|
Plagegeister aller Art und deren Bekämpfung: Emails mit Link werden verschickt: AOLWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
15.04.2014, 20:57 | #1 |
| Emails mit Link werden verschickt: AOL Hallo, ich habe heute gemerkt, dass mein AOL-Emailkonto eine Email mit einem Link an einige Kontakte versendet hat. Im Ordner der gesendeten Mails ist aber nichts auffindbar. Benutze außerdem Outlook, falls es sein kann, dass dies vom meinem Laptop aus geschieht. Schonmal Danke Gruß Steffen |
16.04.2014, 09:04 | #2 |
/// the machine /// TB-Ausbilder | Emails mit Link werden verschickt: AOL hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
16.04.2014, 10:06 | #3 |
| Emails mit Link werden verschickt: AOL Hi,
__________________hier die Logs: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-04-2014 Ran by Steffen (administrator) on STEFFEN-PC on 16-04-2014 11:00:05 Running from C:\Users\Steffen\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe ( ) C:\Windows\system32\dlcgcoms.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Salfeld Computer) C:\Windows\SysWOW64\cchservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files (x86)\watchmi\TvdService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Pegatron Corporation) C:\Program Files (x86)\PHotkey\PHotkey.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe () C:\Program Files (x86)\PHotkey\ATouch64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe () C:\Program Files (x86)\PHotkey\PVDesktop.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe () C:\Program Files (x86)\PHotkey\PVDAgent.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Pegatron Corporation) C:\Program Files (x86)\PHotkey\POSD.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Spotify Ltd) C:\Users\Steffen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\watchmi\TvdTray.exe (Dropbox, Inc.) C:\Users\Steffen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11817576 2011-04-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2209896 2011-04-18] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [10361616 2011-02-11] (Intel Corporation) HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84816 2010-12-10] (UPEK Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated) HKLM\...\Run: [DLCGCATS] => C:\Windows\system32\spool\DRIVERS\x64\3\DLCGtime.dll [28672 2006-10-21] () HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [172144 2012-12-14] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [399984 2012-12-14] (Intel Corporation) HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [441968 2012-12-14] (Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [ChicoSys] => C:\Windows\SysWOW64\cc32\webtmr.exe [5528984 2009-07-14] (Salfeld Computer) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.) HKU\S-1-5-19\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-20\...\Run: [Sidebar] => C:\Program Files\Windows Sidebar\Sidebar.exe [1475584 2010-11-21] (Microsoft Corporation) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Run: [Spotify Web Helper] => C:\Users\Steffen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-17] (Spotify Ltd) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-04-24] (Google Inc.) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\MountPoints2: {5983fd30-aab0-11e2-a24d-bc7737cba835} - F:\HTC_Sync_Manager_PC.exe AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174296 2014-03-04] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2014-03-04] (NVIDIA Corporation) Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll Startup: C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Steffen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) GroupPolicyUsers\S-1-5-21-3580909774-2373009125-3570030466-1056\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aldi.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default FF user.js: detected! => C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: OLB - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default\Extensions\{C752FF21-A8EF-468E-B507-5BBAFB84359D} [2014-03-23] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-04-21] Chrome: ======= CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=MDNC&bmod=MDNC CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (AVG Internet Security) - C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (Internet Banking der OLB) - C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fipffogddddpcmkklaodlnofkmpognml [2014-02-13] CHR Extension: (Google Wallet) - C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04] ==================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-19] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 dlcg_device; C:\Windows\system32\dlcgcoms.exe [566152 2006-12-08] ( ) R2 dlcg_device; C:\Windows\SysWOW64\dlcgcoms.exe [537480 2006-12-08] ( ) R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-07] () R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2012-12-12] (Nero AG) S2 ksupmgr; C:\Windows\SysWOW64\ksupmgr.exe [765592 2010-08-25] (Salfeld Computer) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [267824 2007-03-26] (Nero AG) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2013-01-21] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2013-01-21] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-12-14] () R2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [62464 2010-12-06] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-07] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-07] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-07] () R3 com0com; C:\Windows\System32\DRIVERS\com0com.sys [76800 2011-01-25] (Vyacheslav Frolov) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2012-06-11] (Texas Instruments) S3 RSUSBVSTOR; System32\Drivers\RTSUVSTOR.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-16 11:00 - 2014-04-16 11:00 - 00021928 _____ () C:\Users\Steffen\Desktop\FRST.txt 2014-04-16 10:59 - 2014-04-16 11:00 - 00000000 ____D () C:\FRST 2014-04-16 10:58 - 2014-04-16 10:58 - 02054144 _____ (Farbar) C:\Users\Steffen\Desktop\FRST64.exe 2014-04-15 21:33 - 2014-04-16 10:30 - 00000992 _____ () C:\Windows\PFRO.log 2014-04-15 12:16 - 2014-04-15 12:16 - 725663984 _____ () C:\Windows\MEMORY.DMP 2014-04-15 12:16 - 2014-04-15 12:16 - 00340312 _____ () C:\Windows\Minidump\041514-26613-01.dmp 2014-04-14 14:19 - 2014-04-14 14:19 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\OBS 2014-04-14 14:18 - 2014-04-14 14:18 - 00000044 _____ () C:\Users\Steffen\Desktop\key.txt 2014-04-14 14:10 - 2014-04-14 14:20 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-04-14 14:10 - 2014-04-14 14:10 - 00000943 _____ () C:\Users\Steffen\Desktop\Open Broadcaster Software.lnk 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Program Files\OBS 2014-04-14 14:09 - 2014-04-14 14:10 - 07888419 _____ () C:\Users\Steffen\Downloads\OBS_0_613b_Installer.exe 2014-04-13 19:55 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-13 19:55 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-13 19:55 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 19:55 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-13 19:54 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-13 19:54 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-13 19:54 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-13 19:54 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-13 19:54 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-13 19:54 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-13 19:54 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-13 19:54 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-13 19:54 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-13 19:54 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-13 19:54 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-13 19:54 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-04 19:45 - 2014-04-16 10:31 - 00003830 _____ () C:\Windows\setupact.log 2014-04-04 19:45 - 2014-04-04 19:45 - 00000000 _____ () C:\Windows\setuperr.log 2014-03-31 13:47 - 2014-03-31 13:47 - 00000000 ____D () C:\Users\Steffen\Desktop\Steffen 