|
Log-Analyse und Auswertung: Wiederholte Sicherheitssperre des PostfachsWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.04.2014, 12:08 | #1 |
| Wiederholte Sicherheitssperre des Postfachs hallo, ich hoffe das hier ist der richtige Bereich für mein Anliegen. innerhalb von einem Monat wurde nun zum zweiten mal mein GMX-Postfach gesperrt. Habe folgende Mail bekommen "Lieber GMX Nutzer, es geht um Ihre Sicherheit: Unsere automatisierten Sicherheitssysteme haben Unregelmäßigkeiten beim Zugriff auf Ihr GMX Postfach festgestellt. Zu Ihrem persönlichen Schutz haben wir vorsorglich Ihr Postfach gesperrt. Daher werden wir Sie beim nächsten Login auffordern, Ihr Passwort zu ändern." Die mail scheint ja kein fake zu sein, das Postfach war beide male wirklich gesperrt (habe nicht den link in der mail benutzt, beim zweiten mal hab ich direkt mein Postfach gesperrt vorgefunden, von einem anderen Rechner aus). Deswegen mache ich mir Sorgen, das irgendetwas nicht in Ordnung sein könnte. Die Festplatte ist recht neu, deswegen ist auch alles recht neu aufgesetzt, aber das heißt natürlich nicht viel. wäre nett wenn jemand mal drüberschauen könnte mfg ---------------- Die Logfiles: defogger: konnte keine log schreiben, Daemon Tools ist installiert, läuft aber nicht. FRST-Logfiles, FRST.txt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2014 01 Ran by dude (administrator) on TBD on 14-04-2014 12:23:49 Running from C:\Users\dude\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1275608 2014-03-25] (COMODO) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-21-3588706896-3179500147-2110804584-1001\...\MountPoints2: {ab07c865-6630-11e3-970a-00221934f749} - J:\setup.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC18A4A6919F8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF SearchPlugin: C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\searchplugins\duckduckgo.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: HTTPS-Everywhere - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\https-everywhere@eff.org [2014-02-10] FF Extension: Certificate Patrol - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\CertPatrol@PSYC.EU.xpi [2014-01-30] FF Extension: Ghostery - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\firefox@ghostery.com.xpi [2014-01-29] FF Extension: Adblock Plus - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-13] FF Extension: BetterPrivacy - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-12-16] ==================== Services (Whitelisted) ================= R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6812400 2014-03-25] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2264280 2014-03-25] (COMODO) S4 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2013-05-07] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2014-03-25] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [738472 2014-03-25] (COMODO) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-16] (Disc Soft Ltd) R1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-14 12:23 - 2014-04-14 12:23 - 00007650 _____ () C:\Users\dude\Desktop\FRST.txt 2014-04-14 12:17 - 2014-04-14 12:23 - 00000000 ____D () C:\FRST 2014-04-14 12:16 - 2014-04-14 12:16 - 00000000 _____ () C:\Users\dude\defogger_reenable 2014-04-14 11:18 - 2014-04-14 11:18 - 00380416 _____ () C:\Users\dude\Desktop\Gmer-19357.exe 2014-04-14 11:17 - 2014-04-14 11:17 - 02157568 _____ (Farbar) C:\Users\dude\Desktop\FRST64.exe 2014-04-14 11:07 - 2014-04-14 11:07 - 00050477 _____ () C:\Users\dude\Desktop\Defogger.exe 2014-04-11 10:59 - 2014-04-11 11:01 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner (2) 2014-04-10 20:40 - 2014-04-10 20:43 - 00000420 _____ () C:\Users\dude\Desktop\sidechat08.txt 2014-04-10 18:40 - 2014-04-10 18:40 - 00000000 ____D () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split 2014-04-10 17:41 - 2014-04-10 17:43 - 15111863 _____ () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split.zip 2014-04-09 20:37 - 2014-04-09 20:37 - 00001393 _____ () C:\Users\dude\Desktop\devcpp.exe - Verknüpfung.lnk 2014-04-09 11:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 11:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 11:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 11:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 11:03 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 11:03 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 11:03 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 11:03 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 11:03 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 11:03 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-08 14:33 - 2014-04-08 14:34 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 14:32 - 2014-04-08 14:32 - 00000000 ____D () C:\Program Files (x86)\Dev-Cpp 2014-04-08 14:14 - 2014-04-08 14:14 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Scilab 2014-04-08 14:13 - 2014-04-09 19:54 - 00001081 _____ () C:\Users\Public\Desktop\scilab-5.4.1 (64-bit).lnk 2014-04-08 14:12 - 2014-04-08 14:14 - 00000000 ____D () C:\Program Files\scilab-5.4.1 2014-04-08 14:12 - 2014-04-08 14:12 - 28135014 _____ () C:\Users\dude\Desktop\scilab-help-chm-5.4.1.zip 2014-04-08 14:12 - 2014-04-08 14:12 - 20593796 _____ () C:\Users\dude\Desktop\blas-lapack-mkl-5.4.1-win64.zip 2014-04-08 14:11 - 2014-04-08 14:11 - 13866852 _____ () C:\Users\dude\Desktop\commons-mkl-5.4.1-win64.zip 2014-04-08 13:48 - 2014-04-08 13:48 - 00036864 _____ (Juliett_Six) C:\Users\dude\Desktop\WT_Logger_v0.13_64bit.exe 2014-04-04 11:44 - 2010-01-18 15:49 - 00000000 ____D () C:\Users\dude\Desktop\Mouse On The Keys - An Anxious Object (2009) 2014-04-03 12:39 - 2014-04-03 12:39 - 00004540 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-03 12:39 - 2014-04-03 12:39 - 00000000 ___HD () C:\VTRoot 2014-04-01 13:15 - 2014-04-01 13:15 - 00001134 _____ () C:\Users\dude\Desktop\history - Verknüpfung.lnk 2014-04-01 13:12 - 2014-04-01 13:12 - 00000722 _____ () C:\Users\dude\Desktop\Kram - Verknüpfung.lnk 2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Users\dude\Desktop\shega 2014-03-31 13:40 - 2014-03-31 13:40 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner 2014-03-28 17:30 - 2014-03-28 17:30 - 00003138 _____ () C:\Windows\System32\Tasks\{AA396EED-30E7-4B22-840F-0BD819D675B2} 2014-03-28 12:17 - 2014-03-28 12:17 - 00000000 ____D () C:\Windows\Sun 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Users\dude\AppData\Roaming\OpenOffice 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-25 11:23 - 2014-03-25 11:23 - 00036041 _____ () C:\Users\dude\Desktop\TLAL Vault (2).zip 2014-03-18 19:04 - 2014-03-18 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-18 19:00 - 2014-03-19 12:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-15 18:14 - 2014-03-15 18:14 - 00000000 ____D () C:\Users\dude\Desktop\WT Logging Utility Documentation 2014-03-15 11:53 - 2014-03-15 11:53 - 00000000 ____D () C:\Windows\pss ==================== One Month Modified Files and Folders ======= 2014-04-14 12:23 - 2014-04-14 12:23 - 00007650 _____ () C:\Users\dude\Desktop\FRST.txt 2014-04-14 12:23 - 2014-04-14 12:17 - 00000000 ____D () C:\FRST 2014-04-14 12:16 - 2014-04-14 12:16 - 00000000 _____ () C:\Users\dude\defogger_reenable 2014-04-14 12:16 - 2013-12-13 18:03 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-04-14 12:16 - 2013-12-13 17:34 - 00000000 ____D () C:\Users\dude 2014-04-14 12:11 - 2013-12-13 20:20 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Macromedia 2014-04-14 12:06 - 2013-12-13 17:33 - 01326776 _____ () C:\Windows\WindowsUpdate.log 2014-04-14 11:18 - 2014-04-14 11:18 - 00380416 _____ () C:\Users\dude\Desktop\Gmer-19357.exe 2014-04-14 11:17 - 2014-04-14 11:17 - 02157568 _____ (Farbar) C:\Users\dude\Desktop\FRST64.exe 2014-04-14 11:07 - 2014-04-14 11:07 - 00050477 _____ () C:\Users\dude\Desktop\Defogger.exe 2014-04-14 09:54 - 2010-11-21 08:50 - 00696832 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 09:54 - 2010-11-21 08:50 - 00148128 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 09:54 - 2009-07-14 07:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-14 09:54 - 2009-07-14 06:45 - 00021856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-14 09:54 - 2009-07-14 06:45 - 00021856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-14 09:47 - 2013-12-18 10:47 - 00012756 _____ () C:\Windows\setupact.log 2014-04-14 09:47 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-11 11:01 - 2014-04-11 10:59 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner (2) 2014-04-10 20:56 - 2013-12-13 19:04 - 00000000 ____D () C:\Users\dude\AppData\Roaming\foobar2000 2014-04-10 20:43 - 2014-04-10 20:40 - 00000420 _____ () C:\Users\dude\Desktop\sidechat08.txt 2014-04-10 18:40 - 2014-04-10 18:40 - 00000000 ____D () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split 2014-04-10 17:43 - 2014-04-10 17:41 - 15111863 _____ () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split.zip 2014-04-10 01:29 - 2013-12-15 20:22 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 01:28 - 2013-12-15 20:22 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 22:55 - 2014-01-09 23:43 - 00000000 ____D () C:\Users\dude\AppData\Roaming\TS3Client 2014-04-09 20:37 - 2014-04-09 20:37 - 00001393 _____ () C:\Users\dude\Desktop\devcpp.exe - Verknüpfung.lnk 2014-04-09 19:54 - 2014-04-08 14:13 - 00001081 _____ () C:\Users\Public\Desktop\scilab-5.4.1 (64-bit).lnk 2014-04-08 14:34 - 2014-04-08 14:33 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 14:32 - 2014-04-08 14:32 - 00000000 ____D () C:\Program Files (x86)\Dev-Cpp 2014-04-08 14:14 - 2014-04-08 14:14 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Scilab 2014-04-08 14:14 - 2014-04-08 14:12 - 00000000 ____D () C:\Program Files\scilab-5.4.1 2014-04-08 14:12 - 2014-04-08 14:12 - 28135014 _____ () C:\Users\dude\Desktop\scilab-help-chm-5.4.1.zip 2014-04-08 14:12 - 2014-04-08 14:12 - 20593796 _____ () C:\Users\dude\Desktop\blas-lapack-mkl-5.4.1-win64.zip 2014-04-08 14:11 - 2014-04-08 14:11 - 13866852 _____ () C:\Users\dude\Desktop\commons-mkl-5.4.1-win64.zip 2014-04-08 13:48 - 2014-04-08 13:48 - 00036864 _____ (Juliett_Six) C:\Users\dude\Desktop\WT_Logger_v0.13_64bit.exe 2014-04-08 01:36 - 2013-12-13 19:38 - 00000000 ____D () C:\Users\dude\AppData\Roaming\vlc 2014-04-03 12:39 - 2014-04-03 12:39 - 00004540 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-03 12:39 - 2014-04-03 12:39 - 00000000 ___HD () C:\VTRoot 2014-04-03 12:37 - 2013-12-13 18:03 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO 2014-04-01 13:15 - 2014-04-01 13:15 - 00001134 _____ () C:\Users\dude\Desktop\history - Verknüpfung.lnk 2014-04-01 13:12 - 2014-04-01 13:12 - 00000722 _____ () C:\Users\dude\Desktop\Kram - Verknüpfung.lnk 2014-04-01 11:46 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Users\dude\Desktop\shega 2014-03-31 13:40 - 2014-03-31 13:40 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner 2014-03-31 03:16 - 2014-04-09 11:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 11:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 11:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 11:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-28 17:30 - 2014-03-28 17:30 - 00003138 _____ () C:\Windows\System32\Tasks\{AA396EED-30E7-4B22-840F-0BD819D675B2} 2014-03-28 12:17 - 2014-03-28 12:17 - 00000000 ____D () C:\Windows\Sun 2014-03-26 10:17 - 2013-12-13 18:04 - 00063568 _____ () C:\Users\dude\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-26 10:16 - 2009-07-14 06:45 - 00293320 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-25 21:22 - 2013-09-24 12:54 - 00738472 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00105552 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00048360 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00023168 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys 2014-03-25 21:22 - 2013-09-24 12:53 - 00453680 _____ (COMODO) C:\Windows\system32\guard64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00363504 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00352984 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00284888 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00045784 _____ (COMODO) C:\Windows\system32\cmdkbd64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00043216 _____ (COMODO) C:\Windows\system32\cmdcsr.