|
Log-Analyse und Auswertung: Windows 7, 64 bit, Trojaner über Email geöffnetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.04.2014, 19:39 | #16 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnetESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.05.2014, 06:38 | #17 |
| Windows 7, 64 bit, Trojaner über Email geöffnet Hallo! Hoffe, du bist noch da...
__________________Hier logEset Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=f5ed3ad2422b4b4684279a890cefae1c # engine=18204 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-10 05:24:38 # local_time=2014-05-10 07:24:38 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 12048024 151329328 0 0 # scanned=151837 # found=1 # cleaned=0 # scan_time=3460 sh=9C860E0B0EAFF9D2912642BC3940BA098C00BBCE ft=1 fh=41f2b86635803f1b vn="NSIS/StartPage.CC Trojaner" ac=I fn="C:\Users\BS-Lap\Downloads\vlc-2.1.0-win64.exe" Hier log securitycheck Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.206 Adobe Reader XI Mozilla Firefox (28.0) Mozilla Thunderbird (17.0.8) ````````Process Check: objlist.exe by Laurent```````` Bitdefender Bitdefender 2013 bdagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Und nun noch FRST FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2014 01 Ran by BS-Lap (administrator) on BS-LAPTOP on 10-05-2014 07:32:06 Running from C:\Users\BS-Lap\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Super Flexible Software Ltd. & Co. KG) C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe () C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe ( ) C:\Program Files (x86)\LockKey\LockKey.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe (Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe () C:\Program Files (x86)\Syncovery\SyncoveryService.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-16] (Synaptics Incorporated) HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [410896 2011-12-16] (Synaptics) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1156712 2011-11-15] (Realtek Semiconductor) HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789856 2012-08-23] (Lenovo) HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-08-23] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6202416 2012-08-23] (Lenovo(beijing) Limited) HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-08-23] (Lenovo) HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2014-02-09] (Bitdefender) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation) HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( ) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [152896 2012-06-25] (Intel Corporation) HKLM-x32\...\Run: [Lenovo Registration] => C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [4351712 2012-01-26] (Lenovo, Inc.) HKLM-x32\...\Run: [Intelligent Touchpad] => C:\Program Files\Lenovo\Intelligent Touchpad\TouchZone.exe [291272 2011-12-08] () HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-28] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-08-23] (Lenovo) HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-772892197-4109324267-2503982889-1000\...\Run: [Power2GoExpress] => NA HKU\S-1-5-21-772892197-4109324267-2503982889-1001\...\Run: [Syncovery Background Scheduler] => C:\Program Files (x86)\Syncovery\SyncoveryService.exe [15304016 2012-12-06] () AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [260928 2012-02-23] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [215360 2012-02-23] (NVIDIA Corporation) Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.google.com/ig/redirectdomain?brand=KMOH&bmod=KMOH HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM-x32 - URL hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms} SearchScopes: HKLM-x32 - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=43169&gid=40335331560044&dbCode=1&command={searchTerms} SearchScopes: HKLM-x32 - TopResultURLFallback hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms} SearchScopes: HKCU - URL hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms} SearchScopes: HKCU - SuggestionsURL_JSON hxxp://api.widdit.com/suggestions/?format=ffplugin&ua=ie&src=addon&si=43169&gid=40335331560044&dbCode=1&command={searchTerms} SearchScopes: HKCU - TopResultURLFallback hxxp://search.certified-toolbar.com?si=43169&st=bs&tid=3580&ver=4.8&ts=1381653751865&tguid=43169-3580-1381653751865-BCEF67A9751EB9E99AD2C9882A747EF0&q={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7KMOH_deDE511DE512 BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120823200948.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20121126152057.dll No File BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\BS-Lap\AppData\Roaming\Mozilla\Firefox\Profiles\6h0z3s5z.default\Extensions\firefox@ghostery.com.xpi [2013-08-29] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] Chrome: ======= CHR HomePage: about:newtab CHR RestoreOnStartup: "about:newtab"], "restore_on_startup_migrated":true, "restore_on_startup":4}, "net":{"http_server_properties":{"toolbarqueries.google.com:443":{"settings":[{"value":100, "id":4}], "supports_spdy":true}}}, "countryid_at_install":17477, "download":{"directory_upgrade":true, "extensions_to_open":""}, "extensions":{"autoupdate":{"next_check":"12998413474678835"}, "settings":{"coobgpohoikkiipiblmjeljniedjpjpf":{"from_bookmark":true, "path":"coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.19_0", "ack_external":true, "location":1, "was_installed_by_default":true, "install_time":"12998412905687238", "page_ordinal":"n", "manifest":{"name":"Google-Suche", "app":{"urls":["*://www.google.com/search", "*://www.google.com/webhp", "*://www.google.com/imgres"], "launch":{"web_url":"hxxp://www.google.com/webhp?source=search_app"}}, "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIiso3Loy5VJHL40shGhUl6it5ZG55XB9q/2EX6aa88jAxwPutbCgy5d9bm1YmBzLfSgpX4xcpgTU08ydWbd7b50fbkLsqWl1mRhxoqnN01kuNfv9Hbz9dWWYd+O4ZfD3L2XZs0wQqo0y6k64n+qeLkUMd1MIhf6MR8Xz1SOA8pwIDAQAB", "default_locale":"en", "update_url":"hxxp://clients2.google.com/service/update2/crx", "current_locale":"de", "icons":{"128":"128.png", "48":"48.png", "32":"32.png", "16":"16.png"}, "version":"0.0.0.19", "description":"Die schnellste Suche im Web."}, "state":1, "from_webstore":true, "app_launcher_ordinal":"t"}, "ahfgeienlihckogmohjhadlkjgocpleb":{"page_ordinal":"n", "app_launcher_ordinal":"q"}, "pjkljhegncpnkpknbcohdijeoejaedia":{"from_bookmark":false, "active_permissions":{"api":["notifications"]}, "path":"pjkljhegncpnkpknbcohdijeoejaedia\\7_0", "ack_external":true, "location":1, "was_installed_by_default":true, "install_time":"12998412906122238", "page_ordinal":"n", "manifest":{"permissions":["notifications"], "name":"Google Mail", "app":{"urls":["*://mail.google.com/mail/ca"], "launch":{"web_url":"https://mail.google.com/mail/ca", "container":"tab"}}, "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB", "default_locale":"en", "update_url":"hxxp://clients2.google.com/service/update2/crx", "current_locale":"de", "icons":{"128":"128.png"}, "version":"7", "options_page":"https://mail.google.com/mail/ca/#settings", "description":"Schneller E-Mail-Dienst mit Suchfunktion und wenig Spam."}, "state":1, "from_webstore":true, "app_launcher_ordinal":"w"}, "fmlgoencnlndpglbocajlimaikjohmab":{"from_bookmark":false, "active_permissions":{"scriptable_host":["*://*/*"], "api":["tabs", "webNavigation"], "explicit_host":["hxxp://*/*", "https://*/*"]}, "location":1, "events":["tabs.onActivated", "tabs.onUpdated"], "was_installed_by_default":true, "install_time":"13019142355583918", "creation_flags":1, "manifest":{"permissions":["webNavigation", "tabs", "hxxp://*/*", "https://*/*"], "name":"VIS", "background":{"page":"background.html", "persistent":false}, "version":"1.0.0", "content_scripts":[{"run_at":"document_end", "matches":["*://*/*"], "js":["fire.js"]}, {"run_at":"document_start", "matches":["*://*/*"], "js":["refire.js"]}], "description":"VIS Internet Security", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWwJqSJFc9ehlVKVRoE/V/oErSKrI2eyWPyCQmf+T4M6EQi8psUuB10jppjAFf5hgAtBPOTdkSGXMxSw5MrJgU+SFeDevwOAGfDHdsm0sViMOPWwjkH2wkUc3qyeXkBBc4zemsFKDVr15PMVQI+Znt7qdGkF7tBnqx85reIpiUsQIDAQAB", "manifest_version":2}, "state":1, "from_webstore":true, "path":"fmlgoencnlndpglbocajlimaikjohmab", "granted_permissions":{"scriptable_host":["*://*/*"], "api":["tabs", "webNavigation"], "explicit_host":["hxxp://*/*", "https://*/*"]}}, "fheoggkfdfchfphceeifdbepaooicaho":{"from_bookmark":false, "active_permissions":{"scriptable_host":["hxxp://*/*", "https://*/*"], "api":["plugin", "tabs"], "explicit_host":["hxxp://*/*", "https://*/*"]}, "location":3, "ack_external":true, "state":1, "install_time":"12998358019168843", "manifest":{"plugins":[{"public":false, "path":"McChPlg.dll"}], "name":"SiteAdvisor", "permissions":["tabs", "hxxp://*/*", "https://*/*", "chrome://*"], "page_action":{"default_title":"SiteAdvisor", "default_popup":"popup.html"}, "background_page":"Background.html", "version":"3.41.122.1", "content_scripts":[{"run_at":"document_end", "matches":["hxxp://*/*", "https://*/*"], "all_frames":true, "js":["ContentScript.js"]}, {"run_at":"document_start", "matches":["hxxp://*/*", "https://*/*"], "all_frames":true, "js":["ContentOnDocStart.js"]}], "description":"SiteAdvisor", "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrOrksCVomv4HZxXZu6eb3fMbFPlYcSWHnBa0eGSLlBx4YJU3hgqATLB9FrVu1I2kjEKU02kDNejzwnooAjAMpQLMN6rDnVLt/xgvBvwfUcqVOX2vmJvzBFUNhrShiAco662ZtJRD2B4MshsjoggFtWvpBDi3VXRzpr1I0jA0tUwIDAQAB"}, "from_webstore":false, "path":"fheoggkfdfchfphceeifdbepaooicaho\\3.41.122.1_0"}, "blpcfgokakmgnkcojhhkbfbldkacnbeo":{"from_bookmark":true, "active_permissions":{"api":["appNotifications"]}, "path":"blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.5_0", "ack_external":true, "location":1, "was_installed_by_default":true, "install_time":"12998412906721238", "page_ordinal":"n", "manifest":{"name":"YouTube", "app":{"launch":{"web_url":"hxxp://www.youtube.com/", "container":"tab"}, "web_content":{"origin":"hxxp://www.youtube.com", "enabled":true}}, "key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC/HotmFlyuz5FaHaIbVBhhL4BwbcUtsfWwzgUMpZt5ZsLB2nW/Y5xwNkkPANYGdVsJkT2GPpRRIKBO5QiJ7jPMa3EZtcZHpkygBlQLSjMhdrAKevpKgIl6YTkwzNvExY6rzVDzeE9zqnIs33eppY4S5QcoALMxuSWlMKqgFQjHQIDAQAB", "default_locale":"en", "update_url":"hxxp://clients2.google.com/service/update2/crx", "current_locale":"de", "icons":{"128":"128.png"}, "version":"4.2.5", "permissions":["appNotifications"], "description":"Die beliebteste Online-Video-Community der Welt"}, "state":1, "from_webstore":true, "app_launcher_ordinal":"n"}, "djbdlklldbflagkkpaljamjfbpefcbpf":{"ack_external":true}}, "chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]}, "alerts":{"initialized":true}, "toolbar":[]}, "ntp":{"promo_is_logged_in_to_plus":false, "sign_in_promo":{"group_max":100}, "promo_build":4, "promo_feature_mask":0, "promo_resource_cache_update":"1353939306.776238", "promo_platform":8}, "profile":{"avatar_index":0, "content_settings":{"clear_on_exit_migrated":true, "pref_version":1}, "exited_cleanly":true, "name":"Erster Nutzer"}, "distribution":{"verbose_logging":false, "create_all_shortcuts":true, "import_search_engine":false, "require_eula":false, "skip_first_run_ui":false, "show_welcome_page":true, "import_bookmarks":false, "alternate_shortcut_text":false, "system_level":true, "make_chrome_default":true, "do_not_launch_chrome":true, "import_history":false}, "dns_prefetching":{"startup_list":[1, "hxxp://0bps664l3vqk05dj8qih0t5renri9iic-a-ig-opensocial.googleusercontent.com/", "hxxp://csi.gstatic.com/", "hxxp://g0.gstatic.com/", "hxxp://id.google.de/", "hxxp://igoogle-skins.googleusercontent.com/", "hxxp://ssl.gstatic.com/", "hxxp://www-ig-opensocial.googleusercontent.com/", "hxxp://www.google.com/", "hxxp://www.google.de/", "hxxp://www.gstatic.com/"], "host_referral_list":[2, ["hxxp://0bps664l3vqk05dj8qih0t5renri9iic-a-ig-opensocial.googleusercontent.com/", ["hxxp://0bps664l3vqk05dj8qih0t5renri9iic-a-ig-opensocial.googleusercontent.com/", 2.2733802, "hxxp://csi.gstatic.com/", 2.2733802, "hxxp://i.ytimg.com/", 2.2733802, "hxxp://www-ig-opensocial.googleusercontent.com/", 2.2733802, "hxxp://www.google-analytics.com/", 2.2733802, "hxxp://www.gstatic.com/", 3.2643408]], ["hxxp://office.microsoft.com/", ["hxxp://c.atdmt.com/", 1.45771366336596, "hxxp://c.msn.com/", 1.66951821274392, "hxxp://js.microsoft.com/", 1.99043419664992, "hxxp://m.webtrends.com/", 2.52315472993388, "hxxp://office.microsoft.com/", 