2014-03-31 13:32 - 2014-03-31 13:32 - 00001727 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 142.odb 2014-03-27 16:06 - 2014-03-27 16:06 - 00000000 ____D () C:\Users\Steffen\Desktop\Stick123 2014-03-23 17:00 - 2014-03-23 17:00 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 141.odb 2014-03-23 16:57 - 2014-03-23 16:57 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 140.odb 2014-03-23 14:09 - 2014-03-23 16:56 - 00000000 ____D () C:\Users\Steffen\Desktop\USB-Stick 2014-03-22 20:26 - 2014-03-22 20:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair.htm 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair (1).htm 2014-03-21 13:09 - 2014-03-21 13:12 - 00000222 _____ () C:\Users\Steffen\Desktop\PAYDAY 2.url 2014-03-19 12:07 - 2014-03-19 12:07 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Template 2014-03-19 11:16 - 2014-03-19 11:16 - 01484080 _____ (Microsoft Corporation) C:\Users\Steffen\Downloads\WorksConv.exe 2014-03-19 11:16 - 2014-03-19 11:16 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-03-19 11:10 - 2014-03-19 11:10 - 04745216 _____ () C:\Users\Steffen\Downloads\Works632_de-DE.msi 2014-03-19 10:50 - 2014-03-19 10:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 ==================== One Month Modified Files and Folders ======= 2014-04-16 11:00 - 2014-04-16 11:00 - 00021928 _____ () C:\Users\Steffen\Desktop\FRST.txt 2014-04-16 11:00 - 2014-04-16 10:59 - 00000000 ____D () C:\FRST 2014-04-16 11:00 - 2013-08-08 13:56 - 00000164 _____ () C:\Windows\SysWOW64\SWCTL.DLL 2014-04-16 10:58 - 2014-04-16 10:58 - 02054144 _____ (Farbar) C:\Users\Steffen\Desktop\FRST64.exe 2014-04-16 10:54 - 2013-04-21 21:37 - 00000000 ___RD () C:\Users\Steffen\Dropbox 2014-04-16 10:54 - 2013-04-21 21:35 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Dropbox 2014-04-16 10:54 - 2013-01-07 15:49 - 00000000 ____D () C:\Users\Steffen\AppData\Local\HTC MediaHub 2014-04-16 10:54 - 2012-07-19 14:27 - 01615974 _____ () C:\Windows\WindowsUpdate.log 2014-04-16 10:53 - 2012-04-24 22:15 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-16 10:38 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-16 10:38 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-16 10:31 - 2014-04-04 19:45 - 00003830 _____ () C:\Windows\setupact.log 2014-04-16 10:30 - 2014-04-15 21:33 - 00000992 _____ () C:\Windows\PFRO.log 2014-04-16 10:30 - 2011-06-24 16:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-16 10:30 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-15 23:03 - 2012-04-24 22:15 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-15 21:38 - 2013-04-21 20:27 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-15 17:08 - 2013-02-08 23:21 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-15 17:07 - 2014-02-03 17:17 - 00000000 ____D () C:\Users\Steffen\AppData\Local\DayZ 2014-04-15 15:38 - 2013-04-01 14:01 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\TS3Client 2014-04-15 12:20 - 2014-02-01 18:31 - 00185856 ___SH () C:\Users\Steffen\Desktop\Thumbs.db 2014-04-15 12:16 - 2014-04-15 12:16 - 725663984 _____ () C:\Windows\MEMORY.DMP 2014-04-15 12:16 - 2014-04-15 12:16 - 00340312 _____ () C:\Windows\Minidump\041514-26613-01.dmp 2014-04-15 12:16 - 2014-02-11 17:40 - 00000000 ____D () C:\Windows\Minidump 2014-04-14 20:04 - 2011-06-19 19:00 - 00703176 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 20:04 - 2011-06-19 19:00 - 00150784 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 20:04 - 2009-07-14 07:13 - 01629276 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-14 16:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-14 14:20 - 2014-04-14 14:10 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-04-14 14:19 - 2014-04-14 14:19 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\OBS 2014-04-14 14:18 - 2014-04-14 14:18 - 00000044 _____ () C:\Users\Steffen\Desktop\key.txt 2014-04-14 14:10 - 2014-04-14 14:10 - 00000943 _____ () C:\Users\Steffen\Desktop\Open Broadcaster Software.lnk 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Program Files\OBS 2014-04-14 14:10 - 2014-04-14 14:09 - 07888419 _____ () C:\Users\Steffen\Downloads\OBS_0_613b_Installer.exe 2014-04-14 12:23 - 2012-05-12 12:37 - 00000000 ____D () C:\Program Files\Dl_cats 2014-04-13 22:44 - 2013-08-09 16:06 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Spotify 2014-04-13 22:39 - 2012-07-06 22:39 - 00000000 ____D () C:\Users\Steffen\AppData\Local\Spotify 2014-04-13 20:10 - 2012-04-27 12:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-13 20:09 - 2013-07-13 11:39 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-13 20:09 - 2012-04-24 22:16 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-13 20:05 - 2011-06-19 14:08 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-12 18:54 - 2013-06-03 17:26 - 00000000 ____D () C:\Users\Steffen\AppData\Local\CyberLink 2014-04-04 19:45 - 2014-04-04 19:45 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-04 19:00 - 2006-01-01 14:27 - 00000000 ____D () C:\Users\Steffen\Desktop\DCIM 2014-04-02 14:51 - 2013-04-24 15:32 - 00000000 ____D () C:\Users\Steffen\Documents\VirtualDJ 2014-04-02 14:22 - 2014-02-12 19:30 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\FileZilla 2014-03-31 13:47 - 2014-03-31 13:47 - 00000000 ____D () C:\Users\Steffen\Desktop\Steffen 2014-03-31 13:32 - 2014-03-31 13:32 - 00001727 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 142.odb 2014-03-31 03:16 - 2014-04-13 19:55 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-13 19:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-13 19:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-13 19:55 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 13:58 - 2012-04-24 22:15 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-29 13:58 - 2012-04-24 22:15 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 13:34 - 2012-07-01 19:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-27 16:06 - 2014-03-27 16:06 - 00000000 ____D () C:\Users\Steffen\Desktop\Stick123 2014-03-23 17:04 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-03-23 17:00 - 2014-03-23 17:00 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 141.odb 2014-03-23 16:57 - 2014-03-23 16:57 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 140.odb 2014-03-23 16:56 - 2014-03-23 14:09 - 00000000 ____D () C:\Users\Steffen\Desktop\USB-Stick 2014-03-22 21:07 - 2014-01-27 18:03 - 00000000 ____D () C:\Users\Steffen\Desktop\Facharbeit 2014-03-22 20:27 - 2014-03-22 20:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-22 19:25 - 2012-04-24 22:23 - 00153904 _____ () C:\Users\Steffen\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-22 19:22 - 2009-07-14 06:45 - 05160968 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair.htm 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair (1).htm 2014-03-21 13:12 - 2014-03-21 13:09 - 00000222 _____ () C:\Users\Steffen\Desktop\PAYDAY 2.url 2014-03-19 12:07 - 2014-03-19 12:07 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Template 2014-03-19 11:40 - 2012-04-29 12:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2014-03-19 11:16 - 2014-03-19 11:16 - 01484080 _____ (Microsoft Corporation) C:\Users\Steffen\Downloads\WorksConv.exe 2014-03-19 11:16 - 2014-03-19 11:16 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-03-19 11:10 - 2014-03-19 11:10 - 04745216 _____ () C:\Users\Steffen\Downloads\Works632_de-DE.msi 2014-03-19 10:53 - 2012-04-29 12:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-03-19 10:53 - 2011-04-12 10:28 - 00000000 ____D () C:\Windows\ShellNew 2014-03-19 10:53 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-03-19 10:50 - 2014-03-19 10:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 2014-03-17 15:26 - 2013-03-14 17:23 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-17 15:26 - 2013-03-14 17:23 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight Files to move or delete: ==================== C:\Users\Steffen\AppData\Roaming\CamLayout.ini C:\Users\Steffen\AppData\Roaming\CamShapes.ini C:\Users\Steffen\sicherung.bat Some content of TEMP: ==================== C:\Users\Sicherung\AppData\Local\Temp\AskSLib.