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00040664 _____ (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Users\dude\AppData\Roaming\OpenOffice 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-25 11:23 - 2014-03-25 11:23 - 00036041 _____ () C:\Users\dude\Desktop\TLAL Vault (2).zip 2014-03-20 09:27 - 2013-12-13 17:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 21:44 - 2013-12-14 10:59 - 00000000 ____D () C:\Program Files (x86)\WarThunder 2014-03-19 12:35 - 2014-03-18 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-18 19:04 - 2014-03-18 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-15 21:15 - 2014-01-13 22:09 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-03-15 18:14 - 2014-03-15 18:14 - 00000000 ____D () C:\Users\dude\Desktop\WT Logging Utility Documentation 2014-03-15 11:53 - 2014-03-15 11:53 - 00000000 ____D () C:\Windows\pss Some content of TEMP: ==================== C:\Users\dude\AppData\Local\Temp\Foxit Reader Updater.exe C:\Users\dude\AppData\Local\Temp\kdewin-installer410-gui-1.0.0.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-10 13:00 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2014 01 Ran by dude at 2014-04-14 12:24:08 Running from C:\Users\dude\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: COMODO Antivirus (Enabled - Up to date) {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: COMODO Antivirus (Enabled - Up to date) {0C2D2636-923D-EE52-2A83-E643204A8275} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.170 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 12.5.100.30429 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.937.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80430.0002 - Advanced Micro Devices, Inc.) Hidden Application Verifier (x64) (HKLM\...\{89026002-A893-42D9-9E20-6829B844735E}) (Version: 4.1.1078 - Microsoft Corporation) Bulk Rename Utility 2.7.1.2 (HKLM\...\Bulk Rename Utility_is1) (Version: - TGRMN Software) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2013.0429.2313.39747 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) CloudReading (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.0.27.1025 - Foxit Corporation) COMODO Antivirus (HKLM\...\{093F13A3-177C-493E-8958-912A0C690B64}) (Version: 6.3.32439.2937 - COMODO Security Solutions Inc.) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Debugging Tools for Windows (x64) (HKLM\...\{DBFC6AAE-DCCB-4C23-B01C-3EDDDC03298B}) (Version: 6.12.2.633 - Microsoft Corporation) Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.6.2 - Bloodshed Software) foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.1.1.1025 - Foxit Corporation) GeekBuddy (HKLM\...\{C36B3AE4-FCFE-4A0A-AA3D-71E1A51C1F16}) (Version: 4.11.91 - Comodo Security Solutions Inc) GPL Ghostscript (HKLM\...\GPL Ghostscript 9.10) (Version: 9.10 - Artifex Software Inc.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) JabRef 2.9.2 (HKLM-x32\...\JabRef 2.9.2) (Version: 2.9.2 - JabRef Team) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) MATLAB R2012a (HKLM\...\Matlab R2012a) (Version: 7.14 - The MathWorks, Inc.) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ Compilers 2010 Standard - enu - x64 (HKLM\...\{88387B3B-B110-392F-B919-1A15B48F21D4}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (HKLM-x32\...\{370187B9-6964-38D0-851F-6C4898B0C2B1}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Windows Performance Toolkit (HKLM\...\{E7F9E526-2324-437B-A609-E8C5309465CB}) (Version: 4.8.0 - Microsoft Corporation) Microsoft Windows SDK .NET Framework Tools (30514) (Version: 7.1.30514 - Microsoft) Hidden Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation) Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Common Utilities (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Headers and Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Samples (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK Intellisense and Reference Assemblies (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK MSHelp (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.2 - pdfforge) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) scilab-5.4.1 (64-bit) (HKLM\...\scilab-5.4.1 (64-bit)_is1) (Version: - Scilab Enterprises) Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 2.4 - Krzysztof Kowalczyk) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeXnicCenter Version 2.02 Stable (HKLM\...\TeXnicCenter_is1) (Version: 2.02 Stable - The TeXnicCenter Team) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) War Thunder Launcher 1.0.1.278 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2013 Gaijin Entertainment Corporation) Windows SDK IntellisenseNFX (x32 Version: 7.1.30514 - Microsoft) Hidden WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 25-03-2014 09:26:43 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 25-03-2014 09:27:41 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 25-03-2014 09:29:07 OpenOffice 4.0.1 wird installiert 01-04-2014 11:44:13 Geplanter Prüfpunkt 08-04-2014 17:36:02 Geplanter Prüfpunkt 09-04-2014 23:27:45 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {050A8A26-764C-44BB-955A-3B5D5041521A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {0CABA9A1-EA00-48BE-B070-CC98757A0437} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {28F1E40B-80B3-49C8-9CF5-8F5060090E0A} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {9ECCA2FC-5915-4A8A-8A48-CC2BFF58CB29} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {ADE6ED26-0659-4FFA-B8AF-8810322AF89B} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {D108170C-A7DC-45E9-967E-9C73141F5182} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-13] (Piriform Ltd) Task: {FA4531EB-9A61-4AB1-AF51-9BB3001F07C2} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {FDF2F0BE-CBED-4483-ADB6-69B98F25962B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-18 16:49 - 2013-06-18 16:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-04-30 00:08 - 2013-04-30 00:08 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-04-15 19:39 - 2013-04-15 19:39 - 00073424 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav 2014-03-09 13:42 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2014-03-09 13:42 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2014-03-09 13:42 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2014-03-09 13:42 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2014-03-09 13:42 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: GeekBuddyRSP => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk => C:\Windows\pss\Start GeekBuddy.lnk.CommonStartup MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: SpywareTerminatorShield => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe MSCONFIG\startupreg: SpywareTerminatorUpdater => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/14/2014 09:47:08 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2014 11:53:48 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/11/2014 10:28:55 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/10/2014 09:32:29 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/09/2014 10:57:19 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 01:05:37 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 08:47:59 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/07/2014 02:33:22 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_9_900_170.exe, Version: 11.9.900.170, Zeitstempel: 0x529b79bf Name des fehlerhaften Moduls: NPSWF32_11_9_900_170.dll, Version: 11.9.900.170, Zeitstempel: 0x529b7bf8 Ausnahmecode: 0xc0000005 Fehleroffset: 0x007b781c ID des fehlerhaften Prozesses: 0x13bc Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_9_900_170.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_9_900_170.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_9_900_170.exe2 Berichtskennung: FlashPlayerPlugin_11_9_900_170.exe3 Error: (04/07/2014 10:16:39 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/06/2014 04:48:50 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (03/09/2014 04:10:33 PM) (Source: Microsoft-Windows-HAL) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Error: (03/07/2014 06:56:45 PM) (Source: BugCheck) (User: ) Description: 0x00000119 (0x0000000000000001, 0x000000000001db0f, 0x000000000001db11, 0x000000000001db10)C:\Windows\MEMORY.DMP030714-17784-01 Error: (03/07/2014 06:56:40 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 07.03.2014 um 17:55:47 unerwartet heruntergefahren. Error: (03/06/2014 06:23:02 PM) (Source: Microsoft-Windows-HAL) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Error: (02/28/2014 02:41:07 PM) (Source: Microsoft-Windows-HAL) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Error: (02/21/2014 00:50:34 AM) (Source: Microsoft-Windows-HAL) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Error: (01/28/2014 10:57:53 PM) (Source: Microsoft-Windows-HAL) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Error: (12/17/2013 03:49:02 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk5\DR6. Error: (12/17/2013 03:48:58 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk5\DR6. Error: (12/17/2013 03:48:54 PM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk5\DR6. Microsoft Office Sessions: ========================= Error: (04/14/2014 09:47:08 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2014 11:53:48 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/11/2014 10:28:55 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/10/2014 09:32:29 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/09/2014 10:57:19 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 01:05:37 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/08/2014 