1.88132276212188, "hxxp://officeimg.vo.msecnd.net/", 8.02365469408272]], ["hxxp://www-ig-opensocial.googleusercontent.com/", ["hxxp://ajax.googleapis.com/", 2.2733802, "hxxp://csi.gstatic.com/", 1.17886445341816, "hxxp://nt0.ggpht.com/", 2.2733802, "hxxp://nt2.ggpht.com/", 2.2733802, "hxxp://nt3.ggpht.com/", 3.2643408, "hxxp://services.wikipedia.de/", 2.2733802, "hxxp://www-ig-opensocial.googleusercontent.com/", 1.26077126131839, "hxxp://www.gstatic.com/", 2.16982505341816]], ["hxxp://www.google.de/", ["hxxp://clients1.google.de/", 2.2733802, "hxxp://g0.gstatic.com/", 5.5765822, "hxxp://images0-ig-opensocial.googleusercontent.com/", 2.2733802, "hxxp://images1-ig-opensocial.googleusercontent.com/", 2.6037004, "hxxp://images2-ig-opensocial.googleusercontent.com/", 2.6037004, "hxxp://ssl.gstatic.com/", 2.9340206, "hxxp://www-ig-opensocial.googleusercontent.com/", 4.9159418, "hxxp://www.google.de/", 4.5856216, "https://apis.google.com/", 2.2733802, "https://plusone.google.com/", 3.2643408]], ["hxxp://www7.buyoffice.microsoft.com/", ["hxxp://c.microsoft.com/", 2.09954563117796, "hxxp://c5.img.digitalriver.com/", 15.0132048235554, "hxxp://drh.img.digitalriver.com/", 3.37679124712384, "hxxp://m.webtrends.com/", 2.31135018055592, "hxxp://nexus.ensighten.com/", 2.84407071383988, "hxxp://pto.digitalriver.com/", 2.09954563117796, "hxxp://www7.buyoffice.microsoft.com/", 2.31135018055592, "https://login.passport.com/", 2.31135018055592, "https://www.passportimages.com/", 1.45771366336596, "https://www7.buyoffice.microsoft.com/", 1.77862964727196]], ["https://login.live.com/", ["https://login.live.com/", 4.134152969142, "https://www7.buyoffice.microsoft.com/", 7.022396824296]], ["https://plusone.google.com/", ["https://plusone.google.com/", 2.9340206, "https://ssl.gstatic.com/", 2.2733802]], ["https://www7.buyoffice.microsoft.com/", ["https://c.microsoft.com/", 1.39784739414401, "https://c5.img.digitalriver.com/", 0.356823307875029, "https://drh.img.digitalriver.com/", 1.74187193513144, "https://m.webtrends.com/", 0.400436606803864, "https://nexus.ensighten.com/", 2.06278791903744]]]}, "http_throttling":{"enabled":true}, "homepage":"about:newtab", "browser":{"window_placement":{"work_area_top":0, "work_area_right":1366, "top":10, "left":10, "bottom":718, "maximized":false, "right":1060, "work_area_left":0, "work_area_bottom":728}, "last_prompted_google_url":"hxxp://www.google.de/", "last_known_google_url":"hxxp://www.google.de/" CHR Extension: (YouTube) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-26] CHR Extension: (Google Search) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-26] CHR Extension: (SiteAdvisor) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2012-11-26] CHR Extension: (Gmail) - C:\Users\BS-Lap\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-26] ==================== Services (Whitelisted) ================= S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2014-02-09] (Bitdefender) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [945440 2012-02-01] (Broadcom Corporation.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () S2 NSDSvc; C:\Windows\System32\NSDSvc.exe [120160 2011-12-23] (Lenovo) R2 SyncoveryVSSService; C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe [3255632 2012-06-25] (Super Flexible Software Ltd. & Co. KG) R3 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2014-02-09] (Bitdefender) R3 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2014-02-09] (Bitdefender) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2014-02-09] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2014-02-09] (BitDefender) R3 AVer7231_x64; C:\Windows\System32\DRIVERS\AVer7231_x64.sys [1800448 2011-03-31] (AVerMedia TECHNOLOGIES, Inc.) R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-05-01] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2014-02-09] (BitDefender SRL) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2014-02-09] (BitDefender LLC) R3 hswpan; C:\Windows\System32\DRIVERS\hswpan.sys [109056 2012-01-27] (Ozmo Inc) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104048 2012-03-02] (Qualcomm Atheros Co., Ltd.) R0 NSD; C:\Windows\System32\drivers\nsd.sys [24160 2011-12-23] (Lenovo Corporation") R1 Nsdfltr; C:\Windows\System32\drivers\Nsdfltr.sys [59488 2011-12-21] (Lenovo Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8208488 2011-09-06] (Realtek Semiconductor Corp.) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2014-02-09] (BitDefender S.R.L.) U3 BcmSqlStartupSvc; U2 CLKMSVC10_3A60B698; U2 CLKMSVC10_C3B3B687; U2 DriverService; U2 iATAgentService; U2 idealife Update Service; U3 IGRS; U2 IviRegMgr; U2 Oasis2Service; U2 PCCarerService; U2 ReadyComm.DirectRouter; U2 RichVideo; U2 RtLedService; U2 SeaPort; U2 SoftwareService; U3 SQLWriter; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-10 07:29 - 2014-05-10 07:29 - 00000762 _____ () C:\Users\BS-Lap\Desktop\checkup.txt 2014-05-10 07:28 - 2014-05-10 07:28 - 00855379 _____ () C:\Users\BS-Lap\Desktop\SecurityCheck.exe 2014-05-10 06:25 - 2014-05-10 06:25 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-10 06:21 - 2014-05-10 06:21 - 02347384 _____ (ESET) C:\Users\BS-Lap\Desktop\esetsmartinstaller_deu.exe 2014-05-04 21:53 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-04 21:53 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-04 21:53 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-04 21:53 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-04 21:53 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-04 21:53 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-04 21:53 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-04 21:53 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-04 21:53 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-04 21:53 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-04 21:53 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-04 21:53 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-04 21:53 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-04 21:53 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-04 21:53 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-04 21:53 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-04 21:53 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-04 21:53 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-04 21:53 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-04 21:53 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-04 21:53 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-04 21:53 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-04 21:53 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-04 21:53 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-04 21:53 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-04 21:53 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-04 21:53 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-04 21:53 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-04 21:53 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-04 21:53 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-04 21:53 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-04 21:53 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-04 21:53 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-04 21:53 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-04 21:53 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-04 21:53 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-04 21:53 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-04 21:53 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-04 21:53 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-04 21:53 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-04 21:53 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-04 21:53 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-05-04 21:53 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-04 21:53 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-04 21:52 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-04 21:52 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-04 21:52 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-04 21:52 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-19 11:21 - 2014-05-10 07:32 - 00028964 _____ () C:\Users\BS-Lap\Desktop\FRST.txt 2014-04-19 11:21 - 2014-05-10 07:31 - 00000000 ____D () C:\Users\BS-Lap\Desktop\FRST-OlderVersion 2014-04-19 11:19 - 2014-04-19 11:20 - 00001304 _____ () C:\Users\BS-Lap\Desktop\JRT.txt 2014-04-19 11:13 - 2014-04-19 11:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 11:12 - 2014-04-19 11:13 - 01016261 _____ (Thisisu) C:\Users\BS-Lap\Downloads\JRT.exe 2014-04-19 11:09 - 2014-04-19 11:09 - 00003760 _____ () C:\Users\BS-Lap\Desktop\AdwCleaner[S0].txt 2014-04-19 11:06 - 2014-04-19 11:08 - 00000000 ____D () C:\AdwCleaner 2014-04-19 11:05 - 2014-04-19 11:05 - 01258805 _____ () C:\Users\BS-Lap\Downloads\adwcleaner(1).exe 2014-04-19 11:02 - 2014-04-19 11:02 - 00007707 _____ () C:\Users\BS-Lap\Desktop\mbam.txt 2014-04-19 11:00 - 2014-04-19 11:00 - 00000000 ____D () C:\Users\BS-Lap\Desktop\Neuer Ordner 2014-04-19 10:38 - 2014-04-19 11:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 10:38 - 2014-04-19 10:38 - 00001147 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 10:38 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-19 10:38 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-19 10:38 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-19 10:36 - 2014-04-19 10:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Downloads\mbam-setup-2.0.1.1004.exe ==================== One Month Modified Files and Folders ======= 2014-05-10 07:32 - 2014-04-19 11:21 - 00028964 _____ () C:\Users\BS-Lap\Desktop\FRST.txt 2014-05-10 07:32 - 2014-03-31 13:29 - 00000000 ____D () C:\FRST 2014-05-10 07:31 - 2014-04-19 11:21 - 00000000 ____D () C:\Users\BS-Lap\Desktop\FRST-OlderVersion 2014-05-10 07:31 - 2014-03-31 13:26 - 02064384 _____ (Farbar) C:\Users\BS-Lap\Desktop\FRST64.exe 2014-05-10 07:29 - 2014-05-10 07:29 - 00000762 _____ () C:\Users\BS-Lap\Desktop\checkup.txt 2014-05-10 07:28 - 2014-05-10 07:28 - 00855379 _____ () C:\Users\BS-Lap\Desktop\SecurityCheck.exe 2014-05-10 07:27 - 2014-03-31 16:38 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 07:14 - 2012-11-29 09:56 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-10 06:33 - 2012-08-23 19:24 - 01444192 _____ () C:\Windows\WindowsUpdate.log 2014-05-10 06:25 - 2014-05-10 06:25 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-10 06:21 - 2014-05-10 06:21 - 02347384 _____ (ESET) C:\Users\BS-Lap\Desktop\esetsmartinstaller_deu.exe 2014-05-10 06:20 - 2012-08-24 05:09 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2014-05-10 06:20 - 2012-08-24 05:09 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2014-05-10 06:20 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-10 06:18 - 2009-07-14 06:45 - 00031840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-10 06:18 - 2009-07-14 06:45 - 00031840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-10 06:17 - 2012-12-11 16:51 - 00000000 ____D () C:\ProgramData\Syncovery 2014-05-10 06:16 - 2012-11-26 00:56 - 00944308 _____ () C:\FaceProv.log 2014-05-10 06:16 - 2012-08-23 20:16 - 00613092 _____ () C:\Windows\system32\fastboot.set 2014-05-10 06:16 - 2012-08-23 20:14 - 00000000 ____D () C:\ProgramData\VeriFace 2014-05-10 06:16 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-10 06:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-10 06:13 - 2009-07-14 06:51 - 00077851 _____ () C:\Windows\setupact.log 2014-05-10 06:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-04 12:14 - 2012-11-29 09:56 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-04 12:14 - 2012-11-29 09:56 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-04 12:14 - 2012-11-29 09:56 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-20 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-19 11:20 - 2014-04-19 11:19 - 00001304 _____ () C:\Users\BS-Lap\Desktop\JRT.txt 2014-04-19 11:13 - 2014-04-19 11:13 - 00000000 ____D () C:\Windows\ERUNT 2014-04-19 11:13 - 2014-04-19 11:12 - 01016261 _____ (Thisisu) C:\Users\BS-Lap\Downloads\JRT.exe 2014-04-19 11:09 - 2014-04-19 11:09 - 00003760 _____ () C:\Users\BS-Lap\Desktop\AdwCleaner[S0].txt 2014-04-19 11:08 - 2014-04-19 11:06 - 00000000 ____D () C:\AdwCleaner 2014-04-19 11:05 - 2014-04-19 11:05 - 01258805 _____ () C:\Users\BS-Lap\Downloads\adwcleaner(1).exe 2014-04-19 11:02 - 2014-04-19 11:02 - 00007707 _____ () C:\Users\BS-Lap\Desktop\mbam.txt 2014-04-19 11:01 - 2014-04-19 10:38 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-19 11:00 - 2014-04-19 11:00 - 00000000 ____D () C:\Users\BS-Lap\Desktop\Neuer Ordner 2014-04-19 10:59 - 2010-11-21 05:47 - 00247606 _____ () C:\Windows\PFRO.log 2014-04-19 10:38 - 2014-04-19 10:38 - 00001147 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-19 10:38 - 2014-04-19 10:38 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-19 10:36 - 2014-04-19 10:36 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\BS-Lap\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-11 19:50 - 2013-12-21 01:56 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 19:50 - 2012-11-27 12:58 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-11 19:47 - 2013-02-15 15:43 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\BS-Lap\AppData\Local\Temp\AskSLib.dll C:\Users\BS-Lap\AppData\Local\Temp\AutoRun.exe C:\Users\BS-Lap\AppData\Local\Temp\AutoRunGUI.dll C:\Users\BS-Lap\AppData\Local\Temp\converter.exe C:\Users\BS-Lap\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-04 14:00 ==================== End Of Log ============================ --- --- --- --- --- --- Wie geht es weiter? Wie bekomme ich den Trojaner vom Rechner runter? Ist es in solchen Fällen besser, den Computer "platt" zu machen und alles neu zu installieren? Beste Grüße und ein dickes Dankeschön, vor allem für deine Geduld!!!!!! Geändert von Perle78 (10.05.2014 um 07:08 Uhr) |
11.05.2014, 06:19 | #18 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnet Hi,
