRT.txt 2014-03-13 07:54 - 2014-03-13 07:54 - 00000000 ____D () C:\Program Files\7-Zip 2014-03-13 07:53 - 2014-03-13 07:53 - 01376768 _____ () C:\Users\Felix\Downloads\7z920-x64.msi 2014-03-13 07:51 - 2010-04-10 17:15 - 00000000 _____ () C:\Windows\SysWOW64\config.nt 2014-03-13 07:51 - 2010-04-10 17:14 - 00000000 ____D () C:\ProgramData\Alwil Software 2014-03-13 07:48 - 2014-03-13 07:48 - 00512784 _____ (AVAST Software) C:\Users\Felix\Downloads\avastclear_9.0.2013.exe 2014-03-12 23:10 - 2014-03-12 23:10 - 00000000 ____D () C:\Windows\ERUNT 2014-03-12 23:09 - 2014-03-12 23:09 - 01037734 _____ (Thisisu) C:\Users\Felix\Desktop\JRT.exe 2014-03-12 23:08 - 2014-03-12 23:08 - 00008570 _____ () C:\Users\Felix\Desktop\AdwCleaner[S0].txt 2014-03-12 23:00 - 2014-03-12 22:59 - 00000000 ____D () C:\AdwCleaner 2014-03-12 22:36 - 2012-04-04 09:55 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 22:36 - 2012-04-04 09:55 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 22:36 - 2011-05-25 19:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-12 21:29 - 2014-03-12 21:29 - 01949184 _____ () C:\Users\Felix\Desktop\adwcleaner.exe 2014-03-12 21:28 - 2012-07-12 20:34 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Vilu 2014-03-12 21:28 - 2012-03-13 13:49 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Url 2014-03-12 21:04 - 2014-03-12 21:04 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-12 21:04 - 2014-03-12 21:04 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-12 21:03 - 2014-03-12 21:03 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Felix\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-10 20:51 - 2014-03-10 20:50 - 00002998 _____ () C:\Users\Felix\Downloads\Addition.txt 2014-03-10 20:48 - 2014-03-10 20:48 - 02157056 _____ (Farbar) C:\Users\Felix\Desktop\FRST64.exe 2014-03-03 19:22 - 2013-05-27 07:23 - 00003702 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml 2014-03-03 19:21 - 2012-09-04 14:12 - 00050976 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-03-01 07:05 - 2014-03-13 07:52 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-01 06:17 - 2014-03-13 07:52 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-01 06:16 - 2014-03-13 07:52 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-01 05:58 - 2014-03-13 07:52 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-01 05:52 - 2014-03-13 07:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-01 05:51 - 2014-03-13 07:52 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-01 05:42 - 2014-03-13 07:52 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-01 05:40 - 2014-03-13 07:52 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-01 05:37 - 2014-03-13 07:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-01 05:33 - 2014-03-13 07:52 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-01 05:33 - 2014-03-13 07:52 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-01 05:32 - 2014-03-13 07:52 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-01 05:30 - 2014-03-13 07:52 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-01 05:23 - 2014-03-13 07:52 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-01 05:17 - 2014-03-13 07:52 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-01 05:11 - 2014-03-13 07:52 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-01 05:02 - 2014-03-13 07:52 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-01 04:54 - 2014-03-13 07:52 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-01 04:52 - 2014-03-13 07:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-01 04:51 - 2014-03-13 07:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-01 04:47 - 2014-03-13 07:52 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-01 04:43 - 2014-03-13 07:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-01 04:43 - 2014-03-13 07:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-01 04:42 - 2014-03-13 07:52 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-01 04:40 - 2014-03-13 07:52 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-01 04:38 - 2014-03-13 07:52 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-01 04:37 - 2014-03-13 07:52 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-01 04:35 - 2014-03-13 07:52 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-01 04:18 - 2014-03-13 07:52 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-01 04:16 - 2014-03-13 07:52 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-01 04:14 - 2014-03-13 07:52 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-01 04:10 - 2014-03-13 07:52 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-01 04:03 - 2014-03-13 07:52 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-01 04:00 - 2014-03-13 07:52 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-01 03:57 - 2014-03-13 07:52 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-01 03:38 - 2014-03-13 07:52 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-01 03:32 - 2014-03-13 07:52 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-01 03:27 - 2014-03-13 07:52 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-01 03:25 - 2014-03-13 07:52 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-01 03:25 - 2014-03-13 07:52 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-02-28 23:02 - 2013-02-14 14:26 - 00002043 _____ () C:\Users\Public\Desktop\GeekBuddy.lnk 2014-02-23 17:36 - 2011-01-26 19:44 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\vlc Some content of TEMP: ==================== C:\Users\Felix\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-10 21:25 ==================== End Of Log ============================ Dann scheint alles in Ordnung zu sein? Wenn dem so ist: vielen herzlichen Dank! Absolut tolles Forum! |
20.03.2014, 10:39 | #10 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus? Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.03.2014, 08:22 | #11 |
| Ordner erstellen sich von selbst. Virus? Danke für die Hinweise, werd ich beherzigen. Leider haben sich jedoch mittlerweile doch neue Ordner erstellt, vier insgesamt. Doch eine andere Ursache? |
22.03.2014, 07:45 | #12 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus? wo? welcher Name? Screenshot?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.03.2014, 19:29 | #13 |
| Ordner erstellen sich von selbst. Virus? Auf der E: Partition, wie schon vorher. Namen wie 83bc13d15e68807efb61aa3a, 707f16169f72803025, oder e5f98ca782bfa274452a098a3c98. Brauchst du noch einen Screenshot? |
23.03.2014, 11:19 | #14 |
/// the machine /// TB-Ausbilder | Ordner erstellen sich von selbst. Virus? Ja das wäre schön
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.03.2014, 11:23 | #15 |
| Ordner erstellen sich von selbst. Virus? Alles klar, hier: |
Themen zu Ordner erstellen sich von selbst. Virus? |
ahnung, erstellen, immer wieder, ordner, seltsame ordner, spyware.zbot.es, trojan.phex.thagen1, virus?, win32/adware.toolbar.shopper, win32/packed.vmprotect.aaa |