08:47:59 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/07/2014 02:33:22 PM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_9_900_170.exe11.9.900.170529b79bfNPSWF32_11_9_900_170.dll11.9.900.170529b7bf8c0000005007b781c13bc01cf523d218ce16eC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exeC:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dllcdc2df27-be50-11e3-adbc-00221934f749 Error: (04/07/2014 10:16:39 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/06/2014 04:48:50 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 22% Total physical RAM: 6077.93 MB Available physical RAM: 4735 MB Total Pagefile: 12154.03 MB Available Pagefile: 10411.81 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.21 GB) (Free:128.68 GB) NTFS Drive d: () (Fixed) (Total:1367.19 GB) (Free:1036.82 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 4FDFE16F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=195 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=-731016855552) - (Type=07 NTFS) ==================== End Of Log ============================ GMER.txt Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-14 12:43:44 Windows 6.1.7601 Service Pack 1 x64 Running: Gmer-19357.exe ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\cmdAgent\Mode\Configurations@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\cmdAgent\Mode\Data@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\cmdAgent\Mode\Options@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\cmdAgent\Mode\Configurations@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\cmdAgent\Mode\Data@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\cmdAgent\Mode\Options@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Cam@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... ---- EOF - GMER 2.1 ---- |
14.04.2014, 13:21 | #2 |
/// the machine /// TB-Ausbilder | Wiederholte Sicherheitssperre des Postfachs hi,
__________________Scan mit Combofix
__________________ |
14.04.2014, 14:05 | #3 |
| Wiederholte Sicherheitssperre des Postfachs bekomme beim Ausführen mehrere Fehlermeldungen zb
__________________unable to create C:windows\erdnt\Hiv-backup\ERDNT.INF und später error saving files Hiv-backup\BCD Hiv-backup\SYSTEM ist das normal? habs dann abgebrochen. nun aber kann die erstellte .cmd file nicht geöffnet werden. hab alles geforderte ausgeschalten und als Administrator ausgeführt. nochmal durchführen? vielen dank für deine hilfe |
15.04.2014, 10:57 | #4 |
/// the machine /// TB-Ausbilder | Wiederholte Sicherheitssperre des Postfachs Combofix löschen, neu laden. AV Programm abschalten und als Admin starten.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.04.2014, 14:28 | #5 |
| Wiederholte Sicherheitssperre des Postfachs So, neu geladen, Antivirenprogramme beendet, als Admin ausgeführt. Combofix hat dann aber doch gemeckert, dass Comodo und SS&D noch laufen würden. Prozesse und Dienste beendet, combofix meinte dann comodo laufe immer noch, allerdings konnte ich in dem moment combofix nicht mehr abbrechen, also liefs durch. combofix log: Code:
ATTFilter Combofix Logfile: ---------------------------------------------- also, ich hab das ganze nochmal gemacht, diesmal AV ausm autostart raus. im combofix-logfile steht nun auch disabled. combofix hat aber trotzdem gemeckert comodo und spybot würden laufen. Combofix Logfile: Code:
ATTFilter ComboFix 14-04-12.01 - dude 16.04.2014 15:11:12.2.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.6078.4842 [GMT 2:00] ausgeführt von:: c:\users\dude\Desktop\ComboFix.exe AV: COMODO Antivirus *Disabled/Updated* {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} SP: COMODO Antivirus *Disabled/Updated* {0C2D2636-923D-EE52-2A83-E643204A8275} SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-16 bis 2014-04-16 )))))))))))))))))))))))))))))) . . 2014-04-16 13:18 . 2014-04-16 13:18 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-16 08:37 . 2014-04-16 08:37 -------- d-----w- c:\users\dude\AppData\Local\gtk-2.0 2014-04-16 08:37 . 2014-04-16 08:37 -------- d-----w- c:\users\dude\.thumbnails 2014-04-16 08:31 . 2014-04-16 08:31 -------- d-----w- c:\users\dude\AppData\Local\fontconfig 2014-04-16 08:31 . 2014-04-16 08:38 -------- d-----w- c:\users\dude\.gimp-2.8 2014-04-16 08:31 . 2014-04-16 08:31 -------- d-----w- c:\users\dude\AppData\Local\gegl-0.2 2014-04-16 08:22 . 2014-04-16 08:23 -------- d-----w- c:\program files\GIMP 2 2014-04-14 10:17 . 2014-04-14 10:25 -------- d-----w- C:\FRST 2014-04-09 09:06 . 2014-03-31 01:16 23134208 ----a-w- c:\windows\system32\mshtml.dll 2014-04-09 09:06 . 2014-03-31 01:13 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-04-09 09:06 . 2014-03-31 00:13 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-04-09 09:03 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-04-09 09:03 . 2014-03-04 09:44 243712 ----a-w- c:\windows\system32\wow64.dll 2014-04-09 09:03 . 2014-03-04 09:44 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2014-04-09 09:03 . 2014-03-04 09:44 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2014-04-09 09:03 . 2014-03-04 09:44 1163264 ----a-w- c:\windows\system32\kernel32.dll 2014-04-09 09:03 . 2014-03-04 09:17 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2014-04-09 09:03 . 2014-03-04 09:16 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2014-04-09 09:03 . 2014-03-04 09:16 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2014-04-09 09:03 . 2014-03-04 08:09 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2014-04-09 09:03 . 2014-03-04 08:09 2048 ----a-w- c:\windows\SysWow64\user.exe 2014-04-08 12:33 . 2014-04-08 12:34 -------- d-----w- c:\users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 12:32 . 2014-04-08 12:32 -------- d-----w- c:\program files (x86)\Dev-Cpp 2014-04-08 12:14 . 2014-04-08 12:14 -------- d-----w- c:\users\dude\AppData\Roaming\Scilab 2014-04-08 12:12 . 2014-04-08 12:14 -------- d-----w- c:\program files\scilab-5.4.1 2014-04-03 10:39 . 2014-04-03 10:39 -------- d-----w- C:\VTRoot 2014-03-28 10:17 . 2014-03-28 10:17 -------- d-----w- c:\windows\Sun 2014-03-25 09:29 . 2014-03-25 09:29 -------- d-----w- c:\users\dude\AppData\Roaming\OpenOffice 2014-03-25 09:29 . 2014-03-25 09:29 -------- d-----w- c:\program files (x86)\OpenOffice 4 2014-03-18 17:00 . 2014-03-19 10:35 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-09 23:28 . 2013-12-15 18:22 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-25 19:22 . 2013-09-24 10:54 105552 ----a-w- c:\windows\system32\drivers\inspect.sys 2014-03-25 19:22 . 2013-09-24 10:54 48360 ----a-w- c:\windows\system32\drivers\cmdhlp.sys 2014-03-25 19:22 . 2013-09-24 10:54 738472 ----a-w- c:\windows\system32\drivers\cmdguard.sys 2014-03-25 19:22 . 2013-09-24 10:54 23168 ----a-w- c:\windows\system32\drivers\cmderd.sys 2014-03-25 19:22 . 2013-09-24 10:53 43216 ----a-w- c:\windows\system32\cmdcsr.dll 2014-03-25 19:22 . 2013-09-24 10:53 363504 ----a-w- c:\windows\SysWow64\guard32.dll 2014-03-25 19:22 . 2013-09-24 10:53 453680 ----a-w- c:\windows\system32\guard64.dll 2014-03-25 19:22 . 2013-09-24 10:53 352984 ----a-w- c:\windows\system32\cmdvrt64.dll 2014-03-25 19:22 . 2013-09-24 10:53 45784 ----a-w- c:\windows\system32\cmdkbd64.dll 2014-03-25 19:22 . 2013-09-24 10:53 284888 ----a-w- c:\windows\SysWow64\cmdvrt32.dll 2014-03-25 19:22 . 2013-09-24 10:53 40664 ----a-w- c:\windows\SysWow64\cmdkbd32.dll 2014-03-08 16:07 . 2014-03-08 16:07 51496 ----a-w- c:\windows\system32\drivers\stflt.sys 2014-03-04 09:17 . 2014-04-09 09:03 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-01 05:16 . 2014-03-12 08:59 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-01 04:58 . 2014-03-12 08:59 2765824 ----a-w- c:\windows\system32\iertutil.dll 2014-03-01 04:52 . 2014-03-12 08:59 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-01 04:51 . 2014-03-12 08:59 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-01 04:42 . 2014-03-12 08:59 53760 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-01 04:40 . 2014-03-12 08:59 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-01 04:37 . 2014-03-12 08:59 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-01 04:33 . 2014-03-12 08:59 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-01 04:33 . 2014-03-12 08:59 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-01 04:32 . 2014-03-12 08:59 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-01 04:23 . 2014-03-12 08:59 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:17 . 2014-03-12 08:59 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-01 04:02 . 2014-03-12 08:59 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-01 03:54 . 2014-03-12 08:59 5768704 ----a-w- c:\windows\system32\jscript9.dll 2014-03-01 03:52 . 2014-03-12 08:59 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-01 03:51 . 2014-03-12 08:59 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-01 03:42 . 2014-03-12 08:59 627200 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-01 03:38 . 2014-03-12 08:59 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-01 03:37 . 2014-03-12 08:59 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-01 03:35 . 2014-03-12 08:59 2041856 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-01 03:18 . 2014-03-12 08:59 13051904 ----a-w- c:\windows\system32\ieframe.dll 2014-03-01 03:14 . 2014-03-12 08:59 4244480 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-01 03:10 . 2014-03-12 08:59 2334208 ----a-w- c:\windows\system32\wininet.dll 2014-03-01 03:00 . 2014-03-12 08:59 1964032 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-01 02:38 . 2014-03-12 08:59 1393664 ----a-w- c:\windows\system32\urlmon.dll 2014-03-01 02:32 . 2014-03-12 08:59 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-01 02:25 . 2014-03-12 08:59 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2014-02-07 01:23 . 2014-03-12 08:59 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-12 08:59 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-12 08:59 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 02:32 . 2014-03-12 08:59 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-12 08:59 381440 ----a-w- c:\windows\SysWow64\wer.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-04-29 642304] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 CLPSLauncher;COMODO LPS Launcher;c:\program files (x86)\Common Files\COMODO\launcher_service.exe;c:\program files (x86)\Common Files\COMODO\launcher_service.exe [x] R4 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [x] R4 GeekBuddyRSP;GeekBuddyRSP Server;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe;c:\program files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [x] R4 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] R4 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] R4 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S1 CFRMD;CFRMD;c:\windows\system32\DRIVERS\CFRMD.sys;c:\windows\SYSNATIVE\DRIVERS\CFRMD.sys [x] S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys;c:\windows\SYSNATIVE\DRIVERS\cmderd.sys [x] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys;c:\windows\SYSNATIVE\DRIVERS\cmdguard.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 HMD;COMODO livePCsupport Hardware Monitor Driver;c:\windows\system32\DRIVERS\hmd.sys;c:\windows\SYSNATIVE\DRIVERS\hmd.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] . . . --------- X64 Entries ----------- . . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Notify-SDWinLogon - SDWinLogon.dll . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\COMODO\CIS\Installer\Sym_Cam\CIS] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cmdAgent\Mode\Configurations] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cmdAgent\Mode\Data] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\cmdAgent\Mode\Options] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\Software\COMODO\Cam] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\Software\COMODO\Firewall Pro] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\ . Zeit der Fertigstellung: 2014-04-16 15:21:52 ComboFix-quarantined-files.txt 2014-04-16 13:21 ComboFix2.txt 2014-04-15 18:11 . Vor Suchlauf: 12 Verzeichnis(se), 145.452.064.768 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 145.017.593.856 Bytes frei . - - End Of File - - 870F8850FEE48098701C62DF642B2FA8 A36C5E4F47E84449FF07ED3517B43A31 grüsse |