__________________der ist schon lange runter, das waren Scans auf Reste. Der Fund von ESET ist weil Du VLC PLayer nicht beim Hersteller geladen hast, sondern so ne Version mit Gimmick dazu. Andere Rechner im Netz sind sicher. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
11.05.2014, 20:01 | #19 |
| Windows 7, 64 bit, Trojaner über Email geöffnet Danke! Was ich noch nicht ganz verstehe - wie ist der Trojaner denn runtergekommen? Er ist mir nie aufgefallen - hätte mir nicht eines der Programme mal sagen müssen: Trojaner gefunden...oder irgendwas ähnliches??? Habe alles ausgeführt, was du geschrieben hast und mir auch deine Vorschläge durchgelesen und zu Herzen genommen. btw: kann ich den IE denn gar nicht deinstallieren? Da der dritte Rechner seit ein paar Tagen verstärkt Probleme hat im IE, aber auch bei Firefox Seiten zu öffnen bzw. ewig braucht, der Bitdefender aber nichts findet und ich jetzt genug Stress mit den anderen Rechnern hatte, bin ich natürlich misstrauisch. Können wir uns den vorsichtshalber auch noch ansehen? Wenn ja, gehe ich dann so vor, wie in der Anleitung für die ersten Schritte beschrieben oder schlägst du etwas anderes vor? Besten Dank für die schnelle Hilfe und das "Opfern" deiner Freizeit!!! Beste Grüße Jana |
12.05.2014, 16:21 | #20 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnet Adware-Erkennung ist immer so ne Sache. Du hast es ja teilweise erlaubt dass es installiert wird. Poste einfach mal FRST Logs von dem anderen Rechner
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.05.2014, 20:43 | #21 | |
| Windows 7, 64 bit, Trojaner über Email geöffnetZitat:
Super! FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01 Ran by Axel (administrator) on CORE-I7-3770 on 12-05-2014 21:32:15 Running from C:\Users\Axel\Desktop Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Super Flexible Software Ltd. & Co. KG) C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Syncovery\SyncoveryService.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Dropbox, Inc.) C:\Users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (LucidLogix) C:\Program Files\Lucidlogix Technologies\VIRTU\LucidServices.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM\...\Run: [VIRTU] => C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe [2593568 2012-04-22] () HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-10-24] (Bitdefender) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1394281553-801495742-107340834-1002\...\Run: [Syncovery Background Scheduler] => C:\Program Files (x86)\Syncovery\SyncoveryService.exe [15304016 2012-12-06] () HKU\S-1-5-21-1394281553-801495742-107340834-1002\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries) AppInit_DLLs: C:\Windows\system32\appinit_dll.dll => C:\Windows\system32\appinit_dll.dll [456992 2012-04-22] (Lucidlogix Inc.) AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll => C:\Windows\SysWOW64\appinit_dll.dll [411936 2012-04-22] (Lucidlogix Inc.) Startup: C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1112748220FBCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - {888C2D85-2D24-4BCA-8E5E-3CC93717A017} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^DE&apn_uid=7353ECF5-D7B9-42EC-B979-CE187F1BED0A&apn_sauid=6E7DA701-C54F-49EC-995B-C062D65905B4 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default FF SearchEngineOrder.1: Ask.com FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @java.com/DTPlugin,version=10.11.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @garmin.com/GpsControl - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\searchplugins\askcom.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\Extensions\firefox@ghostery.com.xpi [2013-08-17] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] ==================== Services (Whitelisted) ================= S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-10-24] (Bitdefender) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) R2 MSSQL$SQLMULTIBASECS; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation) S4 SQLAgent$SQLMULTIBASECS; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation) R2 SyncoveryVSSService; C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe [3255632 2012-06-25] (Super Flexible Software Ltd. & Co. KG) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-10-24] (Bitdefender) R2 vsserv; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-10-24] (Bitdefender) ==================== Drivers (Whitelisted) ==================== R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-10-24] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-10-24] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-04-29] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-10-24] (BitDefender SRL) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-24] (BitDefender LLC) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-24] (BitDefender S.R.L.) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-05-12] () S3 AIDA64Driver; \??\J:\Appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\kerneld.x64 [X] S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-12 21:32 - 2014-05-12 21:32 - 00013546 _____ () C:\Users\Axel\Desktop\FRST.txt 2014-05-12 21:32 - 2014-05-12 21:32 - 00000000 ____D () C:\FRST 2014-05-12 21:29 - 2014-05-12 21:31 - 00000000 ____D () C:\Users\Axel\Desktop\Desktop-Bilder 2014-05-12 21:28 - 2014-05-12 21:28 - 02066944 _____ (Farbar) C:\Users\Axel\Desktop\FRST64.exe 2014-05-10 10:30 - 2014-05-10 10:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-07 08:24 - 2014-05-07 08:24 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\DropboxMaster 2014-05-07 08:20 - 2014-05-07 08:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-06 13:09 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-06 13:09 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-04 09:41 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-04 09:41 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-04 09:41 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-04 09:41 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-30 17:51 - 2014-05-01 00:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-29 05:17 - 2014-05-12 07:12 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieUserList 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieSiteList 2014-04-12 05:46 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-12 05:46 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-12 05:46 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-12 05:46 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-12 05:46 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-12 05:46 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-12 05:46 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-12 05:46 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-12 05:46 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-12 05:46 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-12 05:46 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-12 05:46 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-12 05:46 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-12 05:46 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-12 05:46 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-12 05:46 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-12 05:46 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-12 05:46 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-12 05:46 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-12 05:46 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-12 05:46 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-12 05:46 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-12 05:46 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-12 05:46 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-12 05:46 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-12 05:46 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-12 05:46 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-12 05:46 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-12 05:46 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-12 05:46 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-12 05:46 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-12 05:46 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-12 05:46 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-12 05:46 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-12 05:46 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-12 05:46 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-12 05:46 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-12 05:46 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-12 05:46 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-12 05:46 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-12 05:46 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-12 05:46 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-12 05:46 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-12 05:46 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll ==================== One Month Modified Files and Folders ======= 2014-05-12 21:32 - 2014-05-12 21:32 - 00013546 _____ () C:\Users\Axel\Desktop\FRST.txt 2014-05-12 21:32 - 2014-05-12 21:32 - 00000000 ____D () C:\FRST 2014-05-12 21:31 - 2014-05-12 21:29 - 00000000 ____D () C:\Users\Axel\Desktop\Desktop-Bilder 2014-05-12 21:28 - 2014-05-12 21:28 - 02066944 _____ (Farbar) C:\Users\Axel\Desktop\FRST64.exe 2014-05-12 21:28 - 2013-01-29 11:40 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-12 20:49 - 2013-01-23 09:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-12 16:58 - 2011-04-12 09:43 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-05-12 16:58 - 2011-04-12 09:43 - 00175138 _____ () C:\Windows\system32\perfc007.dat 2014-05-12 16:58 - 2009-07-14 07:13 - 01807994 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-12 12:26 - 2013-02-15 19:25 - 00000000 ____D () C:\ProgramData\firebird 2014-05-12 12:26 - 2013-01-23 10:45 - 00000000 ____D () C:\ProgramData\Syncovery 2014-05-12 10:29 - 2013-01-22 15:42 - 01858496 _____ () C:\Windows\WindowsUpdate.log 2014-05-12 08:28 - 2013-01-29 11:40 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-12 07:19 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-12 07:19 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-12 07:12 - 2014-04-29 05:17 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-05-12 07:12 - 2013-03-11 10:27 - 00000000 ___RD () C:\Users\Axel\Dropbox 2014-05-12 07:12 - 2013-03-11 10:25 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Dropbox 2014-05-12 07:12 - 2013-01-23 09:37 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys 2014-05-12 07:12 - 2010-11-21 05:47 - 09318546 _____ () C:\Windows\PFRO.log 2014-05-12 07:12 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-12 