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-14 16:46 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-04-2014 Ran by Steffen at 2014-04-16 11:00:44 Running from C:\Users\Steffen\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1784.41616 - ABBYY Software House) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1860 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.1860 - Adobe Systems Incorporated) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.2.5 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.2.5 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.7.700.202 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.202 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 3.6 64-bit (HKLM\...\{D4F66BBA-D79E-4F11-9B06-70C3D75A2958}) (Version: 3.6.1 - Adobe) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.6.636 - Adobe Systems, Inc.) AMI VR-pulse OS Switcher (HKLM\...\{EC1369CF-15BD-4FAF-BA84-65E4788C682E}) (Version: 1.1 - American Megatrends Inc.) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio (HKLM-x32\...\Ashampoo Burning Studio_is1) (Version: 10.0.10 - Ashampoo GmbH & Co. KG) Ashampoo Photo Commander (HKLM-x32\...\Ashampoo Photo Commander_is1) (Version: 9.2.0 - Ashampoo GmbH & Co. KG) Ashampoo Photo Optimizer (HKLM-x32\...\Ashampoo Photo Optimizer_is1) (Version: 4.0.0 - Ashampoo GmbH & Co. KG) Ashampoo Snap (HKLM-x32\...\Ashampoo Snap_is1) (Version: 4.3.0 - Ashampoo GmbH & Co. KG) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 8.0.1489.0 - AVAST Software) AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - ) AVM FRITZ!Box Dokumentation (HKLM-x32\...\AVMFBox) (Version: - AVM Berlin) AVM FRITZ!Box Druckeranschluss (HKLM-x32\...\AVMFBoxPrinter) (Version: - AVM Berlin) BMWi Updater (HKLM-x32\...\BMWi Updater) (Version: 1.0 - A2C Software AG, Aachen) BMWi Updater (x32 Version: 1.0 - A2C Software AG, Aachen) Hidden BMWi-Softwarepaket 10 - Warenwirtschaft (HKLM-x32\...\BMWi-Softwarepaket 10 - Warenwirtschaft) (Version: 10.0 - A2C Software AG) BMWi-Softwarepaket 10 - Warenwirtschaft (x32 Version: 10.0 - A2C Software AG, Aachen) Hidden Boeing 737 Fuel Planner (HKLM-x32\...\Boeing 737 Fuel Planner) (Version: - ) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) Cheat Engine 6.2 (HKLM-x32\...\Cheat Engine 6.2_is1) (Version: - Dark Byte) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{72DB27D3-FE05-4227-AF5A-11CD101ECF09}) (Version: 15.1.0.588 - Corel Corporation) Corel Graphics - Windows Shell Extension (x32 Version: 15.1.588 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Common (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Connect (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - DE (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Draw (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - EN (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - ES (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Extra Content (HKLM-x32\...\_{5A10CFDA-FA2B-453C-B561-AE864E62EAC8}) (Version: - Corel Corporation) CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Filters (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - FR (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IPM (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - IT (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 - WT (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Essentials X5 (HKLM-x32\...\_{EDBEBF07-F880-48FB-9AA5-0E8E71E02D83}) (Version: 15.1.0.588 - Corel Corporation) CorelDRAW Essentials X5 (x32 Version: 15.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (Version: 15.1.588 - Corel Corporation) Hidden CrystalDiskInfo 6.1.1 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.1.1 - Crystal Dew World) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.3624 - CyberLink Corp.) Hidden CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1508_36229 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1508_36229 - CyberLink Corp.) Hidden CyberLink MediaShow (HKLM-x32\...\InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}) (Version: 5.1.2414 - CyberLink Corp.) CyberLink MediaShow (x32 Version: 5.1.2414 - CyberLink Corp.) Hidden CyberLink PhotoNow (HKLM-x32\...\InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}) (Version: 1.1.0.6904 - CyberLink Corp.) CyberLink PhotoNow (x32 Version: 1.1.0.6904 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1327 - CyberLink Corp.) CyberLink Power2Go (x32 Version: 7.0.0.1327 - CyberLink Corp.) Hidden CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.4020 - CyberLink Corp.) CyberLink PowerDirector (x32 Version: 8.0.4020 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.2930.52 - CyberLink Corp.) CyberLink PowerDVD 10 (x32 Version: 10.0.2930.52 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy (HKLM-x32\...\InstallShield_{E3D04529-6EDB-11D8-A372-0050BAE317E1}) (Version: 1.5.1306 - CyberLink Corp.) CyberLink PowerDVD Copy (x32 Version: 1.5.1306 - CyberLink Corp.) Hidden CyberLink PowerProducer (HKLM-x32\...\InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version: 5.0.2.3503 - CyberLink Corp.) CyberLink PowerProducer (x32 Version: 5.0.2.3503 - CyberLink Corp.) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4013 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.1.4013 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive) DCTnet (remove only) (HKLM-x32\...\DCTnet) (Version: - ) Dell AIO 810 (HKLM\...\Dell AIO 810) (Version: - Dell, Inc.) Dell PC-Fax (HKLM\...\Dell Fax Solutions) (Version: - ) Der Kleine Turnierplaner 7.1.7.1 (HKLM-x32\...\Der_Deploy_0) (Version: 7.1.7.1 - Der Kleine Turnierplaner) Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.4 - Dolby Laboratories Inc) Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 14.0.0.10960 - Landesfinanzdirektion Thüringen) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Evernote v. 4.5.5 (HKLM-x32\...\{4C9EA6BE-9555-11E1-9683-984BE15F174E}) (Version: 4.5.5.6827 - Evernote Corp.) FileZilla Client 3.7.4.1 (HKLM-x32\...\FileZilla Client) (Version: 3.7.4.1 - Tim Kosse) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.0.2.413 - Foxit Corporation) Fraps (HKLM-x32\...\Fraps) (Version: - ) Free YouTube to MP3 Converter version 3.12.7.711 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.7.711 - DVDVideoSoft Ltd.) FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version: - ) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden GIMP 2.8.6 (HKLM\...\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.) HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.0.1.001 - HTC Corporation) HTC Sync Manager (HKLM-x32\...\{5DC3BFF3-B84F-4CBE-B2BD-FB52B6C247CA}) (Version: 1.1.77.0 - HTC) ICQ7M (HKLM-x32\...\{781B39EC-2E18-41FC-9B00-B84E4FFCA85F}) (Version: 7.8 - ICQ) Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2418 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{A0E106D2-4815-4B7A-BAA7-7E21B530CFB4}) (Version: 1.1.0.0157 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{C7B40C35-85AE-4303-9EEA-1A1EA779664D}) (Version: 1.0.2.0518 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1026 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{0DD706AF-B542-438C-999E-B30C7F625C8D}) (Version: 2.1.39.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) IvAc v1.2.4 (b225) (HKLM-x32\...\IvAc_is1) (Version: - IVAO) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kill-ID 1.2.4.0 für Chrome (HKLM-x32\...\Kill-ID für Chrome_is1) (Version: 1.2.5.0 - Alexander Miehlke Softwareentwicklung) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Medion Home Cinema (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2608 - CyberLink Corp.) Medion Home Cinema (x32 Version: 8.0.2608 - CyberLink Corp.) Hidden Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: - ) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Flight Simulator 2004 A Century of Flight (HKLM-x32\...\Flight Simulator 9.0) (Version: 9.0 - Microsoft) Microsoft Mathematics (64-Bit) (HKLM\...\{E57B7E0A-8BE5-42E2-BE60-C07ED680A063}) (Version: 4.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Standard 2007 (HKLM-x32\...