17.04.2014, 10:09 | #6 |
/// the machine /// TB-Ausbilder | Wiederholte Sicherheitssperre des Postfachs Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Wiederholte Sicherheitssperre des Postfachs |
17.04.2014, 11:24 | #7 |
| Wiederholte Sicherheitssperre des Postfachs hi, alles ausgeführt, hier die log-files mbam.txt Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 17.04.2014 Suchlauf-Zeit: 11:32:13 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.17.02 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: dude Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 251352 Verstrichene Zeit: 9 Min, 19 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 17/04/2014 um 11:36:08 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : dude - TBD # Gestartet von : C:\Users\dude\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\dude\AppData\Roaming\pdfforge ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\prefs.js ] ************************* AdwCleaner[R0].txt - [937 octets] - [17/04/2014 11:34:40] AdwCleaner[S0].txt - [815 octets] - [17/04/2014 11:36:08] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [874 octets] ########## JRT.txt: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by dude on 17.04.2014 at 11:41:27,17 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\dude\AppData\Roaming\mozilla\firefox\profiles\r6rtoebk.default\minidumps [9 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 17.04.2014 at 12:07:25,69 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 Ran by dude (administrator) on TBD on 17-04-2014 12:12:00 Running from C:\Users\dude\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC18A4A6919F8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF SearchPlugin: C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\searchplugins\duckduckgo.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: HTTPS-Everywhere - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\https-everywhere@eff.org [2014-04-15] FF Extension: Certificate Patrol - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\CertPatrol@PSYC.EU.xpi [2014-01-30] FF Extension: Ghostery - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\firefox@ghostery.com.xpi [2014-01-29] FF Extension: Adblock Plus - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-13] FF Extension: BetterPrivacy - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-12-16] ==================== Services (Whitelisted) ================= S4 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) S4 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6812400 2014-03-25] (COMODO) S4 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2264280 2014-03-25] (COMODO) S4 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2013-05-07] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2014-03-25] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [738472 2014-03-25] (COMODO) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-16] (Disc Soft Ltd) R1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-17 12:09 - 2014-04-17 12:12 - 00006361 _____ () C:\Users\dude\Desktop\FRST.txt 2014-04-17 12:09 - 2014-04-17 12:09 - 00000000 ____D () C:\Users\dude\Desktop\FRST-OlderVersion 2014-04-17 12:08 - 2014-04-17 12:08 - 00000754 _____ () C:\Users\dude\Desktop\JRT2.txt 2014-04-17 12:08 - 2014-04-17 12:08 - 00000000 ____D () C:\Users\dude\Desktop\firstscn 2014-04-17 12:07 - 2014-04-17 12:07 - 00000754 _____ () C:\Users\dude\Desktop\JRT.txt 2014-04-17 11:41 - 2014-04-17 11:41 - 00000000 ____D () C:\Windows\ERUNT 2014-04-17 11:38 - 2014-04-17 11:38 - 00000953 _____ () C:\Users\dude\Desktop\AdwCleaner[S0].txt 2014-04-17 11:34 - 2014-04-17 11:36 - 00000000 ____D () C:\AdwCleaner 2014-04-17 11:33 - 2014-04-17 11:33 - 00001144 _____ () C:\Users\dude\Desktop\mbam.txt 2014-04-17 11:19 - 2014-04-17 11:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-17 11:18 - 2014-04-17 11:18 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-17 11:18 - 2014-04-17 11:18 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-17 11:18 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-17 11:18 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-17 11:14 - 2014-04-17 11:14 - 01016261 _____ (Thisisu) C:\Users\dude\Desktop\JRT.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\dude\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 01426178 _____ () C:\Users\dude\Desktop\adwcleaner.exe 2014-04-17 10:32 - 2014-04-17 10:32 - 00001314 _____ () C:\Users\Public\Desktop\WTAssetViewer.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001304 _____ () C:\Users\Public\Desktop\WTMissionEditor.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001292 _____ () C:\Users\Public\Desktop\LocationEd.lnk 2014-04-16 15:21 - 2014-04-16 15:21 - 00013341 _____ () C:\ComboFix.txt 2014-04-16 10:37 - 2014-04-16 10:37 - 00000866 _____ () C:\Users\dude\AppData\Local\recently-used.xbel 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\Desktop\template_bf-109g-2 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\AppData\Local\gtk-2.0 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\.thumbnails 2014-04-16 10:31 - 2014-04-16 10:38 - 00000000 ____D () C:\Users\dude\.gimp-2.8 2014-04-16 10:31 - 2014-04-16 10:31 - 00000000 ____D () C:\Users\dude\AppData\Local\gegl-0.2 2014-04-16 10:22 - 2014-04-16 10:23 - 00000000 ____D () C:\Program Files\GIMP 2 2014-04-16 09:57 - 2014-04-16 10:48 - 466674314 _____ () C:\Users\dude\Desktop\game.of.thrones.s04e02.hdtv.xvid-fum.avi 2014-04-16 09:55 - 2014-04-16 10:20 - 90396104 _____ (The GIMP Team ) C:\Users\dude\Desktop\gimp-2.8.10-setup.exe 2014-04-15 19:58 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-15 19:58 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-15 19:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-15 19:40 - 2014-04-15 19:43 - 05194807 ____R (Swearware) C:\Users\dude\Desktop\ComboFix.exe 2014-04-14 14:39 - 2014-04-16 15:21 - 00000000 ____D () C:\Qoobox 2014-04-14 14:31 - 2014-04-15 20:08 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 12:44 - 2014-04-14 12:43 - 00001136 _____ () C:\Users\dude\Desktop\Gmer.txt 2014-04-14 12:43 - 2014-04-14 12:43 - 00001136 _____ () C:\Users\dude\Documents\Gmer.txt 2014-04-14 12:17 - 2014-04-17 12:12 - 00000000 ____D () C:\FRST 2014-04-14 12:16 - 2014-04-14 12:16 - 00000000 _____ () C:\Users\dude\defogger_reenable 2014-04-14 11:18 - 2014-04-14 11:18 - 00380416 _____ () C:\Users\dude\Desktop\Gmer-19357.exe 2014-04-14 11:17 - 2014-04-17 12:09 - 02158592 _____ (Farbar) C:\Users\dude\Desktop\FRST64.exe 2014-04-14 11:07 - 2014-04-14 11:07 - 00050477 _____ () C:\Users\dude\Desktop\Defogger.exe 2014-04-11 10:59 - 2014-04-11 11:01 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner (2) 2014-04-10 20:40 - 2014-04-10 20:43 - 00000420 _____ () C:\Users\dude\Desktop\sidechat08.txt 2014-04-10 18:40 - 2014-04-10 18:40 - 00000000 ____D () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split 2014-04-10 17:41 - 2014-04-10 17:43 - 15111863 _____ () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split.zip 2014-04-09 20:37 - 2014-04-09 20:37 - 00001393 _____ () C:\Users\dude\Desktop\devcpp.exe - Verknüpfung.lnk 2014-04-09 11:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 11:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 11:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 11:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 11:03 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 11:03 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 11:03 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 11:03 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 11:03 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 11:03 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-08 14:33 - 2014-04-08 14:34 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 14:32 - 2014-04-08 14:32 - 00000000 ____D () C:\Program Files (x86)\Dev-Cpp 2014-04-08 14:14 - 2014-04-08 14:14 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Scilab 2014-04-08 14:13 - 2014-04-09 19:54 - 00001081 _____ () C:\Users\Public\Desktop\scilab-5.4.1 (64-bit).lnk 2014-04-08 14:12 - 2014-04-08 14:14 - 00000000 ____D () C:\Program Files\scilab-5.4.1 2014-04-08 14:12 - 2014-04-08 14:12 - 28135014 _____ () C:\Users\dude\Desktop\scilab-help-chm-5.4.1.zip 2014-04-08 14:12 - 2014-04-08 14:12 - 20593796 _____ () C:\Users\dude\Desktop\blas-lapack-mkl-5.4.1-win64.zip 2014-04-08 14:11 - 2014-04-08 14:11 - 13866852 _____ () C:\Users\dude\Desktop\commons-mkl-5.4.1-win64.zip 2014-04-08 13:48 - 2014-04-08 13:48 - 00036864 _____ (Juliett_Six) C:\Users\dude\Desktop\WT_Logger_v0.13_64bit.exe 2014-04-04 11:44 - 2010-01-18 15:49 - 00000000 ____D () C:\Users\dude\Desktop\Mouse On The Keys - An Anxious Object (2009) 2014-04-03 12:39 - 2014-04-03 12:39 - 00004540 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-03 12:39 - 2014-04-03 12:39 - 00000000 ____D () C:\VTRoot 2014-04-01 13:15 - 2014-04-01 13:15 - 00001134 _____ () C:\Users\dude\Desktop\history - Verknüpfung.lnk 2014-04-01 13:12 - 2014-04-01 13:12 - 00000722 _____ () C:\Users\dude\Desktop\Kram - Verknüpfung.lnk 2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Users\dude\Desktop\shega 2014-03-31 13:40 - 2014-03-31 13:40 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner 2014-03-28 17:30 - 2014-03-28 17:30 - 00003138 _____ () C:\Windows\System32\Tasks\{AA396EED-30E7-4B22-840F-0BD819D675B2} 2014-03-28 12:17 - 2014-03-28 12:17 - 00000000 ____D () C:\Windows\Sun 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Users\dude\AppData\Roaming\OpenOffice 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-25 11:23 - 2014-03-25 11:23 - 00036041 _____ () C:\Users\dude\Desktop\TLAL