07:12 - 2009-07-14 06:51 - 00081270 _____ () C:\Windows\setupact.log 2014-05-10 15:46 - 2013-01-25 19:29 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-10 10:30 - 2014-05-10 10:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-09 08:23 - 2013-01-29 11:40 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 08:23 - 2013-01-29 11:40 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-08 16:24 - 2013-04-23 11:31 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\vlc 2014-05-08 09:57 - 2013-01-26 02:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\CutePDF Writer 2014-05-07 08:24 - 2014-05-07 08:24 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\DropboxMaster 2014-05-07 08:24 - 2013-03-11 10:25 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-07 08:24 - 2013-01-25 18:54 - 00000000 ___RD () C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-07 08:20 - 2014-05-07 08:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-05 18:28 - 2014-01-20 21:34 - 00161634 _____ () C:\Users\Axel\Documents\Brother Jana 2014-05-04 18:53 - 2013-01-26 01:43 - 00000000 ____D () C:\Users\Axel\AppData\Local\Microsoft Help 2014-05-01 00:52 - 2014-04-30 17:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-29 17:49 - 2013-01-23 09:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-29 17:49 - 2013-01-23 09:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-29 17:49 - 2013-01-23 09:44 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-29 16:01 - 2014-05-04 09:41 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-29 15:40 - 2014-05-04 09:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-29 14:48 - 2014-05-04 09:41 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-29 14:34 - 2014-05-04 09:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieUserList 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieSiteList 2014-04-20 16:42 - 2014-03-28 01:30 - 00000000 ____D () C:\Users\Axel\AppData\Local\Windows Live 2014-04-14 04:24 - 2014-05-06 13:09 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:19 - 2014-05-06 13:09 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-12 15:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-12 05:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-12 05:43 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT Some content of TEMP: ==================== C:\Users\Axel\AppData\Local\Temp\APNStub.exe C:\Users\Axel\AppData\Local\Temp\CNC4LauncherUpdate.exe C:\Users\Axel\AppData\Local\Temp\converter.exe C:\Users\Axel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcqw5hb.dll C:\Users\Axel\AppData\Local\Temp\jre-7u15-windows-i586-iftw.exe C:\Users\Axel\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\Axel\AppData\Local\Temp\rro2k3st.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-09 11:45 ==================== End Of Log ============================ und Additional Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-05-2014 01 Ran by Axel at 2014-05-12 21:32:34 Running from C:\Users\Axel\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Bitdefender Virenschutz (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Spyware-Schutz (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09} FW: Bitdefender Firewall (Enabled) {A364D236-8096-DCCF-EF3F-4E4DBCD170CF} ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.206 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.206 - Adobe Systems Incorporated) Bitdefender Internet Security 2013 (HKLM\...\Bitdefender) (Version: 16.26.0.1739 - Bitdefender) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.12.52.0 - Canon Inc.) Catalyst Control Center (x32 Version: 2012.1219.1521.27485 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.1219.1520.27485 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.0.3717 - CDBurnerXP) Command & Conquer™ 4 Tiberian Twilight (HKLM-x32\...\{BA4C8F9F-D81B-4AFE-AE5A-3837830F5B89}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Command & Conquer™ and The Covert Operations™ (HKLM-x32\...\{050E298D-C9B8-4582-A332-26201268A297}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Command & Conquer™ Red Alert, Counterstrike and The Aftermath (HKLM-x32\...\{B9A7CCBE-48F7-4B3E-BD20-76ADDD4DC69F}) (Version: 1.0.0.0 - Electronic Arts, Inc.) Command & Conquer™: Generals and Zero Hour (HKLM-x32\...\{8F0F5689-6900-425B-A8C2-0DBD10DAB694}) (Version: 1.0.0.0 - Electronic Arts, Inc.) CrystalDiskInfo 3.5.3a (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 3.5.3a - Crystal Dew World) CutePDF Writer 2.7 (HKLM\...\CutePDF Writer Installation) (Version: - ) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version: - Microsoft) Designer 2.0 (HKLM-x32\...\Designer 2.0_is1) (Version: 7.9.5 - Fomanu AG) Dropbox (HKCU\...\Dropbox) (Version: 2.6.31 - Dropbox, Inc.) Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology) Garmin Express (HKLM-x32\...\{0904cc72-1b29-426a-b0f0-228d2744a4f6}) (Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden GPL Ghostscript 8.64 (HKLM-x32\...\GPL Ghostscript 8.64) (Version: - ) Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (HKLM-x32\...\{8343C2D8-09DF-38B3-9D1A-A26148918E45}.KB947789) (Version: 1 - Microsoft Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) K-Lite Codec Pack 9.7.0 (64-bit) (HKLM\...\KLiteCodecPack64_is1) (Version: 9.7.0 - ) MagicMaps Berlin Brandenburg Sachsen-Anhalt 6.0 (HKLM-x32\...\{4152D5DF-8C80-4DD3-84B2-5D7014F31C10}) (Version: 6.0 - MagicMaps) MagicMaps Niedersachsen Bremen 6.0 (HKLM-x32\...\{DF5907C6-0B08-4026-B315-9CA0D75B9D2C}) (Version: 6.0 - MagicMaps) MagicMaps Sachsen Thüringen 6.0 (HKLM-x32\...\{0F07238C-F0D9-47B5-86FC-9DE7E3B375F6}) (Version: 6.0 - MagicMaps) MagicMaps Schleswig-Holstein Hamburg Mecklenburg-Vorpommern 6.0 (HKLM-x32\...\{7AAB0C37-0F59-4872-801B-7A874A4F2A13}) (Version: 6.0 - MagicMaps) MagicMaps Support und Update Tool (HKLM-x32\...\{0CA1C412-6716-40E8-B033-006002E7F7EC}) (Version: 1.1.4 - MagicMaps) MagicMaps Tour Explorer 25 Deutschland V 6.0 (HKLM-x32\...\{9DB39B0C-1D8A-4D93-BC8E-E69BACAA75E0}) (Version: 6.0.6 - MagicMaps) MagicMaps Tour Explorer 25 Deutschland V 6.0 (x32 Version: 6.0.0 - MagicMaps) Hidden MagicMaps Tour Explorer 25 Deutschland V 6.0 (x32 Version: 6.0.6 - MagicMaps) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (x32 Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Help Viewer 1.1 Language Pack - DEU (HKLM\...\Microsoft Help Viewer 1.1 Language Pack - DEU) (Version: 1.1.40219 - Microsoft Corporation) Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Report Viewer Redistributable 2008 (KB971119) (x32 Version: 9.0.30731 - Microsoft Corporation) Hidden Microsoft Report Viewer Redistributable 2008 SP1 (HKLM-x32\...\Microsoft Report Viewer Redistributable 2008 (KB971119)) (Version: - Microsoft Corporation) Microsoft Report Viewer Redistributable 2008 SP1 Language Pack - DEU (HKLM-x32\...\Microsoft Report Viewer Redistributable 2008 SP1 Language Pack - DEU) (Version: - Microsoft Corporation) Microsoft Report Viewer Redistributable 2008 SP1 Language Pack - DEU (x32 Version: 9.0.30729 - Microsoft Corporation) Hidden Microsoft SQL Server 2008 R2 (64 Bit) (HKLM\...\Microsoft SQL Server 2008 R2) (Version: - Microsoft Corporation) Microsoft SQL Server 2008 R2 (64 Bit) (Version: - Microsoft Corporation) Hidden MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek) Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla) Origin (HKLM-x32\...\Origin) (Version: 9.1.11.2678 - Electronic Arts, Inc.) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.6.2 - pdfforge) QGIS Dufour 2.0.1 Dufour (HKLM\...\QGIS Dufour) (Version: - QGIS Development Team) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.) Samsung SSD Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 3.2 - Samsung Electronics) Service Pack 1 für SQL Server 2008 R2 (KB2528583) (64-bit) (HKLM\...\KB2528583) (Version: 10.51.2500.0 - Microsoft Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden SILKYPIX Developer Studio 3.0 SE (HKLM-x32\...\InstallShield_{B2F25F71-D920-4288-A548-54CD253DEF14}) (Version: 3 - Ichikawa Soft Laboratory) SILKYPIX Developer Studio 3.0 SE (x32 Version: 3 - Ichikawa Soft Laboratory) Hidden Syncovery 6.19 (HKLM-x32\...\Syncovery_is1) (Version: 6.19 - Super Flexible Software) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Vegetationsaufnahme - Version 5.0 (HKLM-x32\...\Vegetationsaufnahme - Version 5.0) (Version: - ) VIRTU 1.2.114 (HKLM\...\VIRTU_is1) (Version: 1.2.114 - Lucidlogix Technologies LTD) VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN) Winart - Pflanzen Version 5.0 (HKLM-x32\...\Winart - Pflanzen Version 5.0) (Version: - ) Winart - Wirbellose Version 5.0 (HKLM-x32\...\Winart - Wirbellose Version 5.0) (Version: - ) Winart - Wirbeltiere Version 5.0 (HKLM-x32\...\Winart - Wirbeltiere Version 5.0) (Version: - ) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (HKLM\...\98157A226B40B173301B0F53C8E98C47805D5152) (Version: 04/19/2012 2.3.1.0 - Garmin) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3522.0110 - Microsoft Corporation) WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) ==================== Restore Points ========================= 15-04-2014 07:52:21 Windows Update 22-04-2014 05:09:19 Windows Update 25-04-2014 06:43:34 Windows Update 30-04-2014 05:00:33 Windows Update 04-05-2014 07:41:25 Windows Update 07-05-2014 06:18:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1AF0700D-28B5-406D-952E-9074FE8B485F} - System32\Tasks\AIDA64 AutoStart => J:\Appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\aida64.exe <==== ATTENTION Task: {36F30F58-BFA9-4E57-A466-1949DA55E1E8} - System32\Tasks\Sicherung MultiBaseCS Datenbank => C:\Program Files (x86)\34u GmbH\MultiBaseCS\Professional\Datenbank-Sicherung\SQLBackup_MultiBase.cmd [2013-08-22] () Task: {59A58318-7988-494B-9B28-CE2812C2B5CB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-29] (Google Inc.) Task: {78125554-AEB9-456B-BC44-1A41C46D1EBF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-29] (Google Inc.) Task: {C3D7DFE8-06F6-44F2-BB2D-85D7A4A11A29} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-29] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-02-15 14:33 - 2013-10-24 19:28 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\txmlutil.dll 2013-10-24 19:30 - 2013-10-24 19:30 - 00003072 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\UI\accessl.ui 2013-02-15 14:33 - 2011-11-14 20:17 - 00153680 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\bdfwcore.dll 2013-02-15 14:33 - 2013-10-24 19:28 - 00005120 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\UI\IMSecurityAL.ui 2014-03-25 14:16 - 2014-03-25 14:16 - 00771328 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00038_022\ashttpbr.mdl 2014-03-25 14:16 - 2014-03-25 14:16 - 00568400 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00038_022\ashttpdsp.mdl 2014-03-25 14:16 - 2014-03-25 14:16 - 02593416 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00038_022\ashttpph.mdl 2014-03-25 14:16 - 2014-03-25 14:16 - 01317216 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\otengines_00038_022\ashttprbl.mdl 2013-01-26 02:05 - 2007-07-12 23:37 - 00085504 _____ () C:\Windows\System32\cpwmon64.dll 2012-02-09 18:26 - 2012-02-09 18:26 - 00133632 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe 2012-02-09 18:26 - 2012-02-09 18:26 - 00048128 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll 2012-02-09 18:26 - 2012-02-09 18:26 - 00036864 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\ISCTNetDetect.dll 2013-01-23 09:39 - 2012-04-22 21:32 - 02593568 _____ () C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.exe 2013-01-23 09:39 - 2012-04-22 21:31 - 00104736 _____ () C:\Program Files\Lucidlogix Technologies\VIRTU\GuiCommon.dll 2012-10-22 19:39 - 2012-10-22 19:39 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-01-23 10:45 - 2012-12-06 01:11 - 15304016 _____ () C:\Program Files (x86)\Syncovery\SyncoveryService.exe 2014-05-12 07:12 - 2014-05-12 07:12 - 00041984 _____ () c:\users\axel\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcqw5hb.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Axel\AppData\Roaming\Dropbox\bin\libcef.dll 2014-04-30 17:51 - 2014-04-30 17:51 - 03019888 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2014-04-30 17:51 - 2014-04-30 17:51 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2014-04-30 17:51 - 2014-04-30 17:51 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2013-03-30 08:39 - 2013-10-24 19:29 - 00204280 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\Antispam32\txmlutil.dll 2014-05-10 10:30 - 2014-05-10 10:30 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-01-23 09:23 - 2012-02-07 19:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2012-09-23 22:43 - 2012-09-23 22:43 - 00313992 _____ () C:\Program Files (x86)\Adobe\Reader 11.0\Reader\sqlite.