\STANDARD) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Standard 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server Native Client (HKLM\...\{519918B9-24E9-4227-B927-9DD4F0FDBD0E}) (Version: 9.00.3042.00 - Microsoft Corporation) Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version: - ) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{cb41fc68-4442-4f7f-b22f-8f31c74897ac}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Works 6-9 Converter (HKLM-x32\...\{172423F9-522A-483A-AD65-03600CE4CA4F}) (Version: 9.7.0000 - Microsoft Corporation) Microsoft Works 6-9 Converter (HKLM-x32\...\{95140000-0137-0407-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation) Microsoft Works 7.0 (HKLM-x32\...\{EDDDC607-91D9-4758-9F57-265FDCD8A772}) (Version: 07.02.0702 - Microsoft Corporation) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.4 - F.J. Wechselberger) Nero 7 Essentials (HKLM-x32\...\{97F32DF8-D66E-446A-A425-C1D7B45C1031}) (Version: 7.02.6782 - Nero AG) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.2 - Notepad++ Team) NSpire Text Editor 2.2b (HKLM-x32\...\{4395E06B-6A2C-4370-BE8A-DFABA4BDF72C}_is1) (Version: - Blue_Key [swisstonic@gmail.com]) Null-modem emulator (com0com) (HKLM-x32\...\com0com) (Version: 2.2.2.0 - Vyacheslav Frolov) NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2 - NVIDIA Corporation) NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Optimus Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.11 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - ) OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.) pc-profi-Chart_de2013 (HKLM-x32\...\pc-profi-Chart_de2013_is1) (Version: - Deutscher Sparkassen Verlag GmbH) PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0032 - Pegatron Corporation) PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: 11.0.0.14 - ProtectDisc Software GmbH) Protector Suite 2011 (HKLM\...\{BF30D9F5-23B6-4E1C-B580-C9CDBA2CD894}) (Version: 5.9.4.6894 - UPEK Inc.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.) QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.41.216.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6353 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.) RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - ) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden Scribus 1.4.3 (64bit) (HKLM\...\Scribus 1.4.3) (Version: 1.4.3 - The Scribus Team) SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden SketchUp 8 (HKLM-x32\...\{8EB62C87-AAA6-4850-A5BC-64155884B973}) (Version: 3.0.16846 - Trimble Navigation Limited) Speccy (HKLM\...\Speccy) (Version: 1.20 - Piriform) Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated) Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.4.0 - Synaptics Incorporated) TeamSpeak 2 RC2 (HKLM-x32\...\Teamspeak 2 RC2_is1) (Version: 2.0.32.60 - Dominating Bytes Design) TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) TI-Nspire(TM) Computer Link (HKLM-x32\...\{C0B7C804-B89F-47F7-91CC-21ACDC7D7AAC}) (Version: 3.2.0.124 - Texas Instruments Inc.) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_STANDARD_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_STANDARD_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{9B1DEEA3-B4ED-49F0-9EF7-4A820EEEA7F1}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition (HKLM-x32\...\{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{9B1DEEA3-B4ED-49F0-9EF7-4A820EEEA7F1}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_STANDARD_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_STANDARD_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_STANDARD_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_STANDARD_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VirtualDJ Home FREE (HKLM-x32\...\{A6AC699F-8315-40CA-8F70-E917494978AB}) (Version: 7.4 - Atomix Productions) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) VLC media player 2.0.7 (HKLM-x32\...\VLC media player) (Version: 2.0.7 - VideoLAN) VRiSim version 1.0 (HKLM-x32\...\{53CCD1CA-E3BA-4978-B156-7F6A389164E0}_is1) (Version: 1.0 - VRInsight Inc.) VRiSim/MCP_Combo version 1.0 (HKLM-x32\...\{D663928E-92A2-434E-B916-8EFF32B25A03}_is1) (Version: 1.0 - VRInsight Inc.) VR-pulse Installer (HKLM\...\{D3836C5E-6824-4C9F-9B45-09C989B13EF6}) (Version: 1.5.2.0 - American Megatrends Inc.) watchmi (HKLM-x32\...\{AA4D1C5E-116A-4FF4-AA91-28F526868203}) (Version: 2.5.0 - Axel Springer Digital TV Guide GmbH) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 18-03-2014 14:14:07 Windows Update 19-03-2014 08:48:17 Installed Microsoft Office Professional Plus 2007 19-03-2014 09:10:35 Microsoft Works 6-9 Converter wird installiert 19-03-2014 09:37:16 Microsoft Works 7.0 wird installiert 21-03-2014 11:02:04 Windows Update 23-03-2014 01:04:16 Windows Update 28-03-2014 11:42:34 Windows Update 01-04-2014 16:43:09 Windows Update 13-04-2014 17:53:44 Windows Update 13-04-2014 18:02:55 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {146D8710-FAA8-4D60-88E6-96FFAB4C36BB} - System32\Tasks\{558CD4BD-0E03-4E42-9FEA-AC2DF20145B8} => C:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's H.A.W.X - Demo\HAWX.exe Task: {3D5CF4E7-6320-4BDC-9EDD-EDCBCD1BD3D9} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {6CC1C136-9B0A-4826-9717-DB65B5F00163} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {6EA66944-2ACD-48B3-A117-D77894F89F0D} - System32\Tasks\{66F83062-0C89-4407-B1BB-F0EBC08492BA} => C:\Program Files (x86)\Steam\steamapps\common\Tom Clancy's H.A.W.X - Demo\HAWX.exe Task: {7735E719-DFC9-46EF-8C36-78913F03DC60} - System32\Tasks\Sicherung Facharbeit Dropbox => C:\Users\Steffen\sicherung.bat [2014-02-16] () Task: {7A4D3B10-94CF-44AD-A513-3CF2A83F9B94} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: {AE0D9BC3-3E9A-421C-9DF7-538F7FE579BC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24] (Google Inc.) Task: {CDD104C5-8C2C-49AB-AC5E-C2B23DDD7234} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24] (Google Inc.) Task: {DC92959E-E545-488F-9A33-A5A7253EC209} - System32\Tasks\{10131E2E-8D8D-4DA3-979E-1DAA392DDB66} => C:\Program Files (x86)\Quadriga Games\Emergency 2012\bin.x86\em2012.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-02-03 22:21 - 2014-03-04 16:35 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-02-09 12:29 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2011-06-19 16:21 - 2009-12-19 00:40 - 00104968 ____R () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2011-06-19 16:21 - 2010-10-07 02:46 - 00159752 ____R () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe 2012-05-12 12:40 - 2006-10-06 14:27 - 00045056 _____ () C:\Windows\System32\DLPRMON.DLL 2012-05-12 12:39 - 2006-10-06 14:24 - 00016384 _____ () C:\Program Files (x86)\Dell Fax Solutions\DlCtrStr.dll 2012-05-12 12:39 - 2006-10-06 14:24 - 00081408 _____ () C:\Program Files (x86)\Dell Fax Solutions\ipcmt64.dll 2012-09-24 18:20 - 2010-06-17 21:56 - 00087040 _____ () C:\Windows\System32\redmonnt.dll 2013-01-07 15:47 - 2012-12-07 18:26 - 00167424 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe 2013-01-21 18:51 - 2013-01-21 18:51 - 00066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2013-01-21 18:51 - 2013-01-21 18:51 - 00107832 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2011-06-19 17:37 - 2010-12-14 11:39 - 00244904 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2010-12-06 12:52 - 2010-12-06 12:52 - 00062464 _____ () C:\Program Files (x86)\watchmi\TvdService.exe 2012-04-24 22:18 - 2012-04-24 22:18 - 00061952 _____ () C:\Windows\assembly\GAC_MSIL\Tvd.Remote\2.5.0.5__f722db7bec59a14b\Tvd.Remote.dll 2012-04-24 22:18 - 2012-04-24 22:18 - 00009216 _____ () C:\Windows\assembly\GAC_MSIL\FingerPrint\1.0.0.0__a62e68e935d72fa6\FingerPrint.dll 2012-04-24 22:18 - 2012-04-24 22:18 - 00078848 _____ () C:\Windows\assembly\GAC_MSIL\Tvd.Reporting\2.5.0.5__f722db7bec59a14b\Tvd.Reporting.dll 2012-04-24 22:18 - 2012-04-24 22:18 - 00148480 _____ () C:\Windows\assembly\GAC_MSIL\Tvd.Aprico\2.5.0.5__f722db7bec59a14b\Tvd.Aprico.dll 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll 2011-06-19 16:21 - 2010-01-13 02:36 - 00117256 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe 2011-06-19 