Vault (2).zip 2014-03-18 19:04 - 2014-03-18 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-18 19:00 - 2014-03-19 12:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-17 12:12 - 2014-04-17 12:09 - 00006361 _____ () C:\Users\dude\Desktop\FRST.txt 2014-04-17 12:12 - 2014-04-14 12:17 - 00000000 ____D () C:\FRST 2014-04-17 12:10 - 2013-12-13 18:03 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-04-17 12:09 - 2014-04-17 12:09 - 00000000 ____D () C:\Users\dude\Desktop\FRST-OlderVersion 2014-04-17 12:09 - 2014-04-14 11:17 - 02158592 _____ (Farbar) C:\Users\dude\Desktop\FRST64.exe 2014-04-17 12:08 - 2014-04-17 12:08 - 00000754 _____ () C:\Users\dude\Desktop\JRT2.txt 2014-04-17 12:08 - 2014-04-17 12:08 - 00000000 ____D () C:\Users\dude\Desktop\firstscn 2014-04-17 12:07 - 2014-04-17 12:07 - 00000754 _____ () C:\Users\dude\Desktop\JRT.txt 2014-04-17 11:47 - 2010-11-21 08:50 - 00696832 _____ () C:\Windows\system32\perfh007.dat 2014-04-17 11:47 - 2010-11-21 08:50 - 00148128 _____ () C:\Windows\system32\perfc007.dat 2014-04-17 11:47 - 2009-07-14 07:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-17 11:47 - 2009-07-14 06:45 - 00021856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-17 11:47 - 2009-07-14 06:45 - 00021856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-17 11:43 - 2013-12-13 17:33 - 01522949 _____ () C:\Windows\WindowsUpdate.log 2014-04-17 11:41 - 2014-04-17 11:41 - 00000000 ____D () C:\Windows\ERUNT 2014-04-17 11:40 - 2013-12-18 10:47 - 00013484 _____ () C:\Windows\setupact.log 2014-04-17 11:40 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-17 11:38 - 2014-04-17 11:38 - 00000953 _____ () C:\Users\dude\Desktop\AdwCleaner[S0].txt 2014-04-17 11:36 - 2014-04-17 11:34 - 00000000 ____D () C:\AdwCleaner 2014-04-17 11:33 - 2014-04-17 11:33 - 00001144 _____ () C:\Users\dude\Desktop\mbam.txt 2014-04-17 11:22 - 2014-04-17 11:19 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-17 11:18 - 2014-04-17 11:18 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-17 11:18 - 2014-04-17 11:18 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-17 11:18 - 2014-03-09 14:06 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Malwarebytes 2014-04-17 11:18 - 2014-03-09 14:06 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-17 11:16 - 2013-12-13 20:20 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Macromedia 2014-04-17 11:14 - 2014-04-17 11:14 - 01016261 _____ (Thisisu) C:\Users\dude\Desktop\JRT.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\dude\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 01426178 _____ () C:\Users\dude\Desktop\adwcleaner.exe 2014-04-17 10:32 - 2014-04-17 10:32 - 00001314 _____ () C:\Users\Public\Desktop\WTAssetViewer.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001304 _____ () C:\Users\Public\Desktop\WTMissionEditor.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001292 _____ () C:\Users\Public\Desktop\LocationEd.lnk 2014-04-17 10:32 - 2013-12-14 10:59 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder 2014-04-17 10:31 - 2013-12-14 10:59 - 00000000 ____D () C:\Program Files (x86)\WarThunder 2014-04-16 23:38 - 2013-12-13 19:38 - 00000000 ____D () C:\Users\dude\AppData\Roaming\vlc 2014-04-16 23:24 - 2014-01-09 23:43 - 00000000 ____D () C:\Users\dude\AppData\Roaming\TS3Client 2014-04-16 15:40 - 2014-01-14 10:14 - 00001984 _____ () C:\Windows\PFRO.log 2014-04-16 15:21 - 2014-04-16 15:21 - 00013341 _____ () C:\ComboFix.txt 2014-04-16 15:21 - 2014-04-14 14:39 - 00000000 ____D () C:\Qoobox 2014-04-16 15:18 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-16 15:05 - 2013-12-13 19:04 - 00000000 ____D () C:\Users\dude\AppData\Roaming\foobar2000 2014-04-16 10:48 - 2014-04-16 09:57 - 466674314 _____ () C:\Users\dude\Desktop\game.of.thrones.s04e02.hdtv.xvid-fum.avi 2014-04-16 10:38 - 2014-04-16 10:31 - 00000000 ____D () C:\Users\dude\.gimp-2.8 2014-04-16 10:37 - 2014-04-16 10:37 - 00000866 _____ () C:\Users\dude\AppData\Local\recently-used.xbel 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\Desktop\template_bf-109g-2 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\AppData\Local\gtk-2.0 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\.thumbnails 2014-04-16 10:37 - 2013-12-13 17:34 - 00000000 ____D () C:\Users\dude 2014-04-16 10:31 - 2014-04-16 10:31 - 00000000 ____D () C:\Users\dude\AppData\Local\gegl-0.2 2014-04-16 10:23 - 2014-04-16 10:22 - 00000000 ____D () C:\Program Files\GIMP 2 2014-04-16 10:20 - 2014-04-16 09:55 - 90396104 _____ (The GIMP Team ) C:\Users\dude\Desktop\gimp-2.8.10-setup.exe 2014-04-16 00:31 - 2014-03-09 13:42 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-04-15 20:11 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-15 20:08 - 2014-04-14 14:31 - 00000000 ____D () C:\Windows\erdnt 2014-04-15 19:43 - 2014-04-15 19:40 - 05194807 ____R (Swearware) C:\Users\dude\Desktop\ComboFix.exe 2014-04-14 12:43 - 2014-04-14 12:44 - 00001136 _____ () C:\Users\dude\Desktop\Gmer.txt 2014-04-14 12:43 - 2014-04-14 12:43 - 00001136 _____ () C:\Users\dude\Documents\Gmer.txt 2014-04-14 12:16 - 2014-04-14 12:16 - 00000000 _____ () C:\Users\dude\defogger_reenable 2014-04-14 11:18 - 2014-04-14 11:18 - 00380416 _____ () C:\Users\dude\Desktop\Gmer-19357.exe 2014-04-14 11:07 - 2014-04-14 11:07 - 00050477 _____ () C:\Users\dude\Desktop\Defogger.exe 2014-04-11 11:01 - 2014-04-11 10:59 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner (2) 2014-04-10 20:43 - 2014-04-10 20:40 - 00000420 _____ () C:\Users\dude\Desktop\sidechat08.txt 2014-04-10 18:40 - 2014-04-10 18:40 - 00000000 ____D () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split 2014-04-10 17:43 - 2014-04-10 17:41 - 15111863 _____ () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split.zip 2014-04-10 01:29 - 2013-12-15 20:22 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 01:28 - 2013-12-15 20:22 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 20:37 - 2014-04-09 20:37 - 00001393 _____ () C:\Users\dude\Desktop\devcpp.exe - Verknüpfung.lnk 2014-04-09 19:54 - 2014-04-08 14:13 - 00001081 _____ () C:\Users\Public\Desktop\scilab-5.4.1 (64-bit).lnk 2014-04-08 14:34 - 2014-04-08 14:33 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 14:32 - 2014-04-08 14:32 - 00000000 ____D () C:\Program Files (x86)\Dev-Cpp 2014-04-08 14:14 - 2014-04-08 14:14 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Scilab 2014-04-08 14:14 - 2014-04-08 14:12 - 00000000 ____D () C:\Program Files\scilab-5.4.1 2014-04-08 14:12 - 2014-04-08 14:12 - 28135014 _____ () C:\Users\dude\Desktop\scilab-help-chm-5.4.1.zip 2014-04-08 14:12 - 2014-04-08 14:12 - 20593796 _____ () C:\Users\dude\Desktop\blas-lapack-mkl-5.4.1-win64.zip 2014-04-08 14:11 - 2014-04-08 14:11 - 13866852 _____ () C:\Users\dude\Desktop\commons-mkl-5.4.1-win64.zip 2014-04-08 13:48 - 2014-04-08 13:48 - 00036864 _____ (Juliett_Six) C:\Users\dude\Desktop\WT_Logger_v0.13_64bit.exe 2014-04-03 12:39 - 2014-04-03 12:39 - 00004540 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-03 12:39 - 2014-04-03 12:39 - 00000000 ____D () C:\VTRoot 2014-04-03 12:37 - 2013-12-13 18:03 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO 2014-04-03 09:51 - 2014-04-17 11:18 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-17 11:18 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-03-09 14:06 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-01 13:15 - 2014-04-01 13:15 - 00001134 _____ () C:\Users\dude\Desktop\history - Verknüpfung.lnk 2014-04-01 13:12 - 2014-04-01 13:12 - 00000722 _____ () C:\Users\dude\Desktop\Kram - Verknüpfung.lnk 2014-04-01 11:46 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Users\dude\Desktop\shega 2014-03-31 13:40 - 2014-03-31 13:40 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner 2014-03-31 03:16 - 2014-04-09 11:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 11:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 11:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 11:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-28 17:30 - 2014-03-28 17:30 - 00003138 _____ () C:\Windows\System32\Tasks\{AA396EED-30E7-4B22-840F-0BD819D675B2} 2014-03-28 12:17 - 2014-03-28 12:17 - 00000000 ____D () C:\Windows\Sun 2014-03-26 10:17 - 2013-12-13 18:04 - 00063568 _____ () C:\Users\dude\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-26 10:16 - 2009-07-14 06:45 - 00293320 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-25 21:22 - 2013-09-24 12:54 - 00738472 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00105552 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00048360 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00023168 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys 2014-03-25 21:22 - 2013-09-24 12:53 - 00453680 _____ (COMODO) C:\Windows\system32\guard64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00363504 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00352984 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00284888 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00045784 _____ (COMODO) C:\Windows\system32\cmdkbd64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00043216 _____ (COMODO) C:\Windows\system32\cmdcsr.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00040664 _____ (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Users\dude\AppData\Roaming\OpenOffice 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-25 11:23 - 2014-03-25 11:23 - 00036041 _____ () C:\Users\dude\Desktop\TLAL Vault (2).zip 2014-03-20 09:27 - 2013-12-13 17:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 12:35 - 2014-03-18 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-18 19:04 - 2014-03-18 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox Some content of TEMP: ==================== C:\Users\dude\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-10 13:00 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 Ran by dude at 2014-04-17 12:12:20 Running from C:\Users\dude\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: COMODO Antivirus (Disabled - Up to date) {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: COMODO Antivirus (Disabled - Up to date) {0C2D2636-923D-EE52-2A83-E643204A8275} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.170 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 12.5.100.30429 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.937.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80430.0002 - Advanced Micro Devices, Inc.) Hidden Application Verifier (x64) (HKLM\...\{89026002-A893-42D9-9E20-6829B844735E}) (Version: 4.1.1078 - Microsoft Corporation) Bulk Rename Utility 2.7.1.2 (HKLM\...\Bulk Rename Utility_is1) (Version: - TGRMN Software) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2013.0429.2313.39747 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) CloudReading (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.0.27.1025 - Foxit Corporation) COMODO Antivirus (HKLM\...\{093F13A3-177C-493E-8958-912A0C690B64}) (Version: 6.3.32439.2937 - COMODO Security Solutions Inc.) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Debugging Tools for Windows (x64) (HKLM\...\{DBFC6AAE-DCCB-4C23-B01C-3EDDDC03298B}) (Version: 6.12.2.633 - Microsoft Corporation) Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.6.2 - Bloodshed Software) foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.1.1.1025 - Foxit Corporation) GeekBuddy (HKLM\...\{C36B3AE4-FCFE-4A0A-AA3D-71E1A51C1F16}) (Version: 4.11.91 - Comodo Security Solutions Inc) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) GPL Ghostscript (HKLM\...\GPL Ghostscript 9.10) (Version: 9.10 - Artifex Software Inc.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) JabRef 2.9.2 (HKLM-x32\...\JabRef 2.9.2) (Version: 2.9.2 - JabRef Team) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MATLAB R2012a (HKLM\...\Matlab R2012a) (Version: 7.14 - The MathWorks, Inc.) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ Compilers 2010 Standard - enu - x64 (HKLM\...\{88387B3B-B110-392F-B919-1A15B48F21D4}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (HKLM-x32\...\{370187B9-6964-38D0-851F-6C4898B0C2B1}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Windows Performance Toolkit (HKLM\...\{E7F9E526-2324-437B-A609-E8C5309465CB}) (Version: 4.8.0 - Microsoft Corporation) Microsoft Windows SDK .NET Framework Tools (30514) (Version: 7.1.30514 - Microsoft) Hidden Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation) Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Common Utilities (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Headers and Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Samples (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK Intellisense and Reference Assemblies (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK MSHelp (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.2 - pdfforge) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) scilab-5.4.1 (64-bit) (HKLM\...\scilab-5.4.1 (64-bit)_is1) (Version: - Scilab Enterprises) Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 2.4 - Krzysztof Kowalczyk) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeXnicCenter Version 2.02 Stable (HKLM\...\TeXnicCenter_is1) (Version: 2.02 Stable - The TeXnicCenter Team) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) War Thunder CDK 0.1 (HKLM-x32\...\{ed8deea4-29fe-1932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment) War Thunder Launcher 1.0.1.278 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2013 Gaijin Entertainment Corporation) Windows SDK IntellisenseNFX (x32 Version: 7.1.30514 - Microsoft) Hidden WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 08-04-2014 17:36:02 Geplanter Prüfpunkt 09-04-2014 23:27:45 Windows Update 16-04-2014 13:09:47 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {050A8A26-764C-44BB-955A-3B5D5041521A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {0CABA9A1-EA00-48BE-B070-CC98757A0437} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {28F1E40B-80B3-49C8-9CF5-8F5060090E0A} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {9ECCA2FC-5915-4A8A-8A48-CC2BFF58CB29} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {ADE6ED26-0659-4FFA-B8AF-8810322AF89B} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {D108170C-A7DC-45E9-967E-9C73141F5182} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-13] (Piriform Ltd) Task: {FA4531EB-9A61-4AB1-AF51-9BB3001F07C2} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {FDF2F0BE-CBED-4483-ADB6-69B98F25962B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-18 16:49 - 2013-06-18 16:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-04-30 00:08 - 2013-04-30 00:08 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: CLPSLauncher => 2 MSCONFIG\Services: cmdAgent => 2 MSCONFIG\Services: cmdvirth => 3 MSCONFIG\Services: GeekBuddyRSP => 2 MSCONFIG\Services: SDScannerService => 2 MSCONFIG\Services: SDUpdateService => 2 MSCONFIG\Services: SDWSCService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk => C:\Windows\pss\Start GeekBuddy.lnk.CommonStartup MSCONFIG\startupreg: COMODO Internet Security => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" MSCONFIG\startupreg: SpywareTerminatorShield => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe MSCONFIG\startupreg: SpywareTerminatorUpdater => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 20% Total physical RAM: 6077.93 MB Available physical RAM: 4821.66 MB Total Pagefile: 12154.03 MB Available Pagefile: 10696.02 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.21 GB) (Free:130.16 GB) NTFS Drive d: () (Fixed) (Total:1367.19 GB) (Free:1036.75 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 4FDFE16F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=195 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=-731016855552) - (Type=07 NTFS) ==================== End Of Log ============================ grüsse und vielen dank |
18.04.2014, 09:51 | #8 |
/// the machine /// TB-Ausbilder | Wiederholte Sicherheitssperre des Postfachs jede Menge Adware. Jetzt och Kontrollscans und wir sind durch ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.04.2014, 12:11 | #9 |
| Wiederholte Sicherheitssperre des Postfachs hi schrauber, sorry, war kurzfristig weg und hatte mein passwort nicht mit... zu deiner frage: Probleme hatte ich ja nicht wirklich, ging ja um die sicherheitssperre, wegen der ich mir sorgen gemacht habe das ich mir einen keylogger o.ä. eingefangen habe. das eset-log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=c17613ad59c2274ca667483c855479b3 # engine=17973 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-22 10:49:52 # local_time=2014-04-22 12:49:52 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=3074 16777213 100 84 9050 59178068 0 0 # compatibility_mode=5893 16776574 100 94 11053730 149793642 0 0 # scanned=686380 # found=0 # cleaned=0 # scan_time=8205 Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Java 7 Update 51 Java version out of Date! Adobe Flash Player 11.9.900.170 Flash Player out of Date! Mozilla Firefox (28.0) Mozilla Thunderbird (24.4.0) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 Ran by dude (administrator) on TBD on 17-04-2014 12:12:00 Running from C:\Users\dude\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-30] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC18A4A6919F8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF SearchPlugin: C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\searchplugins\duckduckgo.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: HTTPS-Everywhere - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\https-everywhere@eff.org [2014-04-15] FF Extension: Certificate Patrol - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\CertPatrol@PSYC.EU.xpi [2014-01-30] FF Extension: Ghostery - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\firefox@ghostery.com.xpi [2014-01-29] FF Extension: Adblock Plus - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-13] FF Extension: BetterPrivacy - C:\Users\dude\AppData\Roaming\Mozilla\Firefox\Profiles\r6rtoebk.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-12-16] ==================== Services (Whitelisted) ================= S4 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70352 2014-02-27] (Comodo Security Solutions, Inc.) S4 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [6812400 2014-03-25] (COMODO) S4 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2264280 2014-03-25] (COMODO) S4 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-02-27] (Comodo Security Solutions, Inc.) S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2013-05-07] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [23168 2014-03-25] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [738472 2014-03-25] (COMODO) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-16] (Disc Soft Ltd) R1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [14888 2013-10-07] () S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-17 12:09 - 2014-04-17 12:12 - 00006361 _____ () C:\Users\dude\Desktop\FRST.txt 2014-04-17 12:09 - 2014-04-17 12:09 - 00000000 ____D () C:\Users\dude\Desktop\FRST-OlderVersion 2014-04-17 12:08 - 2014-04-17 12:08 - 00000754 _____ () C:\Users\dude\Desktop\JRT2.txt 2014-04-17 12:08 - 2014-04-17 12:08 - 00000000 ____D () C:\Users\dude\Desktop\firstscn 2014-04-17 12:07 - 2014-04-17 12:07 - 00000754 _____ () C:\Users\dude\Desktop\JRT.txt 2014-04-17 11:41 - 2014-04-17 11:41 - 00000000 ____D () C:\Windows\ERUNT 2014-04-17 11:38 - 2014-04-17 11:38 - 00000953 _____ () C:\Users\dude\Desktop\AdwCleaner[S0].txt 2014-04-17 11:34 - 2014-04-17 11:36 - 00000000 ____D () C:\AdwCleaner 2014-04-17 11:33 - 2014-04-17 11:33 - 00001144 _____ () C:\Users\dude\Desktop\mbam.txt 2014-04-17 11:19 - 2014-04-17 11:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-17 11:18 - 2014-04-17 11:18 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-17 11:18 - 2014-04-17 11:18 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-17 11:18 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-17 11:18 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-17 11:14 - 2014-04-17 11:14 - 01016261 _____ (Thisisu) C:\Users\dude\Desktop\JRT.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\dude\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 01426178 _____ () C:\Users\dude\Desktop\adwcleaner.exe 2014-04-17 10:32 - 2014-04-17 10:32 - 00001314 _____ () C:\Users\Public\Desktop\WTAssetViewer.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001304 _____ () C:\Users\Public\Desktop\WTMissionEditor.