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Axel\Desktop\FRST64.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\Dropbox 1.6.17(1).exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\Dropbox 1.6.17.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\GarminExpress.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\install_flashplayer11x32au_mssa_aih.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\MozBackup-1.5.1-EN.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\QGIS-OSGeo4W-2.0.1-3-Setup-x86_64.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\SQLEXPRWT_x64_DEU.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\TourExplorer25Deutschland6060.exe:BDU AlternateDataStreams: C:\Users\Axel\Downloads\vlc-2.1.2-win32.exe:BDU ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: TP-LINK 300Mbps Wireless N Adapter Description: TP-LINK 300Mbps Wireless N Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: TP-LINK Service: athr Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (05/12/2014 10:44:15 AM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 90080108 Error: (05/12/2014 09:52:01 AM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 80004005 Error: (05/12/2014 07:13:56 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/12/2014 07:12:10 AM) (Source: ISCT Agent) (User: ) (EventID: 1003) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (05/11/2014 03:41:27 PM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 90080108 Error: (05/11/2014 02:39:21 PM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 80004005 Error: (05/11/2014 09:38:46 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/11/2014 09:36:59 AM) (Source: ISCT Agent) (User: ) (EventID: 1003) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (05/11/2014 09:08:16 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/11/2014 09:06:30 AM) (Source: ISCT Agent) (User: ) (EventID: 1003) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 System errors: ============= Error: (05/12/2014 06:17:09 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/12/2014 05:37:09 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/12/2014 02:24:17 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 08:14:31 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 08:01:25 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 07:49:27 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 07:37:26 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 07:25:13 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 07:13:36 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (05/11/2014 07:02:58 PM) (Source: bowser) (User: ) (EventID: 8003) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "PERLE-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FFAFB6F1-4AA4-4079-9EF4-014E7150A523}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Microsoft Office Sessions: ========================= Error: (05/12/2014 10:44:15 AM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 90080108 Error: (05/12/2014 09:52:01 AM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 80004005 Error: (05/12/2014 07:13:56 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/12/2014 07:12:10 AM) (Source: ISCT Agent) (User: ) (EventID: 1003) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (05/11/2014 03:41:27 PM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 90080108 Error: (05/11/2014 02:39:21 PM) (Source: Customer Experience Improvement Program) (User: ) (EventID: 1008) Description: 80004005 Error: (05/11/2014 09:38:46 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/11/2014 09:36:59 AM) (Source: ISCT Agent) (User: ) (EventID: 1003) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (05/11/2014 09:08:16 AM) (Source: WinMgmt) (User: ) (EventID: 10) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/11/2014 09:06:30 AM) (Source: ISCT Agent) (User: ) (EventID: 1003) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 CodeIntegrity Errors: =================================== Date: 2013-01-25 17:20:35.631 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\l3codecp.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-25 17:20:35.615 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\l3codeca.acm" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 16275.49 MB Available physical RAM: 12784.94 MB Total Pagefile: 32549.16 MB Available Pagefile: 28119.98 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (SSD) (Fixed) (Total:232.66 GB) (Free:45.46 GB) NTFS Drive d: (Tower Axel) (Fixed) (Total:1765.23 GB) (Free:1385.93 GB) NTFS Drive e: (OBH) (CDROM) (Total:2.08 GB) (Free:0 GB) UDF Drive k: (FiiO S5K) (Removable) (Total:1.9 GB) (Free:1.9 GB) FAT32 Drive r: (RECOVER) (Fixed) (Total:97.66 GB) (Free:87.65 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 6 (Size: 2 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ Jetzt bin ich gespannt! |
13.05.2014, 15:36 | #22 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnet runtergekommen im Sine vom Rechner gelöscht? Na mit ner netten Mixtur aus Schrauber und den verwendeten Tools Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.05.2014, 18:57 | #23 |
| Windows 7, 64 bit, Trojaner über Email geöffnet Ja, im Sinne von gelöscht! Nette Antwort Hier Combofix Code:
ATTFilter ComboFix 14-05-13.01 - Axel 13.05.2014 19:38:56.1.8 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.16275.13590 [GMT 2:00] ausgeführt von:: c:\users\Axel\Desktop\ComboFix.exe AV: Bitdefender Virenschutz *Disabled/Updated* {9B5F5313-CAF9-DD97-C460-E778420237B4} FW: Bitdefender Firewall *Enabled* {A364D236-8096-DCCF-EF3F-4E4DBCD170CF} SP: Bitdefender Spyware-Schutz *Disabled/Updated* {203EB2F7-ECC3-D219-FED0-DC0A39857D09} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\1360930647.bdinstall.bin c:\programdata\1360930808.bdinstall.bin c:\programdata\1360930886.bdinstall.bin c:\users\Axel\AppData\Local\Microsoft\Windows\Temporary Internet Files\{797D903A-649E-45BA-AC97-AD53DC962E34}.xps c:\users\Axel\AppData\Local\Microsoft\Windows\Temporary Internet Files\{F5B92229-304C-4CB2-9550-0DC2FE467405}.xps c:\windows\SysWow64\dbcdbf32.dll . . ((((((((((((((((((((((( Dateien erstellt von 2014-04-13 bis 2014-05-13 )))))))))))))))))))))))))))))) . . 2014-05-13 10:27 . 2014-05-13 10:27 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F868F826-EED1-464A-879C-9C01EF7DA6F9}\offreg.dll 2014-05-13 05:48 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F868F826-EED1-464A-879C-9C01EF7DA6F9}\mpengine.dll 2014-05-12 20:07 . 2014-05-12 20:07 -------- d-----w- c:\users\Axel\AppData\Roaming\Opera Software 2014-05-12 20:07 . 2014-05-12 20:07 -------- d-----w- c:\users\Axel\AppData\Local\Opera Software 2014-05-12 20:07 . 2014-05-12 20:07 -------- d-----w- c:\program files (x86)\Opera 2014-05-12 19:32 . 2014-05-12 19:32 -------- d-----w- C:\FRST 2014-05-07 06:24 . 2014-05-07 06:24 -------- d-----w- c:\users\Axel\AppData\Roaming\DropboxMaster 2014-05-07 06:20 . 2014-05-07 06:20 -------- d-s---w- c:\windows\system32\CompatTel 2014-05-06 11:09 . 2014-04-14 02:24 465408 ----a-w- c:\windows\system32\aepdu.dll 2014-05-06 11:09 . 2014-04-14 02:19 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-05-04 07:41 . 2014-04-29 14:01 23547904 ----a-w- c:\windows\system32\mshtml.dll 2014-05-04 07:41 . 2014-04-29 13:40 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-04 07:41 . 2014-04-29 12:34 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-04-30 15:51 . 2014-04-30 22:52 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2014-04-29 03:17 . 2014-05-13 05:44 94656 ----a-w- c:\windows\system32\WPRO_41_2001woem.tmp 2014-04-21 08:21 . 2014-04-21 08:21 -------- d-sh--w- c:\users\Axel\AppData\Local\EmieUserList 2014-04-21 08:21 . 2014-04-21 08:21 -------- d-sh--w- c:\users\Axel\AppData\Local\EmieSiteList . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-05-13 05:44 . 2013-01-23 07:37 34752 ----a-w- c:\windows\system32\drivers\WPRO_41_2001.sys 2014-05-07 13:10 . 2013-10-17 16:48 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin 2014-04-29 15:49 . 2013-01-23 07:44 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-04-29 15:49 . 2013-01-23 07:44 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-04-10 08:43 . 2013-02-02 16:13 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-31 07:35 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-03-06 09:31 . 2014-04-12 03:46 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-06 08:59 . 2014-04-12 03:46 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-06 08:57 . 2014-04-12 03:46 548352 ----a-w- c:\windows\system32\vbscript.dll 2014-03-06 08:57 . 2014-04-12 03:46 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-06 08:53 . 2014-04-12 03:46 2767360 ----a-w- c:\windows\system32\iertutil.dll 2014-03-06 08:40 . 2014-04-12 03:46 51200 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-06 08:39 . 2014-04-12 03:46 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-06 08:32 . 2014-04-12 03:46 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-06 08:29 . 2014-04-12 03:46 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-06 08:29 . 2014-04-12 03:46 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-06 08:28 . 2014-04-12 03:46 752640 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-06 08:15 . 2014-04-12 03:46 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-06 08:11 . 2014-04-12 03:46 5784064 ----a-w- c:\windows\system32\jscript9.dll 2014-03-06 08:09 . 2014-04-12 03:46 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2014-03-06 08:03 . 2014-04-12 03:46 586240 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-06 08:02 . 2014-04-12 03:46 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-06 08:02 . 2014-04-12 03:46 455168 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-03-06 08:01 . 2014-04-12 03:46 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-06 07:56 . 2014-04-12 03:46 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-03-06 07:48 . 2014-04-12 03:46 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-06 07:46 . 2014-04-12 03:46 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-06 07:42 . 2014-04-12 03:46 296960 ----a-w- c:\windows\system32\dxtrans.dll 2014-03-06 07:38 . 2014-04-12 03:46 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-06 07:36 . 2014-04-12 03:46 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-06 07:21 . 2014-04-12 03:46 628736 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-06 07:13 . 2014-04-12 03:46 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-03-06 07:11 . 2014-04-12 03:46 2043904 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-06 06:53 . 2014-04-12 03:46 13551104 ----a-w- c:\windows\system32\ieframe.dll 2014-03-06 06:40 . 2014-04-12 03:46 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-06 06:22 . 2014-04-12 03:46 2260480 ----a-w- c:\windows\system32\wininet.dll 2014-03-06 05:58 . 2014-04-12 03:46 1400832 ----a-w- c:\windows\system32\urlmon.dll 2014-03-06 05:50 . 2014-04-12 03:46 846336 ----a-w- c:\windows\system32\ieapfltr.dll 2014-03-06 05:41 . 2014-04-12 03:46 1789440 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-04 09:44 . 2014-04-09 05:32 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-03-04 09:44 . 2014-04-09 05:32 243712 ----a-w- c:\windows\system32\wow64.dll 2014-03-04 09:44 . 2014-04-09 05:32 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2014-03-04 09:44 . 2014-04-09 05:32 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2014-03-04 09:44 . 2014-04-09 05:32 1163264 ----a-w- c:\windows\system32\kernel32.dll 2014-03-04 09:17 . 2014-04-09 05:32 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2014-03-04 09:17 . 2014-04-09 05:32 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-04 09:16 . 2014-04-09 05:32 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2014-03-04 09:16 . 2014-04-09 05:32 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2014-03-04 08:09 . 2014-04-09 05:32 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2014-03-04 08:09 . 2014-04-09 05:32 2048 ----a-w- c:\windows\SysWow64\user.