16:21 - 2010-01-13 02:36 - 00121864 ____R () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe 2011-06-19 16:21 - 2010-12-17 23:04 - 00449032 ____R () C:\Program Files (x86)\PHotkey\ATouch64.exe 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-06-19 16:21 - 2010-12-01 20:36 - 00589320 ____R () C:\Program Files (x86)\PHotkey\PVDesktop.exe 2012-12-27 17:26 - 2012-12-27 17:26 - 00169464 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe 2011-06-19 16:21 - 2010-12-01 20:37 - 00462344 ____R () C:\Program Files (x86)\PHotkey\PVDAgent.exe 2011-06-19 15:00 - 2011-04-15 10:16 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-12-06 12:52 - 2010-12-06 12:52 - 01070080 _____ () C:\Program Files (x86)\watchmi\TvdTray.exe 2010-12-06 12:52 - 2010-12-06 12:52 - 00004608 _____ () C:\Program Files (x86)\watchmi\de\TvdTray.resources.dll 2014-04-15 21:38 - 2014-04-15 20:26 - 02289664 _____ () C:\Program Files\AVAST Software\Avast\defs\14041501\algo.dll 2012-02-20 21:29 - 2012-02-20 21:29 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-02-20 21:28 - 2012-02-20 21:28 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2012-12-27 17:24 - 2012-12-27 17:24 - 00025088 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DbAccess.dll 2012-12-27 17:25 - 2012-12-27 17:25 - 00466856 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\sqlite3.dll 2012-12-27 17:25 - 2012-12-27 17:25 - 00044544 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NAdvLog.dll 2012-12-27 17:25 - 2012-12-27 17:25 - 00036368 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NFileCacheDBAccess.dll 2012-12-27 17:25 - 2012-12-27 17:25 - 00080400 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\ninstallerhelper.dll 2012-12-27 17:28 - 2012-12-27 17:28 - 00223744 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DevConnMon.dll 2014-02-24 16:36 - 2014-02-24 16:36 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\ae685719bd599604bdf031cdad0ba38a\IsdiInterop.ni.dll 2011-06-19 15:47 - 2011-04-30 09:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2011-06-24 16:55 - 2014-03-04 16:35 - 00014280 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2011-06-19 16:21 - 2009-12-19 00:36 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll 2011-06-19 16:21 - 2009-12-19 00:41 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll 2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Steffen\AppData\Roaming\Dropbox\bin\libcef.dll 2014-04-13 20:09 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2014-02-11 21:29 - 2014-02-11 21:29 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-04-13 20:09 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll 2014-04-13 20:09 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll 2014-04-13 20:09 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-13 20:09 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-13 20:09 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ksupmgr => ""="Service" ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Steffen^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EvernoteClipper.lnk => C:\Windows\pss\EvernoteClipper.lnk.Startup MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: dlcgmon.exe => "C:\Program Files (x86)\Dell AIO 810\dlcgmon.exe" MSCONFIG\startupreg: FaxCenterServer => "C:\Program Files (x86)\Dell Fax Solutions\fm3032.exe" /s MSCONFIG\startupreg: FreePDF Assistant => "C:\Program Files (x86)\FreePDF_XP\fpassist.exe" MSCONFIG\startupreg: ICQ => "C:\Program Files (x86)\ICQ7M\ICQ.exe" silent loginmode=4 MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Steffen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/15/2014 09:32:31 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (User: ) Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008] Error: (04/15/2014 06:02:25 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2293 Error: (04/15/2014 06:02:25 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2293 Error: (04/15/2014 06:02:25 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/15/2014 06:02:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1279 Error: (04/15/2014 06:02:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1279 Error: (04/15/2014 06:02:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/15/2014 01:04:55 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig. Error: (04/15/2014 01:04:55 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig. Error: (04/15/2014 00:23:26 PM) (Source: Steam Client Service) (User: ) Description: Error: Failed to poke open firewall System errors: ============= Error: (04/15/2014 11:07:21 PM) (Source: DCOM) (User: ) Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} Error: (04/15/2014 09:32:44 PM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (04/15/2014 00:29:43 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.169.2651.0) Error: (04/15/2014 00:16:51 PM) (Source: BugCheck) (User: ) Description: 0xe0010002 (0xfffffa80097df000, 0x000000000000000c, 0x0000000000000205, 0x000000000000094e)C:\Windows\MEMORY.DMP041514-26613-01 Error: (04/15/2014 00:16:36 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 15.04.2014 um 12:14:38 unerwartet heruntergefahren. Error: (04/13/2014 08:17:30 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x8007045b Error: (04/13/2014 08:03:18 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (04/13/2014 04:32:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "watchmi service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/13/2014 04:32:58 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst watchmi service erreicht. Error: (04/12/2014 06:57:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Microsoft Office Sessions: ========================= Error: (01/17/2014 10:55:17 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6683.5002, Microsoft Office Version: 12.0.6612.1000. This session lasted 2504 seconds with 2160 seconds of active time. This session ended with a crash. Error: (05/13/2013 05:42:04 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5608 seconds with 3360 seconds of active time. This session ended with a crash. Error: (12/23/2012 11:46:10 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 11395 seconds with 1320 seconds of active time. This session ended with a crash. Error: (11/15/2012 10:40:15 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 15149 seconds with 6960 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 37% Total physical RAM: 6055.05 MB Available physical RAM: 3801.21 MB Total Pagefile: 12108.29 MB Available Pagefile: 9447.01 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:657.54 GB) (Free:476.15 GB) NTFS Drive d: (Recover) (Fixed) (Total:37.99 GB) (Free:14.71 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 2BD2C32A) Partition 1: (Active) - (Size=101 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=658 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=40 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ Habe auch noch zwei Logfiles mit Funden von MWBT: Quick-Scan: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.04.15.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16659 Steffen :: STEFFEN-PC [Administrator] 15.04.2014 21:22:06 mbam-log-2014-04-15 (21-22-06).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP Deaktivierte Suchlaufeinstellungen: PUM | P2P Durchsuchte Objekte: 334488 Laufzeit: 9 Minute(n), 35 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKCU\Software\Softonic\Universal Downloader (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Vittalia\AxtanInstaller (PUP.Optional.BundleInstaller.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\Steffen\Downloads\installer_microsoft_works_update_Deutsch.exe (PUP.Optional.Vittalia) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Steffen\Downloads\Setup (2).exe (PUP.Optional.DomalQ) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.04.15.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16659 Steffen :: STEFFEN-PC [Administrator] 15.04.2014 21:58:29 MBAM-log-2014-04-15 (23-03-36).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP Deaktivierte Suchlaufeinstellungen: PUM | P2P Durchsuchte Objekte: 277445 Laufzeit: 1 Stunde(n), 4 Minute(n), 25 Sekunde(n) [Abgebrochen] Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000000 (PUP.Optional.DomalQ) -> Keine Aktion durchgeführt. (Ende) Geändert von steffen2 (16.04.2014 um 10:17 Uhr) |
17.04.2014, 09:50 | #4 |