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001292 _____ () C:\Users\Public\Desktop\LocationEd.lnk 2014-04-16 15:21 - 2014-04-16 15:21 - 00013341 _____ () C:\ComboFix.txt 2014-04-16 10:37 - 2014-04-16 10:37 - 00000866 _____ () C:\Users\dude\AppData\Local\recently-used.xbel 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\Desktop\template_bf-109g-2 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\AppData\Local\gtk-2.0 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\.thumbnails 2014-04-16 10:31 - 2014-04-16 10:38 - 00000000 ____D () C:\Users\dude\.gimp-2.8 2014-04-16 10:31 - 2014-04-16 10:31 - 00000000 ____D () C:\Users\dude\AppData\Local\gegl-0.2 2014-04-16 10:22 - 2014-04-16 10:23 - 00000000 ____D () C:\Program Files\GIMP 2 2014-04-16 09:57 - 2014-04-16 10:48 - 466674314 _____ () C:\Users\dude\Desktop\game.of.thrones.s04e02.hdtv.xvid-fum.avi 2014-04-16 09:55 - 2014-04-16 10:20 - 90396104 _____ (The GIMP Team ) C:\Users\dude\Desktop\gimp-2.8.10-setup.exe 2014-04-15 19:58 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-15 19:58 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-15 19:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-15 19:58 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-15 19:40 - 2014-04-15 19:43 - 05194807 ____R (Swearware) C:\Users\dude\Desktop\ComboFix.exe 2014-04-14 14:39 - 2014-04-16 15:21 - 00000000 ____D () C:\Qoobox 2014-04-14 14:31 - 2014-04-15 20:08 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 12:44 - 2014-04-14 12:43 - 00001136 _____ () C:\Users\dude\Desktop\Gmer.txt 2014-04-14 12:43 - 2014-04-14 12:43 - 00001136 _____ () C:\Users\dude\Documents\Gmer.txt 2014-04-14 12:17 - 2014-04-17 12:12 - 00000000 ____D () C:\FRST 2014-04-14 12:16 - 2014-04-14 12:16 - 00000000 _____ () C:\Users\dude\defogger_reenable 2014-04-14 11:18 - 2014-04-14 11:18 - 00380416 _____ () C:\Users\dude\Desktop\Gmer-19357.exe 2014-04-14 11:17 - 2014-04-17 12:09 - 02158592 _____ (Farbar) C:\Users\dude\Desktop\FRST64.exe 2014-04-14 11:07 - 2014-04-14 11:07 - 00050477 _____ () C:\Users\dude\Desktop\Defogger.exe 2014-04-11 10:59 - 2014-04-11 11:01 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner (2) 2014-04-10 20:40 - 2014-04-10 20:43 - 00000420 _____ () C:\Users\dude\Desktop\sidechat08.txt 2014-04-10 18:40 - 2014-04-10 18:40 - 00000000 ____D () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split 2014-04-10 17:41 - 2014-04-10 17:43 - 15111863 _____ () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split.zip 2014-04-09 20:37 - 2014-04-09 20:37 - 00001393 _____ () C:\Users\dude\Desktop\devcpp.exe - Verknüpfung.lnk 2014-04-09 11:06 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 11:06 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 11:06 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 11:06 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 11:03 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 11:03 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 11:03 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 11:03 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 11:03 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 11:03 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 11:03 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-08 14:33 - 2014-04-08 14:34 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 14:32 - 2014-04-08 14:32 - 00000000 ____D () C:\Program Files (x86)\Dev-Cpp 2014-04-08 14:14 - 2014-04-08 14:14 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Scilab 2014-04-08 14:13 - 2014-04-09 19:54 - 00001081 _____ () C:\Users\Public\Desktop\scilab-5.4.1 (64-bit).lnk 2014-04-08 14:12 - 2014-04-08 14:14 - 00000000 ____D () C:\Program Files\scilab-5.4.1 2014-04-08 14:12 - 2014-04-08 14:12 - 28135014 _____ () C:\Users\dude\Desktop\scilab-help-chm-5.4.1.zip 2014-04-08 14:12 - 2014-04-08 14:12 - 20593796 _____ () C:\Users\dude\Desktop\blas-lapack-mkl-5.4.1-win64.zip 2014-04-08 14:11 - 2014-04-08 14:11 - 13866852 _____ () C:\Users\dude\Desktop\commons-mkl-5.4.1-win64.zip 2014-04-08 13:48 - 2014-04-08 13:48 - 00036864 _____ (Juliett_Six) C:\Users\dude\Desktop\WT_Logger_v0.13_64bit.exe 2014-04-04 11:44 - 2010-01-18 15:49 - 00000000 ____D () C:\Users\dude\Desktop\Mouse On The Keys - An Anxious Object (2009) 2014-04-03 12:39 - 2014-04-03 12:39 - 00004540 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-03 12:39 - 2014-04-03 12:39 - 00000000 ____D () C:\VTRoot 2014-04-01 13:15 - 2014-04-01 13:15 - 00001134 _____ () C:\Users\dude\Desktop\history - Verknüpfung.lnk 2014-04-01 13:12 - 2014-04-01 13:12 - 00000722 _____ () C:\Users\dude\Desktop\Kram - Verknüpfung.lnk 2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Users\dude\Desktop\shega 2014-03-31 13:40 - 2014-03-31 13:40 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner 2014-03-28 17:30 - 2014-03-28 17:30 - 00003138 _____ () C:\Windows\System32\Tasks\{AA396EED-30E7-4B22-840F-0BD819D675B2} 2014-03-28 12:17 - 2014-03-28 12:17 - 00000000 ____D () C:\Windows\Sun 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Users\dude\AppData\Roaming\OpenOffice 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-25 11:23 - 2014-03-25 11:23 - 00036041 _____ () C:\Users\dude\Desktop\TLAL Vault (2).zip 2014-03-18 19:04 - 2014-03-18 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-18 19:00 - 2014-03-19 12:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== One Month Modified Files and Folders ======= 2014-04-17 12:12 - 2014-04-17 12:09 - 00006361 _____ () C:\Users\dude\Desktop\FRST.txt 2014-04-17 12:12 - 2014-04-14 12:17 - 00000000 ____D () C:\FRST 2014-04-17 12:10 - 2013-12-13 18:03 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2014-04-17 12:09 - 2014-04-17 12:09 - 00000000 ____D () C:\Users\dude\Desktop\FRST-OlderVersion 2014-04-17 12:09 - 2014-04-14 11:17 - 02158592 _____ (Farbar) C:\Users\dude\Desktop\FRST64.exe 2014-04-17 12:08 - 2014-04-17 12:08 - 00000754 _____ () C:\Users\dude\Desktop\JRT2.txt 2014-04-17 12:08 - 2014-04-17 12:08 - 00000000 ____D () C:\Users\dude\Desktop\firstscn 2014-04-17 12:07 - 2014-04-17 12:07 - 00000754 _____ () C:\Users\dude\Desktop\JRT.txt 2014-04-17 11:47 - 2010-11-21 08:50 - 00696832 _____ () C:\Windows\system32\perfh007.dat 2014-04-17 11:47 - 2010-11-21 08:50 - 00148128 _____ () C:\Windows\system32\perfc007.dat 2014-04-17 11:47 - 2009-07-14 07:13 - 01613340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-17 11:47 - 2009-07-14 06:45 - 00021856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-17 11:47 - 2009-07-14 06:45 - 00021856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-17 11:43 - 2013-12-13 17:33 - 01522949 _____ () C:\Windows\WindowsUpdate.log 2014-04-17 11:41 - 2014-04-17 11:41 - 00000000 ____D () C:\Windows\ERUNT 2014-04-17 11:40 - 2013-12-18 10:47 - 00013484 _____ () C:\Windows\setupact.log 2014-04-17 11:40 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-17 11:38 - 2014-04-17 11:38 - 00000953 _____ () C:\Users\dude\Desktop\AdwCleaner[S0].txt 2014-04-17 11:36 - 2014-04-17 11:34 - 00000000 ____D () C:\AdwCleaner 2014-04-17 11:33 - 2014-04-17 11:33 - 00001144 _____ () C:\Users\dude\Desktop\mbam.txt 2014-04-17 11:22 - 2014-04-17 11:19 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-17 11:18 - 2014-04-17 11:18 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-17 11:18 - 2014-04-17 11:18 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-17 11:18 - 2014-03-09 14:06 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Malwarebytes 2014-04-17 11:18 - 2014-03-09 14:06 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-17 11:16 - 2013-12-13 20:20 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Macromedia 2014-04-17 11:14 - 2014-04-17 11:14 - 01016261 _____ (Thisisu) C:\Users\dude\Desktop\JRT.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\dude\Desktop\mbam-setup-2.0.1.1004.exe 2014-04-17 11:13 - 2014-04-17 11:13 - 01426178 _____ () C:\Users\dude\Desktop\adwcleaner.exe 2014-04-17 10:32 - 2014-04-17 10:32 - 00001314 _____ () C:\Users\Public\Desktop\WTAssetViewer.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001304 _____ () C:\Users\Public\Desktop\WTMissionEditor.lnk 2014-04-17 10:32 - 2014-04-17 10:32 - 00001292 _____ () C:\Users\Public\Desktop\LocationEd.lnk 2014-04-17 10:32 - 2013-12-14 10:59 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder 2014-04-17 10:31 - 2013-12-14 10:59 - 00000000 ____D () C:\Program Files (x86)\WarThunder 2014-04-16 23:38 - 2013-12-13 19:38 - 00000000 ____D () C:\Users\dude\AppData\Roaming\vlc 2014-04-16 23:24 - 2014-01-09 23:43 - 00000000 ____D () C:\Users\dude\AppData\Roaming\TS3Client 2014-04-16 15:40 - 2014-01-14 10:14 - 00001984 _____ () C:\Windows\PFRO.log 2014-04-16 15:21 - 2014-04-16 15:21 - 00013341 _____ () C:\ComboFix.txt 2014-04-16 15:21 - 2014-04-14 14:39 - 00000000 ____D () C:\Qoobox 2014-04-16 15:18 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-16 15:05 - 2013-12-13 19:04 - 00000000 ____D () C:\Users\dude\AppData\Roaming\foobar2000 2014-04-16 10:48 - 2014-04-16 09:57 - 466674314 _____ () C:\Users\dude\Desktop\game.of.thrones.s04e02.hdtv.xvid-fum.avi 2014-04-16 10:38 - 2014-04-16 10:31 - 00000000 ____D () C:\Users\dude\.gimp-2.8 2014-04-16 10:37 - 2014-04-16 10:37 - 00000866 _____ () C:\Users\dude\AppData\Local\recently-used.xbel 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\Desktop\template_bf-109g-2 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\AppData\Local\gtk-2.0 2014-04-16 10:37 - 2014-04-16 10:37 - 00000000 ____D () C:\Users\dude\.thumbnails 2014-04-16 10:37 - 2013-12-13 17:34 - 00000000 ____D () C:\Users\dude 2014-04-16 10:31 - 2014-04-16 10:31 - 00000000 ____D () C:\Users\dude\AppData\Local\gegl-0.2 2014-04-16 10:23 - 2014-04-16 10:22 - 00000000 ____D () C:\Program Files\GIMP 2 2014-04-16 10:20 - 2014-04-16 09:55 - 90396104 _____ (The GIMP Team ) C:\Users\dude\Desktop\gimp-2.8.10-setup.exe 2014-04-16 00:31 - 2014-03-09 13:42 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-04-15 20:11 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-04-15 20:08 - 2014-04-14 14:31 - 00000000 ____D () C:\Windows\erdnt 2014-04-15 19:43 - 2014-04-15 19:40 - 05194807 ____R (Swearware) C:\Users\dude\Desktop\ComboFix.exe 2014-04-14 12:43 - 2014-04-14 12:44 - 00001136 _____ () C:\Users\dude\Desktop\Gmer.txt 2014-04-14 12:43 - 2014-04-14 12:43 - 00001136 _____ () C:\Users\dude\Documents\Gmer.txt 2014-04-14 12:16 - 2014-04-14 12:16 - 00000000 _____ () C:\Users\dude\defogger_reenable 2014-04-14 11:18 - 2014-04-14 11:18 - 00380416 _____ () C:\Users\dude\Desktop\Gmer-19357.exe 2014-04-14 11:07 - 2014-04-14 11:07 - 00050477 _____ () C:\Users\dude\Desktop\Defogger.exe 2014-04-11 11:01 - 2014-04-11 10:59 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner (2) 2014-04-10 20:43 - 2014-04-10 20:40 - 00000420 _____ () C:\Users\dude\Desktop\sidechat08.txt 2014-04-10 18:40 - 2014-04-10 18:40 - 00000000 ____D () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split 2014-04-10 17:43 - 2014-04-10 17:41 - 15111863 _____ () C:\Users\dude\Desktop\NOOTHGRUSH - SUPPRESSION - Noothgrush - Suppression Split.zip 2014-04-10 01:29 - 2013-12-15 20:22 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 01:28 - 2013-12-15 20:22 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 20:37 - 2014-04-09 20:37 - 00001393 _____ () C:\Users\dude\Desktop\devcpp.exe - Verknüpfung.lnk 2014-04-09 19:54 - 2014-04-08 14:13 - 00001081 _____ () C:\Users\Public\Desktop\scilab-5.4.1 (64-bit).lnk 2014-04-08 14:34 - 2014-04-08 14:33 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Dev-Cpp 2014-04-08 14:32 - 2014-04-08 14:32 - 00000000 ____D () C:\Program Files (x86)\Dev-Cpp 2014-04-08 14:14 - 2014-04-08 14:14 - 00000000 ____D () C:\Users\dude\AppData\Roaming\Scilab 2014-04-08 14:14 - 2014-04-08 14:12 - 00000000 ____D () C:\Program Files\scilab-5.4.1 2014-04-08 14:12 - 2014-04-08 14:12 - 28135014 _____ () C:\Users\dude\Desktop\scilab-help-chm-5.4.1.zip 2014-04-08 14:12 - 2014-04-08 14:12 - 20593796 _____ () C:\Users\dude\Desktop\blas-lapack-mkl-5.4.1-win64.zip 2014-04-08 14:11 - 2014-04-08 14:11 - 13866852 _____ () C:\Users\dude\Desktop\commons-mkl-5.4.1-win64.zip 2014-04-08 13:48 - 2014-04-08 13:48 - 00036864 _____ (Juliett_Six) C:\Users\dude\Desktop\WT_Logger_v0.13_64bit.exe 2014-04-03 12:39 - 2014-04-03 12:39 - 00004540 _____ () C:\Windows\system32\Drivers\fvstore.dat 2014-04-03 12:39 - 2014-04-03 12:39 - 00000000 ____D () C:\VTRoot 2014-04-03 12:37 - 2013-12-13 18:03 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO 2014-04-03 09:51 - 2014-04-17 11:18 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-17 11:18 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-03-09 14:06 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-01 13:15 - 2014-04-01 13:15 - 00001134 _____ () C:\Users\dude\Desktop\history - Verknüpfung.lnk 2014-04-01 13:12 - 2014-04-01 13:12 - 00000722 _____ () C:\Users\dude\Desktop\Kram - Verknüpfung.lnk 2014-04-01 11:46 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-31 14:02 - 2014-03-31 14:02 - 00000000 ____D () C:\Users\dude\Desktop\shega 2014-03-31 13:40 - 2014-03-31 13:40 - 00000000 ____D () C:\Users\dude\Desktop\Neuer Ordner 2014-03-31 03:16 - 2014-04-09 11:06 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 11:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 11:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 11:06 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-28 17:30 - 2014-03-28 17:30 - 00003138 _____ () C:\Windows\System32\Tasks\{AA396EED-30E7-4B22-840F-0BD819D675B2} 2014-03-28 12:17 - 2014-03-28 12:17 - 00000000 ____D () C:\Windows\Sun 2014-03-26 10:17 - 2013-12-13 18:04 - 00063568 _____ () C:\Users\dude\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-26 10:16 - 2009-07-14 06:45 - 00293320 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-25 21:22 - 2013-09-24 12:54 - 00738472 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00105552 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00048360 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys 2014-03-25 21:22 - 2013-09-24 12:54 - 00023168 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys 2014-03-25 21:22 - 2013-09-24 12:53 - 00453680 _____ (COMODO) C:\Windows\system32\guard64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00363504 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00352984 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00284888 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00045784 _____ (COMODO) C:\Windows\system32\cmdkbd64.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00043216 _____ (COMODO) C:\Windows\system32\cmdcsr.dll 2014-03-25 21:22 - 2013-09-24 12:53 - 00040664 _____ (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Users\dude\AppData\Roaming\OpenOffice 2014-03-25 11:29 - 2014-03-25 11:29 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-03-25 11:23 - 2014-03-25 11:23 - 00036041 _____ () C:\Users\dude\Desktop\TLAL Vault (2).zip 2014-03-20 09:27 - 2013-12-13 17:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-19 12:35 - 2014-03-18 19:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird 2014-03-18 19:04 - 2014-03-18 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox Some content of TEMP: ==================== C:\Users\dude\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-10 13:00 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 Ran by dude at 2014-04-17 12:12:20 Running from C:\Users\dude\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: COMODO Antivirus (Disabled - Up to date) {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: COMODO Antivirus (Disabled - Up to date) {0C2D2636-923D-EE52-2A83-E643204A8275} ==================== Installed Programs ====================== Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.170 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 12.5.100.30429 - Advanced Micro Devices, Inc.) Hidden AMD APP SDK Runtime (Version: 10.0.937.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{37FCE154-7F59-74F0-3A35-BF503CEB230B}) (Version: 8.0.877.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.80430.0002 - Advanced Micro Devices, Inc.) Hidden Application Verifier (x64) (HKLM\...\{89026002-A893-42D9-9E20-6829B844735E}) (Version: 4.1.1078 - Microsoft Corporation) Bulk Rename Utility 2.7.1.2 (HKLM\...\Bulk Rename Utility_is1) (Version: - TGRMN Software) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2013.0429.2313.39747 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0429.2312.39747 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0429.2313.39747 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) CloudReading (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.0.27.1025 - Foxit Corporation) COMODO Antivirus (HKLM\...\{093F13A3-177C-493E-8958-912A0C690B64}) (Version: 6.3.32439.2937 - COMODO Security Solutions Inc.) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd) Debugging Tools for Windows (x64) (HKLM\...\{DBFC6AAE-DCCB-4C23-B01C-3EDDDC03298B}) (Version: 6.12.2.633 - Microsoft Corporation) Dev-C++ (HKLM-x32\...\Dev-C++) (Version: 5.6.2 - Bloodshed Software) foobar2000 v1.2.9 (HKLM-x32\...\foobar2000) (Version: 1.2.9 - Peter Pawlowski) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.1.1.1025 - Foxit Corporation) GeekBuddy (HKLM\...\{C36B3AE4-FCFE-4A0A-AA3D-71E1A51C1F16}) (Version: 4.11.91 - Comodo Security Solutions Inc) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) GPL Ghostscript (HKLM\...\GPL Ghostscript 9.10) (Version: 9.10 - Artifex Software Inc.) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) JabRef 2.9.2 (HKLM-x32\...\JabRef 2.9.2) (Version: 2.9.2 - JabRef Team) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MATLAB R2012a (HKLM\...\Matlab R2012a) (Version: 7.14 - The MathWorks, Inc.) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation) Microsoft Help Viewer 1.0 (Version: 1.0.30319 - Microsoft Corporation) Hidden Microsoft Visual C++ Compilers 2010 Standard - enu - x64 (HKLM\...\{88387B3B-B110-392F-B919-1A15B48F21D4}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ Compilers 2010 Standard - enu - x86 (HKLM-x32\...\{370187B9-6964-38D0-851F-6C4898B0C2B1}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Windows Performance Toolkit (HKLM\...\{E7F9E526-2324-437B-A609-E8C5309465CB}) (Version: 4.8.0 - Microsoft Corporation) Microsoft Windows SDK .NET Framework Tools (30514) (Version: 7.1.30514 - Microsoft) Hidden Microsoft Windows SDK for Visual Studio .NET 4.0 Framework Tools (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 (7.1) (HKLM\...\SDKSetup_7.1.7600.0.30514) (Version: 7.1.7600.0.30514 - Microsoft Corporation) Microsoft Windows SDK for Windows 7 (7.1) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Common Utilities (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Headers and Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Samples (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK for Windows 7 Utilities for Win32 Development (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK Intellisense and Reference Assemblies (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK MSHelp (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden Microsoft Windows SDK Net Fx Interop Headers And Libraries (30514) (Version: 7.1.30514 - Microsoft Corporation) Hidden MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.2 - pdfforge) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) scilab-5.4.1 (64-bit) (HKLM\...\scilab-5.4.1 (64-bit)_is1) (Version: - Scilab Enterprises) Speccy (HKLM\...\Speccy) (Version: 1.24 - Piriform) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking Ltd.) SumatraPDF (HKLM-x32\...\SumatraPDF) (Version: 2.4 - Krzysztof Kowalczyk) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TeXnicCenter Version 2.02 Stable (HKLM\...\TeXnicCenter_is1) (Version: 2.02 Stable - The TeXnicCenter Team) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) War Thunder CDK 0.1 (HKLM-x32\...\{ed8deea4-29fe-1932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment) War Thunder Launcher 1.0.1.278 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2013 Gaijin Entertainment Corporation) Windows SDK IntellisenseNFX (x32 Version: 7.1.30514 - Microsoft) Hidden WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 08-04-2014 17:36:02 Geplanter Prüfpunkt 09-04-2014 23:27:45 Windows Update 16-04-2014 13:09:47 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {050A8A26-764C-44BB-955A-3B5D5041521A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {0CABA9A1-EA00-48BE-B070-CC98757A0437} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {28F1E40B-80B3-49C8-9CF5-8F5060090E0A} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {9ECCA2FC-5915-4A8A-8A48-CC2BFF58CB29} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {ADE6ED26-0659-4FFA-B8AF-8810322AF89B} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {D108170C-A7DC-45E9-967E-9C73141F5182} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-13] (Piriform Ltd) Task: {FA4531EB-9A61-4AB1-AF51-9BB3001F07C2} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2014-03-31] (COMODO) Task: {FDF2F0BE-CBED-4483-ADB6-69B98F25962B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe ==================== Loaded Modules (whitelisted) ============= 2013-06-18 16:49 - 2013-06-18 16:49 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-04-30 00:08 - 2013-04-30 00:08 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: CLPSLauncher => 2 MSCONFIG\Services: cmdAgent => 2 MSCONFIG\Services: cmdvirth => 3 MSCONFIG\Services: GeekBuddyRSP => 2 MSCONFIG\Services: SDScannerService => 2 MSCONFIG\Services: SDUpdateService => 2 MSCONFIG\Services: SDWSCService => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Start GeekBuddy.lnk => C:\Windows\pss\Start GeekBuddy.lnk.CommonStartup MSCONFIG\startupreg: COMODO Internet Security => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" MSCONFIG\startupreg: SpywareTerminatorShield => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe MSCONFIG\startupreg: SpywareTerminatorUpdater => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 20% Total physical RAM: 6077.93 MB Available physical RAM: 4821.66 MB Total Pagefile: 12154.03 MB Available Pagefile: 10696.02 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:195.21 GB) (Free:130.16 GB) NTFS Drive d: () (Fixed) (Total:1367.19 GB) (Free:1036.75 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 4FDFE16F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=195 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=-731016855552) - (Type=07 NTFS) ==================== End Of Log ============================ |
22.04.2014, 19:04 | #10 |
/// the machine /// TB-Ausbilder | Wiederholte Sicherheitssperre des Postfachs Java und Adobe updaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.04.2014, 09:24 | #11 |
| Wiederholte Sicherheitssperre des Postfachs hi, alles deeinstalliert und up to date. vielen vielen dank für deine hilfe |
24.04.2014, 07:11 | #12 |
/// the machine /// TB-Ausbilder | Wiederholte Sicherheitssperre des Postfachs Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Wiederholte Sicherheitssperre des Postfachs |
.dll, antivirus, branding, browser, explorer, festplatte, flash player, memory.dmp, object, performance, refresh, registry, schutz, services.exe, sicherheitssperre, sicherheitssysteme haben unregelmäßigkeiten beim zugriff festgestellt, software, spyware, svchost.exe, teamspeak, temp, winlogon.exe, zu ihrem persönlichen schutz haben wir vorsorglich ihr postfach gesperrt |