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Syncovery Background Scheduler"="c:\program files (x86)\Syncovery\SyncoveryService.exe" [2012-12-05 15304016] "GarminExpressTrayApp"="c:\program files (x86)\Garmin\Express Tray\ExpressTray.exe" [2013-12-30 1095000] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] . c:\users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-4-18 33604728] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\appinit_dll.dll . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AIDA64Driver;FinalWire AIDA64 Kernel Driver;j:\appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\kerneld.x64;j:\appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\kerneld.x64 [x] R3 AsrCDDrv;AsrCDDrv;c:\windows\SysWOW64\Drivers\AsrCDDrv.sys;c:\windows\SysWOW64\Drivers\AsrCDDrv.sys [x] R3 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys;c:\windows\SYSNATIVE\DRIVERS\avckf.sys [x] R3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys;c:\windows\SYSNATIVE\drivers\bdsandbox.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x] R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe;c:\program files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [x] R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x] R4 RsFx0151;RsFx0151 Driver;c:\windows\system32\DRIVERS\RsFx0151.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0151.sys [x] R4 SQLAgent$SQLMULTIBASECS;SQL Server-Agent (SQLMULTIBASECS);c:\program files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\SQLAGENT.EXE [x] S0 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys;c:\windows\SYSNATIVE\DRIVERS\avc3.sys [x] S0 gzflt;gzflt;c:\windows\system32\DRIVERS\gzflt.sys;c:\windows\SYSNATIVE\DRIVERS\gzflt.sys [x] S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [x] S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys;c:\program files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 Garmin Core Update Service;Garmin Core Update Service;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 MSSQL$SQLMULTIBASECS;SQL Server (SQLMULTIBASECS);c:\program files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe;c:\program files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe [x] S2 SyncoveryVSSService;SyncoveryVSSService;c:\program files (x86)\Syncovery\SyncoveryVSS.exe;c:\program files (x86)\Syncovery\SyncoveryVSS.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe;c:\program files\Bitdefender\Bitdefender 2013\updatesrv.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 avchv;avchv Function Driver;c:\windows\system32\DRIVERS\avchv.sys;c:\windows\SYSNATIVE\DRIVERS\avchv.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x] S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x] S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x] S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 VirtuWDDM;VirtuWDDM;c:\windows\system32\DRIVERS\VirtuWDDM.sys;c:\windows\SYSNATIVE\DRIVERS\VirtuWDDM.sys [x] S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-05-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-23 15:49] . 2014-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-29 09:40] . 2014-05-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-29 09:40] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Axel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-06-09 11860072] "VIRTU"="c:\program files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe" [2012-04-22 2593568] "Bdagent"="c:\program files\Bitdefender\Bitdefender 2013\bdagent.exe" [2013-10-24 1575192] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\appinit_dll.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: An OneNote s&enden - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 192.168.2.1 FF - ProfilePath - c:\users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AIDA64Driver] "ImagePath"="\??\j:\appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\kerneld.x64" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-05-13 19:43:37 ComboFix-quarantined-files.txt 2014-05-13 17:43 . Vor Suchlauf: 14 Verzeichnis(se), 56.452.931.584 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 59.042.689.024 Bytes frei . - - End Of File - - 1B4C85CC6A7A033E2A39DC4FA7DF3953 A36C5E4F47E84449FF07ED3517B43A31 |
14.05.2014, 19:09 | #24 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnet Paar Reste, aber es is noch jede Menge Adware da. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.05.2014, 05:24 | #25 |
| Windows 7, 64 bit, Trojaner über Email geöffnet mbam.txt Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 15.05.2014 Suchlauf-Zeit: 02:44:57 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.05.14.11 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Axel Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 366369 Verstrichene Zeit: 3 Min, 33 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.208 - Bericht erstellt am 15/05/2014 um 06:11:41 # Aktualisiert 11/05/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Axel - CORE-I7-3770 # Gestartet von : C:\Users\Axel\Desktop\adwcleaner_3.208.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Ask Datei Gelöscht : C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\searchplugins\Askcom.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Wert Gelöscht : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1] ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\prefs.js ] Zeile gelöscht : user_pref("browser.search.order.1", "Ask.com"); ************************* AdwCleaner[R0].txt - [1413 octets] - [15/05/2014 06:09:49] AdwCleaner[S0].txt - [1334 octets] - [15/05/2014 06:11:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1394 octets] ########## JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by Axel on 15.05.2014 at 6:13:25,65 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{888C2D85-2D24-4BCA-8E5E-3CC93717A017} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Axel\AppData\Roaming\mozilla\firefox\profiles\2g5u56xm.default\minidumps [60 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 15.05.2014 at 6:18:10,14 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST vergessen FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01 Ran by Axel (administrator) on CORE-I7-3770 on 15-05-2014 06:22:49 Running from C:\Users\Axel\Desktop Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Super Flexible Software Ltd. & Co. KG) C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Syncovery\SyncoveryService.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Dropbox, Inc.) C:\Users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (LucidLogix) C:\Program Files\Lucidlogix Technologies\VIRTU\LucidServices.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM\...\Run: [VIRTU] => C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe [2593568 2012-04-22] () HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-10-24] (Bitdefender) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1394281553-801495742-107340834-1002\...\Run: [Syncovery Background Scheduler] => C:\Program Files (x86)\Syncovery\SyncoveryService.exe [15304016 2012-12-06] () HKU\S-1-5-21-1394281553-801495742-107340834-1002\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries) AppInit_DLLs: C:\Windows\System32\appinit_dll.dll => C:\Windows\System32\appinit_dll.dll [456992 2012-04-22] (Lucidlogix Inc.) AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll => C:\Windows\SysWOW64\appinit_dll.dll [411936 2012-04-22] (Lucidlogix Inc.) Startup: C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1112748220FBCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.11.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @garmin.com/GpsControl - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\Extensions\firefox@ghostery.com.xpi [2013-08-17] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] ==================== Services (Whitelisted) ================= S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-10-24] (Bitdefender) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 MSSQL$SQLMULTIBASECS; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation) S4 SQLAgent$SQLMULTIBASECS; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation) R2 SyncoveryVSSService; C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe [3255632 2012-06-25] (Super Flexible Software Ltd. & Co. KG) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-10-24] (Bitdefender) R2 vsserv; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-10-24] (Bitdefender) ==================== Drivers (Whitelisted) ==================== R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-10-24] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-10-24] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-04-29] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-10-24] (BitDefender SRL) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-24] (BitDefender LLC) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-15] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-24] (BitDefender S.R.L.) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-05-15] () S3 AIDA64Driver; \??\J:\Appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\kerneld.x64 [X] S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-15 06:18 - 2014-05-15 06:18 - 00001036 _____ () C:\Users\Axel\Desktop\JRT.txt 2014-05-15 06:13 - 2014-05-15 06:13 - 00000000 ____D () C:\Windows\ERUNT 2014-05-15 06:12 - 2014-05-15 06:12 - 00001474 _____ () C:\Users\Axel\Desktop\AdwCleaner[S0].txt 2014-05-15 06:09 - 2014-05-15 06:11 - 00000000 ____D () C:\AdwCleaner 2014-05-15 06:08 - 2014-05-15 06:08 - 01016261 _____ (Thisisu) C:\Users\Axel\Desktop\JRT.exe 2014-05-15 06:07 - 2014-05-15 06:07 - 01325827 _____ () C:\Users\Axel\Desktop\adwcleaner_3.208.exe 2014-05-15 06:06 - 2014-05-15 06:06 - 00001147 _____ () C:\Users\Axel\Desktop\mbam.txt 2014-05-15 03:02 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 03:02 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 03:02 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 03:02 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 03:02 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 03:02 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 21:09 - 2014-05-15 06:12 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-14 21:09 - 2014-05-14 21:09 - 00001105 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-14 21:09 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-14 21:09 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-14 21:09 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-14 21:08 - 2014-05-14 21:08 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Axel\Desktop\mbam-setup-2.0.1.1004.exe 2014-05-14 11:24 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 11:24 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 11:24 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 11:24 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 11:23 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 11:23 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 11:23 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 11:23 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 11:23 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 11:23 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 11:23 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 11:23 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 11:23 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 11:23 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 11:23 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 11:23 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 11:23 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 11:23 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 11:23 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 11:23 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-13 19:56 - 2014-05-13 19:57 - 05200050 _____ (Swearware) C:\Users\Axel\Downloads\ComboFix.exe 2014-05-13 19:43 - 2014-05-13 19:43 - 00025671 _____ () C:\ComboFix.txt 2014-05-13 19:38 - 2014-05-13 19:43 - 00000000 ____D () C:\Qoobox 2014-05-13 19:38 - 2014-05-13 19:42 - 00000000 ____D () C:\Windows\erdnt 2014-05-13 19:38 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-13 19:38 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-13 19:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-13 19:35 - 2014-05-13 19:36 - 05200050 ____R (Swearware) C:\Users\Axel\Desktop\ComboFix.exe 