/// the machine /// TB-Ausbilder | Emails mit Link werden verschickt: AOL hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.04.2014, 10:53 | #5 |
| Emails mit Link werden verschickt: AOL Combofix Log: Code:
ATTFilter ComboFix 14-04-12.01 - Steffen 17.04.2014 11:32:11.1.3 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6055.4002 [GMT 2:00] ausgeführt von:: c:\users\Steffen\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\Roaming c:\programdata\SPLA6C5.tmp c:\windows\Installer\{AA4D1C5E-116A-4FF4-AA91-28F526868203}\SHCT_TRAY_PROGRAMG_A10D8603999C4E9488776EF2533C58C9.exe c:\windows\security\Database\tmp.edb c:\windows\SysWow64\SWCTL.DLL c:\windows\SysWow64\win.ini . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-17 bis 2014-04-17 )))))))))))))))))))))))))))))) . . 2014-04-16 20:27 . 2014-04-16 20:27 -------- d-----r- C:\Sandbox 2014-04-16 20:25 . 2014-04-16 20:25 -------- d-----w- c:\program files\Sandboxie 2014-04-16 08:59 . 2014-04-16 09:01 -------- d-----w- C:\FRST 2014-04-15 21:07 . 2014-04-16 11:46 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F7476F17-C76B-4A55-B265-97B7DF065FF2}\offreg.dll 2014-04-15 10:32 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F7476F17-C76B-4A55-B265-97B7DF065FF2}\mpengine.dll 2014-04-14 12:19 . 2014-04-14 12:19 -------- d-----w- c:\users\Steffen\AppData\Roaming\OBS 2014-04-14 12:10 . 2014-04-14 12:10 -------- d-----w- c:\program files\OBS 2014-04-14 12:10 . 2014-04-14 12:20 -------- d-----w- c:\program files (x86)\OBS 2014-04-13 17:55 . 2014-03-31 01:16 23134208 ----a-w- c:\windows\system32\mshtml.dll 2014-04-13 17:55 . 2014-03-31 01:13 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-04-13 17:55 . 2014-03-31 00:13 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-03-19 10:07 . 2014-03-19 10:07 -------- d-----w- c:\users\Steffen\AppData\Roaming\Template 2014-03-19 09:16 . 2014-03-19 09:16 -------- d-----w- c:\program files (x86)\MSECache 2014-03-19 08:50 . 2014-03-19 08:50 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8 . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-13 18:05 . 2011-06-19 12:08 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-04 14:35 . 2014-03-15 11:22 18302384 ----a-w- c:\windows\system32\nvwgf2umx.dll 2014-03-04 14:35 . 2014-03-15 11:22 15783992 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2014-03-04 14:35 . 2014-03-15 11:22 9690424 ----a-w- c:\windows\SysWow64\nvopencl.dll 2014-03-04 14:35 . 2014-03-15 11:22 33736 ----a-w- c:\windows\system32\drivers\nvpciflt.sys 2014-03-04 14:35 . 2014-03-15 11:22 11589272 ----a-w- c:\windows\system32\nvopencl.dll 2014-03-04 14:35 . 2014-03-15 11:22 353504 ----a-w- c:\windows\system32\nvoglshim64.dll 2014-03-04 14:35 . 2014-03-15 11:22 31474976 ----a-w- c:\windows\system32\nvoglv64.dll 2014-03-04 14:35 . 2014-03-15 11:22 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll 2014-03-04 14:35 . 2014-03-15 11:22 23716640 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2014-03-04 14:35 . 2014-03-15 11:22 892704 ----a-w- c:\windows\system32\NvIFR64.dll 2014-03-04 14:35 . 2014-03-15 11:22 863064 ----a-w- c:\windows\SysWow64\NvIFR.dll 2014-03-04 14:35 . 2014-03-15 11:22 12708128 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2014-03-04 14:35 . 2014-03-15 11:22 877856 ----a-w- c:\windows\system32\NvFBC64.dll 2014-03-04 14:35 . 2014-03-15 11:22 846168 ----a-w- c:\windows\SysWow64\NvFBC.dll 2014-03-04 14:35 . 2014-03-15 11:22 3143456 ----a-w- c:\windows\system32\nvcuvid.dll 2014-03-04 14:35 . 2014-03-15 11:22 2958792 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2014-03-04 14:35 . 2014-03-15 11:22 2783008 ----a-w- c:\windows\system32\nvcuvenc.dll 2014-03-04 14:35 . 2014-03-15 11:22 1885472 ----a-w- c:\windows\system32\nvdispco6433523.dll 2014-03-04 14:35 . 2014-03-15 11:22 17755424 ----a-w- c:\windows\system32\nvd3dumx.dll 2014-03-04 14:35 . 2014-03-15 11:22 1516488 ----a-w- c:\windows\system32\nvdispgenco6433523.dll 2014-03-04 14:35 . 2014-03-15 11:22 9728064 ----a-w- c:\windows\SysWow64\nvcuda.dll 2014-03-04 14:35 . 2014-03-15 11:22 2411976 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2014-03-04 14:35 . 2014-03-15 11:22 11636176 ----a-w- c:\windows\system32\nvcuda.dll 2014-03-04 14:35 . 2014-03-15 11:22 25255256 ----a-w- c:\windows\system32\nvcompiler.dll 2014-03-04 14:35 . 2014-03-15 11:22 17561544 ----a-w- c:\windows\SysWow64\nvcompiler.dll 2014-03-04 14:35 . 2014-02-19 15:23 14709720 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2014-03-04 14:35 . 2011-06-24 14:55 947808 ----a-w- c:\windows\system32\nvumdshimx.dll 2014-03-04 14:35 . 2011-06-24 14:55 832936 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2014-03-04 14:35 . 2011-06-24 14:55 174296 ----a-w- c:\windows\system32\nvinitx.dll 2014-03-04 14:35 . 2011-06-24 14:55 148016 ----a-w- c:\windows\SysWow64\nvinit.dll 2014-03-04 14:35 . 2011-06-24 14:55 3093280 ----a-w- c:\windows\system32\nvapi64.dll 2014-03-04 14:35 . 2011-06-24 14:55 2715264 ----a-w- c:\windows\SysWow64\nvapi.dll 2014-03-04 13:06 . 2011-06-24 14:55 6714312 ----a-w- c:\windows\system32\nvcpl.dll 2014-03-04 13:06 . 2011-06-24 14:55 3497816 ----a-w- c:\windows\system32\nvsvc64.dll 2014-03-04 13:05 . 2011-06-24 14:55 922968 ----a-w- c:\windows\system32\nvvsvc.exe 2014-03-04 13:05 . 2011-06-24 14:55 64968 ----a-w- c:\windows\system32\nvshext.dll 2014-03-04 13:05 . 2011-06-24 14:55 2558808 ----a-w- c:\windows\system32\nvsvcr.dll 2014-03-04 13:05 . 2011-06-24 14:55 67072 ----a-w- c:\windows\system32\nv3dappshextr.dll 2014-03-04 13:05 . 2011-06-24 14:55 386336 ----a-w- c:\windows\system32\nvmctray.dll 2014-03-04 13:05 . 2011-06-24 14:55 1075032 ----a-w- c:\windows\system32\nv3dappshext.dll 2014-03-04 13:05 . 2011-06-24 14:55 3649185 ----a-w- c:\windows\system32\nvcoproc.bin 2014-03-04 11:32 . 2014-03-15 11:30 599840 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2014-03-04 09:17 . 2014-04-13 17:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-01 05:16 . 2014-03-13 13:31 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-01 04:58 . 2014-03-13 13:31 2765824 ----a-w- c:\windows\system32\iertutil.dll 2014-03-01 04:52 . 2014-03-13 13:31 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-01 04:51 . 2014-03-13 13:31 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-01 04:42 . 2014-03-13 13:30 53760 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-01 04:40 . 2014-03-13 13:31 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-01 04:37 . 2014-03-13 13:30 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-01 04:33 . 2014-03-13 13:30 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-01 04:33 . 2014-03-13 13:30 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-01 04:32 . 2014-03-13 13:30 708608 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-01 04:23 . 2014-03-13 13:30 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-01 04:17 . 2014-03-13 13:31 218624 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-01 04:02 . 2014-03-13 13:30 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-01 03:54 . 2014-03-13 13:30 5768704 ----a-w- c:\windows\system32\jscript9.dll 2014-03-01 03:52 . 2014-03-13 13:31 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-01 03:51 . 2014-03-13 13:31 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-01 03:42 . 2014-03-13 13:31 627200 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-01 03:38 . 2014-03-13 13:30 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-01 03:37 . 2014-03-13 13:31 553472 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-01 03:35 . 2014-03-13 13:30 2041856 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-01 03:18 . 2014-03-13 13:30 13051904 ----a-w- c:\windows\system32\ieframe.dll 2014-03-01 03:14 . 2014-03-13 13:30 4244480 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-01 03:10 . 2014-03-13 13:30 2334208 ----a-w- c:\windows\system32\wininet.dll 2014-03-01 03:00 . 