2014-05-12 22:07 - 2014-05-12 22:07 - 00001132 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-12 22:06 - 2014-05-12 22:07 - 28042800 _____ (Opera Software ASA) C:\Users\Axel\Downloads\Opera_21.0.1432.57_Setup.exe 2014-05-12 21:32 - 2014-05-15 06:22 - 00013562 _____ () C:\Users\Axel\Desktop\FRST.txt 2014-05-12 21:32 - 2014-05-15 06:22 - 00000000 ____D () C:\FRST 2014-05-12 21:32 - 2014-05-12 21:32 - 00032115 _____ () C:\Users\Axel\Desktop\Addition.txt 2014-05-12 21:29 - 2014-05-14 21:06 - 00000000 ____D () C:\Users\Axel\Desktop\Desktop-Bilder 2014-05-12 21:28 - 2014-05-12 21:28 - 02066944 _____ (Farbar) C:\Users\Axel\Desktop\FRST64.exe 2014-05-10 10:30 - 2014-05-10 10:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-07 08:24 - 2014-05-07 08:24 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\DropboxMaster 2014-05-07 08:20 - 2014-05-15 03:17 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 17:51 - 2014-05-01 00:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-29 05:17 - 2014-05-15 06:12 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieUserList 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieSiteList 2014-04-15 02:34 - 2014-04-15 02:34 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX ==================== One Month Modified Files and Folders ======= 2014-05-15 06:22 - 2014-05-12 21:32 - 00013562 _____ () C:\Users\Axel\Desktop\FRST.txt 2014-05-15 06:22 - 2014-05-12 21:32 - 00000000 ____D () C:\FRST 2014-05-15 06:19 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-15 06:19 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-15 06:18 - 2014-05-15 06:18 - 00001036 _____ () C:\Users\Axel\Desktop\JRT.txt 2014-05-15 06:18 - 2011-04-12 09:43 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-05-15 06:18 - 2011-04-12 09:43 - 00175138 _____ () C:\Windows\system32\perfc007.dat 2014-05-15 06:18 - 2009-07-14 07:13 - 01807994 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-15 06:14 - 2013-02-15 19:25 - 00000000 ____D () C:\ProgramData\firebird 2014-05-15 06:13 - 2014-05-15 06:13 - 00000000 ____D () C:\Windows\ERUNT 2014-05-15 06:13 - 2013-01-23 10:45 - 00000000 ____D () C:\ProgramData\Syncovery 2014-05-15 06:12 - 2014-05-15 06:12 - 00001474 _____ () C:\Users\Axel\Desktop\AdwCleaner[S0].txt 2014-05-15 06:12 - 2014-05-14 21:09 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-15 06:12 - 2014-04-29 05:17 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-05-15 06:12 - 2013-03-11 10:27 - 00000000 ___RD () C:\Users\Axel\Dropbox 2014-05-15 06:12 - 2013-03-11 10:25 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Dropbox 2014-05-15 06:12 - 2013-01-29 11:40 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-15 06:12 - 2013-01-23 09:37 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys 2014-05-15 06:12 - 2010-11-21 05:47 - 09320522 _____ () C:\Windows\PFRO.log 2014-05-15 06:12 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-15 06:12 - 2009-07-14 06:51 - 00081494 _____ () C:\Windows\setupact.log 2014-05-15 06:11 - 2014-05-15 06:09 - 00000000 ____D () C:\AdwCleaner 2014-05-15 06:11 - 2013-01-22 15:42 - 02088909 _____ () C:\Windows\WindowsUpdate.log 2014-05-15 06:08 - 2014-05-15 06:08 - 01016261 _____ (Thisisu) C:\Users\Axel\Desktop\JRT.exe 2014-05-15 06:07 - 2014-05-15 06:07 - 01325827 _____ () C:\Users\Axel\Desktop\adwcleaner_3.208.exe 2014-05-15 06:06 - 2014-05-15 06:06 - 00001147 _____ () C:\Users\Axel\Desktop\mbam.txt 2014-05-15 06:05 - 2013-03-11 10:25 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-15 06:05 - 2013-01-25 18:54 - 00000000 ___RD () C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-15 05:49 - 2013-01-23 09:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-15 05:28 - 2013-01-29 11:40 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-15 03:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-15 03:17 - 2014-05-07 08:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 03:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-15 03:02 - 2013-01-26 01:43 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 03:01 - 2013-07-17 14:33 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 03:01 - 2013-02-02 18:13 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 21:09 - 2014-05-14 21:09 - 00001105 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-14 21:08 - 2014-05-14 21:08 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Axel\Desktop\mbam-setup-2.0.1.1004.exe 2014-05-14 21:06 - 2014-05-12 21:29 - 00000000 ____D () C:\Users\Axel\Desktop\Desktop-Bilder 2014-05-14 17:49 - 2013-01-23 09:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 17:49 - 2013-01-23 09:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-14 17:49 - 2013-01-23 09:44 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-13 19:57 - 2014-05-13 19:56 - 05200050 _____ (Swearware) C:\Users\Axel\Downloads\ComboFix.exe 2014-05-13 19:43 - 2014-05-13 19:43 - 00025671 _____ () C:\ComboFix.txt 2014-05-13 19:43 - 2014-05-13 19:38 - 00000000 ____D () C:\Qoobox 2014-05-13 19:42 - 2014-05-13 19:38 - 00000000 ____D () C:\Windows\erdnt 2014-05-13 19:42 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-13 19:36 - 2014-05-13 19:35 - 05200050 ____R (Swearware) C:\Users\Axel\Desktop\ComboFix.exe 2014-05-12 22:07 - 2014-05-12 22:07 - 00001132 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-12 22:07 - 2014-05-12 22:06 - 28042800 _____ (Opera Software ASA) C:\Users\Axel\Downloads\Opera_21.0.1432.57_Setup.exe 2014-05-12 21:32 - 2014-05-12 21:32 - 00032115 _____ () C:\Users\Axel\Desktop\Addition.txt 2014-05-12 21:28 - 2014-05-12 21:28 - 02066944 _____ (Farbar) C:\Users\Axel\Desktop\FRST64.exe 2014-05-10 15:46 - 2013-01-25 19:29 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-10 10:30 - 2014-05-10 10:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-09 08:23 - 2013-01-29 11:40 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 08:23 - 2013-01-29 11:40 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-09 08:14 - 2014-05-14 11:24 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-14 11:24 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-08 16:24 - 2013-04-23 11:31 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\vlc 2014-05-08 09:57 - 2013-01-26 02:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\CutePDF Writer 2014-05-07 08:24 - 2014-05-07 08:24 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\DropboxMaster 2014-05-06 06:40 - 2014-05-15 03:02 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 03:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 03:02 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 03:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 03:02 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 03:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-05 18:28 - 2014-01-20 21:34 - 00161634 _____ () C:\Users\Axel\Documents\Brother Jana 2014-05-04 18:53 - 2013-01-26 01:43 - 00000000 ____D () C:\Users\Axel\AppData\Local\Microsoft Help 2014-05-01 00:52 - 2014-04-30 17:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieUserList 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieSiteList 2014-04-20 16:42 - 2014-03-28 01:30 - 00000000 ____D () C:\Users\Axel\AppData\Local\Windows Live 2014-04-15 02:34 - 2014-04-15 02:34 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX Some content of TEMP: ==================== C:\Users\Axel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpr2dsjq.dll C:\Users\Axel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe [2014-05-14 11:23] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-09 11:45 ==================== End Of Log ============================ --- --- --- Sooo, jetzt aber... |
15.05.2014, 19:57 | #26 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnetESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.05.2014, 21:13 | #27 |
| Windows 7, 64 bit, Trojaner über Email geöffnet ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=6856e58a86656d47978f2a76dcf0acd5 # engine=18279 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-15 07:58:07 # local_time=2014-05-15 09:58:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1023 16777215 0 0 0 0 0 0 # compatibility_mode=5893 16776573 100 94 5627 151813737 0 0 # scanned=271847 # found=1 # cleaned=0 # scan_time=2310 sh=912E823A73BBE47FC8262CA441DFC5E807070E78 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\Axel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\5ff55dc9-4525580e" Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Bitdefender Virenschutz Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.214 Mozilla Firefox (29.0.1) Mozilla Thunderbird (24.5.0) ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Bitdefender Bitdefender 2013 bdagent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-05-2014 Ran by Axel (administrator) on CORE-I7-3770 on 15-05-2014 22:11:04 Running from C:\Users\Axel\Desktop Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Super Flexible Software Ltd. & Co. KG) C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Syncovery\SyncoveryService.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Dropbox, Inc.) C:\Users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (LucidLogix) C:\Program Files\Lucidlogix Technologies\VIRTU\LucidServices.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-09] (Realtek Semiconductor) HKLM\...\Run: [VIRTU] => C:\Program Files\Lucidlogix Technologies\VIRTU\VirtuControlPanel.Exe [2593568 2012-04-22] () HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-10-24] (Bitdefender) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1832760 2012-09-20] (Logitech, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1394281553-801495742-107340834-1002\...\Run: [Syncovery Background Scheduler] => C:\Program Files (x86)\Syncovery\SyncoveryService.exe [15304016 2012-12-06] () HKU\S-1-5-21-1394281553-801495742-107340834-1002\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries) AppInit_DLLs: C:\Windows\System32\appinit_dll.dll => C:\Windows\System32\appinit_dll.dll [456992 2012-04-22] (Lucidlogix Inc.) AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll => C:\Windows\SysWOW64\appinit_dll.dll [411936 2012-04-22] (Lucidlogix Inc.) Startup: C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Axel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x1112748220FBCD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default FF SelectedSearchEngine: Google FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.11.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @garmin.com/GpsControl - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Ghostery - C:\Users\Axel\AppData\Roaming\Mozilla\Firefox\Profiles\2g5u56xm.default\Extensions\firefox@ghostery.com.xpi [2013-08-17] FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2013-02-15] ==================== Services (Whitelisted) ================= S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-10-24] (Bitdefender) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 MSSQL$SQLMULTIBASECS; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation) S4 SQLAgent$SQLMULTIBASECS; C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLMULTIBASECS\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation) R2 SyncoveryVSSService; C:\Program Files (x86)\Syncovery\SyncoveryVSS.exe [3255632 2012-06-25] (Super Flexible Software Ltd. & Co. KG) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-10-24] (Bitdefender) R2 vsserv; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-10-24] (Bitdefender) ==================== Drivers (Whitelisted) ==================== R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-10-24] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-10-24] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-04-29] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-10-24] (BitDefender SRL) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-24] (BitDefender LLC) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-05-15] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-24] (BitDefender S.R.L.) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2014-05-15] () S3 AIDA64Driver; \??