2014-03-13 13:31 1964032 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-01 02:38 . 2014-03-13 13:31 1393664 ----a-w- c:\windows\system32\urlmon.dll 2014-03-01 02:32 . 2014-03-13 13:30 1820160 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-01 02:25 . 2014-03-13 13:30 817664 ----a-w- c:\windows\system32\ieapfltr.dll 2014-02-16 13:37 . 2014-02-16 13:28 227 ----a-w- c:\users\Steffen\sicherung.bat 2014-02-08 18:34 . 2014-02-19 15:23 1885472 ----a-w- c:\windows\system32\nvdispco6433489.dll 2014-02-08 18:34 . 2014-02-19 15:23 1515296 ----a-w- c:\windows\system32\nvdispgenco6433489.dll 2014-02-07 01:23 . 2014-03-13 13:31 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-13 13:27 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-13 13:28 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-13 13:27 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-13 13:28 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 02:32 . 2014-03-13 13:31 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-13 13:31 381440 ----a-w- c:\windows\SysWow64\wer.dll 2014-01-28 02:32 . 2014-03-13 13:31 228864 ----a-w- c:\windows\system32\wwansvc.dll 2014-01-21 02:54 . 2014-02-03 20:11 1048152 ----a-w- c:\windows\SysWow64\nvspcap.dll 2014-01-21 02:54 . 2014-02-03 20:11 1179576 ----a-w- c:\windows\system32\nvspcap64.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spotify Web Helper"="c:\users\Steffen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-01-17 1171968] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-04-24 39408] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2014-01-17 759496] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-04-14 113288] "Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2011-02-03 506712] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "ChicoSys"="c:\windows\SysWOW64\cc32\webtmr.exe" [2009-07-13 5528984] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392] . c:\users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Steffen\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 30714328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer9"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli c:\program files\Protector Suite\psqlpwd.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ksupmgr] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 ksupmgr;File-/Update-Service V1.0;c:\windows\SysWOW64\ksupmgr.exe;c:\windows\SysWOW64\ksupmgr.exe [x] R3 AMPPALP;Intel(R) Centrino(R) Bluetooth 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 btmaudio;Intel Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys;c:\windows\SYSNATIVE\drivers\btmaud.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 fspad_wlh64;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_wlh64;c:\windows\system32\DRIVERS\fspad_wlh64.sys;c:\windows\SYSNATIVE\DRIVERS\fspad_wlh64.sys [x] R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys;c:\windows\SYSNATIVE\drivers\intelaud.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 RSUSBVSTOR;RTSUVSTOR.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys;c:\windows\SYSNATIVE\Drivers\RTSUVSTOR.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys;c:\windows\SYSNATIVE\DRIVERS\tinspusb.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys;c:\windows\SYSNATIVE\drivers\acedrv11.sys [x] S2 AMPPALR3;Intel® Centrino® Bluetooth 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x] S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 GFNEXSrv;GFNEX Service;c:\program files (x86)\PHotkey\GFNEXSrv.exe;c:\program files (x86)\PHotkey\GFNEXSrv.exe [x] S2 HTCMonitorService;HTCMonitorService;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe;c:\program files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x] S2 PEGAGFN;PEGAGFN;c:\program files (x86)\PHotkey\PEGAGFN.sys;c:\program files (x86)\PHotkey\PEGAGFN.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 watchmi;watchmi service;c:\program files (x86)\watchmi\TvdService.exe;c:\program files (x86)\watchmi\TvdService.exe [x] S3 AMPPAL;Intel(R) Centrino(R) Bluetooth 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x] S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x] S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\drivers\iwdbus.sys;c:\windows\SYSNATIVE\drivers\iwdbus.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - SBIEDRV . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-13 17:56 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24 20:15] . 2014-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24 20:15] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 164016 ----a-w- c:\users\Steffen\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay] @="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}" [HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}] 2010-12-10 09:59 5267792 ----a-w- c:\program files\Protector Suite\farchns.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen] @="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}" [HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}] 2010-12-10 09:59 5267792 ----a-w- c:\program files\Protector Suite\farchns.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-04-19 11817576] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-04-18 2209896] "BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-02-11 10361616] "PSQLLauncher"="c:\program files\Protector Suite\launcher.exe" [2010-12-10 84816] "DLCGCATS"="c:\windows\system32\spool\DRIVERS\x64\3\DLCGtime.dll" [2006-10-20 28672] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-01-21 2234144] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-01-21 1179576] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.aldi.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: Free YouTube to MP3 Converter - c:\users\Steffen\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4 IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default\ FF - user.js: extensions.autoDisableScopes - 10 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\watchmi tray.lnk - c:\windows\Installer\{AA4D1C5E-116A-4FF4-AA91-28F526868203}\SHCT_TRAY_PROGRAMG_A10D8603999C4E9488776EF2533C58C9.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ChromeHTML" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-17 11:49:05 ComboFix-quarantined-files.txt 2014-04-17 09:49 . Vor Suchlauf: 13 Verzeichnis(se), 512.320.077.824 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 512.651.272.192 Bytes frei . - - End Of File - - C6A384179B67738118D17ED6C3107302 Schonmal vielen Dank für deine Hilfe Gruß Steffen |
18.04.2014, 09:49 | #6 |
/// the machine /// TB-Ausbilder | Emails mit Link werden verschickt: AOL Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Emails mit Link werden verschickt: AOL |
19.04.2014, 09:04 | #7 |
| Emails mit Link werden verschickt: AOL Sooo, MwBt: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 18.04.2014 Suchlauf-Zeit: 20:11:39 Logdatei: MWBT.