\J:\Appz\Benchmark\AIDA64 Extreme Edition v2.70.2200\kerneld.x64 [X] S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-15 22:10 - 2014-05-15 22:10 - 00000835 _____ () C:\Users\Axel\Desktop\checkup.txt 2014-05-15 22:10 - 2014-05-15 22:10 - 00000000 ____D () C:\Users\Axel\Desktop\FRST-OlderVersion 2014-05-15 22:09 - 2014-05-15 22:09 - 00855379 _____ () C:\Users\Axel\Desktop\SecurityCheck.exe 2014-05-15 06:23 - 2014-05-15 06:23 - 00033036 _____ () C:\Users\Axel\Desktop\FRST150514.txt 2014-05-15 06:18 - 2014-05-15 06:18 - 00001036 _____ () C:\Users\Axel\Desktop\JRT.txt 2014-05-15 06:13 - 2014-05-15 06:13 - 00000000 ____D () C:\Windows\ERUNT 2014-05-15 06:12 - 2014-05-15 06:12 - 00001474 _____ () C:\Users\Axel\Desktop\AdwCleaner[S0].txt 2014-05-15 06:09 - 2014-05-15 06:11 - 00000000 ____D () C:\AdwCleaner 2014-05-15 06:08 - 2014-05-15 06:08 - 01016261 _____ (Thisisu) C:\Users\Axel\Desktop\JRT.exe 2014-05-15 06:07 - 2014-05-15 06:07 - 01325827 _____ () C:\Users\Axel\Desktop\adwcleaner_3.208.exe 2014-05-15 06:06 - 2014-05-15 06:06 - 00001147 _____ () C:\Users\Axel\Desktop\mbam.txt 2014-05-15 03:02 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 03:02 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 03:02 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 03:02 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 03:02 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 03:02 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 21:09 - 2014-05-15 20:58 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-14 21:09 - 2014-05-14 21:09 - 00001105 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-14 21:09 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-14 21:09 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-14 21:09 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-14 21:08 - 2014-05-14 21:08 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Axel\Desktop\mbam-setup-2.0.1.1004.exe 2014-05-14 11:24 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 11:24 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 11:24 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 11:24 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 11:23 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 11:23 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 11:23 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 11:23 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 11:23 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 11:23 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 11:23 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 11:23 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 11:23 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 11:23 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 11:23 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 11:23 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 11:23 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 11:23 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 11:23 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 11:23 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 11:23 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 11:23 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 11:23 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-13 19:43 - 2014-05-13 19:43 - 00025671 _____ () C:\ComboFix.txt 2014-05-13 19:38 - 2014-05-13 19:43 - 00000000 ____D () C:\Qoobox 2014-05-13 19:38 - 2014-05-13 19:42 - 00000000 ____D () C:\Windows\erdnt 2014-05-13 19:38 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-13 19:38 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-13 19:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-13 19:38 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-13 19:35 - 2014-05-13 19:36 - 05200050 ____R (Swearware) C:\Users\Axel\Desktop\ComboFix.exe 2014-05-12 22:07 - 2014-05-12 22:07 - 00001132 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-12 22:06 - 2014-05-12 22:07 - 28042800 _____ (Opera Software ASA) C:\Users\Axel\Downloads\Opera_21.0.1432.57_Setup.exe 2014-05-12 21:32 - 2014-05-15 22:11 - 00013633 _____ () C:\Users\Axel\Desktop\FRST.txt 2014-05-12 21:32 - 2014-05-15 22:11 - 00000000 ____D () C:\FRST 2014-05-12 21:32 - 2014-05-12 21:32 - 00032115 _____ () C:\Users\Axel\Desktop\Addition.txt 2014-05-12 21:29 - 2014-05-14 21:06 - 00000000 ____D () C:\Users\Axel\Desktop\Desktop-Bilder 2014-05-12 21:28 - 2014-05-15 22:10 - 02067456 _____ (Farbar) C:\Users\Axel\Desktop\FRST64.exe 2014-05-10 10:30 - 2014-05-10 10:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-07 08:24 - 2014-05-07 08:24 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\DropboxMaster 2014-05-07 08:20 - 2014-05-15 03:17 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 17:51 - 2014-05-01 00:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-29 05:17 - 2014-05-15 20:14 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieUserList 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieSiteList 2014-04-15 02:34 - 2014-04-15 02:34 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX ==================== One Month Modified Files and Folders ======= 2014-05-15 22:11 - 2014-05-12 21:32 - 00013633 _____ () C:\Users\Axel\Desktop\FRST.txt 2014-05-15 22:11 - 2014-05-12 21:32 - 00000000 ____D () C:\FRST 2014-05-15 22:10 - 2014-05-15 22:10 - 00000835 _____ () C:\Users\Axel\Desktop\checkup.txt 2014-05-15 22:10 - 2014-05-15 22:10 - 00000000 ____D () C:\Users\Axel\Desktop\FRST-OlderVersion 2014-05-15 22:10 - 2014-05-12 21:28 - 02067456 _____ (Farbar) C:\Users\Axel\Desktop\FRST64.exe 2014-05-15 22:09 - 2014-05-15 22:09 - 00855379 _____ () C:\Users\Axel\Desktop\SecurityCheck.exe 2014-05-15 21:49 - 2013-01-23 09:44 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-05-15 21:28 - 2013-01-29 11:40 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-15 20:58 - 2014-05-14 21:09 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-15 20:21 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-15 20:21 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-15 20:18 - 2011-04-12 09:43 - 00765588 _____ () C:\Windows\system32\perfh007.dat 2014-05-15 20:18 - 2011-04-12 09:43 - 00175138 _____ () C:\Windows\system32\perfc007.dat 2014-05-15 20:18 - 2009-07-14 07:13 - 01807994 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-15 20:17 - 2013-01-22 15:42 - 01057061 _____ () C:\Windows\WindowsUpdate.log 2014-05-15 20:16 - 2013-02-15 19:25 - 00000000 ____D () C:\ProgramData\firebird 2014-05-15 20:14 - 2014-04-29 05:17 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2014-05-15 20:14 - 2013-03-11 10:27 - 00000000 ___RD () C:\Users\Axel\Dropbox 2014-05-15 20:14 - 2013-03-11 10:25 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Dropbox 2014-05-15 20:14 - 2013-01-29 11:40 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-15 20:14 - 2013-01-23 10:45 - 00000000 ____D () C:\ProgramData\Syncovery 2014-05-15 20:14 - 2013-01-23 09:37 - 00034752 _____ () C:\Windows\system32\Drivers\WPRO_41_2001.sys 2014-05-15 20:14 - 2010-11-21 05:47 - 09320852 _____ () C:\Windows\PFRO.log 2014-05-15 20:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-15 20:14 - 2009-07-14 06:51 - 00081550 _____ () C:\Windows\setupact.log 2014-05-15 06:23 - 2014-05-15 06:23 - 00033036 _____ () C:\Users\Axel\Desktop\FRST150514.txt 2014-05-15 06:18 - 2014-05-15 06:18 - 00001036 _____ () C:\Users\Axel\Desktop\JRT.txt 2014-05-15 06:13 - 2014-05-15 06:13 - 00000000 ____D () C:\Windows\ERUNT 2014-05-15 06:12 - 2014-05-15 06:12 - 00001474 _____ () C:\Users\Axel\Desktop\AdwCleaner[S0].txt 2014-05-15 06:11 - 2014-05-15 06:09 - 00000000 ____D () C:\AdwCleaner 2014-05-15 06:08 - 2014-05-15 06:08 - 01016261 _____ (Thisisu) C:\Users\Axel\Desktop\JRT.exe 2014-05-15 06:07 - 2014-05-15 06:07 - 01325827 _____ () C:\Users\Axel\Desktop\adwcleaner_3.208.exe 2014-05-15 06:06 - 2014-05-15 06:06 - 00001147 _____ () C:\Users\Axel\Desktop\mbam.txt 2014-05-15 06:05 - 2013-03-11 10:25 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-15 06:05 - 2013-01-25 18:54 - 00000000 ___RD () C:\Users\Axel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-15 03:43 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-15 03:17 - 2014-05-07 08:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 03:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-15 03:02 - 2013-01-26 01:43 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 03:01 - 2013-07-17 14:33 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 03:01 - 2013-02-02 18:13 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 21:09 - 2014-05-14 21:09 - 00001105 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-14 21:09 - 2014-05-14 21:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-14 21:08 - 2014-05-14 21:08 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Axel\Desktop\mbam-setup-2.0.1.1004.exe 2014-05-14 21:06 - 2014-05-12 21:29 - 00000000 ____D () C:\Users\Axel\Desktop\Desktop-Bilder 2014-05-14 17:49 - 2013-01-23 09:44 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 17:49 - 2013-01-23 09:44 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-14 17:49 - 2013-01-23 09:44 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-13 19:43 - 2014-05-13 19:43 - 00025671 _____ () C:\ComboFix.txt 2014-05-13 19:43 - 2014-05-13 19:38 - 00000000 ____D () C:\Qoobox 2014-05-13 19:42 - 2014-05-13 19:38 - 00000000 ____D () C:\Windows\erdnt 2014-05-13 19:42 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-13 19:36 - 2014-05-13 19:35 - 05200050 ____R (Swearware) C:\Users\Axel\Desktop\ComboFix.exe 2014-05-12 22:07 - 2014-05-12 22:07 - 00001132 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\Opera Software 2014-05-12 22:07 - 2014-05-12 22:07 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-05-12 22:07 - 2014-05-12 22:06 - 28042800 _____ (Opera Software ASA) C:\Users\Axel\Downloads\Opera_21.0.1432.57_Setup.exe 2014-05-12 21:32 - 2014-05-12 21:32 - 00032115 _____ () C:\Users\Axel\Desktop\Addition.txt 2014-05-10 15:46 - 2013-01-25 19:29 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-10 10:30 - 2014-05-10 10:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-09 08:23 - 2013-01-29 11:40 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-09 08:23 - 2013-01-29 11:40 - 00003850 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-09 08:14 - 2014-05-14 11:24 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-14 11:24 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-08 16:24 - 2013-04-23 11:31 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\vlc 2014-05-08 09:57 - 2013-01-26 02:07 - 00000000 ____D () C:\Users\Axel\AppData\Local\CutePDF Writer 2014-05-07 08:24 - 2014-05-07 08:24 - 00000000 ____D () C:\Users\Axel\AppData\Roaming\DropboxMaster 2014-05-06 06:40 - 2014-05-15 03:02 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 03:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 03:02 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 03:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 03:02 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 03:02 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-05 18:28 - 2014-01-20 21:34 - 00161634 _____ () C:\Users\Axel\Documents\Brother Jana 2014-05-04 18:53 - 2013-01-26 01:43 - 00000000 ____D () C:\Users\Axel\AppData\Local\Microsoft Help 2014-05-01 00:52 - 2014-04-30 17:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieUserList 2014-04-21 10:21 - 2014-04-21 10:21 - 00000000 __SHD () C:\Users\Axel\AppData\Local\EmieSiteList 2014-04-20 16:42 - 2014-03-28 01:30 - 00000000 ____D () C:\Users\Axel\AppData\Local\Windows Live 2014-04-15 02:34 - 2014-04-15 02:34 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL.OCX Some content of TEMP: ==================== C:\Users\Axel\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpsjrzn7.dll C:\Users\Axel\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe [2014-05-14 11:23] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-09 11:45 ==================== End Of Log ============================ |
16.05.2014, 12:08 | #28 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnet Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.05.2014, 13:47 | #29 |
| Windows 7, 64 bit, Trojaner über Email geöffnet Dank dir! Alles erledigt!!! |
17.05.2014, 13:36 | #30 |
/// the machine /// TB-Ausbilder | Windows 7, 64 bit, Trojaner über Email geöffnet Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7, 64 bit, Trojaner über Email geöffnet |
antivirus, avira, browser, converter, danke für eure hilfe!, desktop, dvdvideosoft ltd., email, excel, fehler, festplatte, firefox, firefox 28.0, flash player, google, helper, home, homepage, installation, log file, mozilla, realtek, registry, security, software, super, svchost.exe, trojaner, windows |