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.18.06 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Steffen Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 401340 Verstrichene Zeit: 1 Std, 57 Min, 39 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) AdwC-Log: Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 23:12:34 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Steffen - STEFFEN-PC # Gestartet von : C:\Users\Steffen\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\boost_interprocess Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\Users\Steffen\AppData\Local\CrashRpt Ordner Gelöscht : C:\Users\Steffen\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Steffen\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Steffen\AppData\Roaming\software4u Datei Gelöscht : C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\pricegong_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\pricegong_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_sweet-home-3d_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_sweet-home-3d_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\powerpack Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\Software\Vittalia ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default\prefs.js ] [ Datei : C:\Users\Party\AppData\Roaming\Mozilla\Firefox\Profiles\tb5ih3x2.default\prefs.js ] -\\ Google Chrome v34.0.1847.116 [ Datei : C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\preferences ] [ Datei : C:\Users\Sicherung\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2669 octets] - [18/04/2014 23:09:55] AdwCleaner[S0].txt - [2399 octets] - [18/04/2014 23:12:34] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2459 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Steffen on 18.04.2014 at 23:24:21,96 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{09C25C54-685C-463B-A20F-71868E1D9FBD} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{1979B67C-7984-42FE-B500-C2D0FE6C6287} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{3C20A8D5-E364-40F7-8C40-A5C6920F6127} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{801D93A2-39CE-442F-9812-FCFA35E14239} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{96AE2B6C-394F-47BE-A9CE-03B492384364} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{A7E364F1-6EF1-45D4-B00D-2BDEEF57AD16} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{A9724A64-A448-4173-8A89-9E131A988F1F} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{C2EEEA91-96E3-499A-A3B7-5D8BBD628A4B} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{DAE3BA6D-967F-429A-9E6F-A125E406F378} Successfully deleted: [Empty Folder] C:\Users\Steffen\appdata\local\{F9A840AA-3893-4C32-BB74-5117AD570706} ~~~ FireFox Emptied folder: C:\Users\Steffen\AppData\Roaming\mozilla\firefox\profiles\5yp8reie.default\minidumps [35 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18.04.2014 at 23:38:17,84 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by Steffen (administrator) on STEFFEN-PC on 18-04-2014 23:39:56 Running from C:\Users\Steffen\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe ( ) C:\Windows\system32\dlcgcoms.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Salfeld Computer) C:\Windows\SysWOW64\cchservice.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe (Pegatron Corporation) C:\Program Files (x86)\PHotkey\PHotkey.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Salfeld Computer) C:\Windows\SysWOW64\cc32\webtmr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe () C:\Windows\SysWOW64\PnkBstrA.exe () C:\Windows\SysWOW64\PnkBstrB.exe (Protexis Inc.) c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files (x86)\watchmi\TvdService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE () C:\Program Files (x86)\PHotkey\ATouch64.exe () C:\Program Files (x86)\PHotkey\PVDesktop.exe () C:\Program Files (x86)\PHotkey\PVDAgent.exe (Pegatron Corporation) C:\Program Files (x86)\PHotkey\POSD.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Spotify Ltd) C:\Users\Steffen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe (UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Dropbox, Inc.) C:\Users\Steffen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11817576 2011-04-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2209896 2011-04-18] (Realtek Semiconductor) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [10361616 2011-02-11] (Intel Corporation) HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [84816 2010-12-10] (UPEK Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated) HKLM\...\Run: [DLCGCATS] => C:\Windows\system32\spool\DRIVERS\x64\3\DLCGtime.dll [28672 2006-10-21] () HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [ChicoSys] => C:\Windows\SysWOW64\cc32\webtmr.exe [5528984 2009-07-14] (Salfeld Computer) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Run: [Spotify Web Helper] => C:\Users\Steffen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-17] (Spotify Ltd) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2012-04-24] (Google Inc.) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3580909774-2373009125-3570030466-1002\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174296 2014-03-04] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2014-03-04] (NVIDIA Corporation) Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll Startup: C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Steffen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) GroupPolicyUsers\S-1-5-21-3580909774-2373009125-3570030466-1056\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.aldi.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: OLB - C:\Users\Steffen\AppData\Roaming\Mozilla\Firefox\Profiles\5yp8reie.default\Extensions\{C752FF21-A8EF-468E-B507-5BBAFB84359D} [2014-03-23] FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-04-21] Chrome: ======= CHR HomePage: hxxp://www.google.com/ig/redirectdomain?brand=MDNC&bmod=MDNC CHR StartupUrls: "hxxp://www.google.de/" CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (AVG Internet Security) - C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Extension: (Internet Banking der OLB) - C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\Extensions\fipffogddddpcmkklaodlnofkmpognml [2014-02-13] CHR Extension: (Google Wallet) - C:\Users\Steffen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-04] ==================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-19] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 dlcg_device; C:\Windows\system32\dlcgcoms.exe [566152 2006-12-08] ( ) R2 dlcg_device; C:\Windows\SysWOW64\dlcgcoms.exe [537480 2006-12-08] ( ) R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-07] () R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2012-12-12] (Nero AG) S2 ksupmgr; C:\Windows\SysWOW64\ksupmgr.exe [765592 2010-08-25] (Salfeld Computer) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [267824 2007-03-26] (Nero AG) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2013-01-21] () R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2013-01-21] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-12-14] () R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC) R2 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [62464 2010-12-06] () ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-07] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-07] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-07] () R3 com0com; C:\Windows\System32\DRIVERS\com0com.sys [76800 2011-01-25] (Vyacheslav Frolov) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation) R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [204568 2013-08-20] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2012-06-11] (Texas Instruments) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 RSUSBVSTOR; System32\Drivers\RTSUVSTOR.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 23:39 - 2014-04-18 23:39 - 00021041 _____ () C:\Users\Steffen\Desktop\FRST.txt 2014-04-18 23:39 - 2014-04-18 23:39 - 00000000 ____D () C:\Users\Steffen\Desktop\FRST-OlderVersion 2014-04-18 23:38 - 2014-04-18 23:38 - 00001843 _____ () C:\Users\Steffen\Desktop\JRT.txt 2014-04-18 23:23 - 2014-04-18 23:23 - 01016261 _____ (Thisisu) C:\Users\Steffen\Desktop\JRT.exe 2014-04-18 23:20 - 2014-04-18 23:20 - 00002539 _____ () C:\Users\Steffen\Desktop\AdwCleaner[S0].txt 2014-04-18 23:20 - 2014-04-18 23:20 - 00000000 ____D () C:\Users\Steffen\Desktop\Scans 2014-04-18 23:09 - 2014-04-18 23:12 - 00000000 ____D () C:\AdwCleaner 2014-04-18 23:09 - 2014-04-18 23:09 - 00001158 _____ () C:\Users\Steffen\Desktop\MWBT.txt 2014-04-18 18:27 - 2014-04-18 18:27 - 01426178 _____ () C:\Users\Steffen\Desktop\adwcleaner.exe 2014-04-18 18:11 - 2014-04-18 18:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-18 18:11 - 2014-04-18 18:11 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 18:11 - 2014-04-18 18:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-18 18:11 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-18 18:11 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-18 18:11 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-18 18:09 - 2014-04-18 18:09 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Steffen\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-17 11:57 - 2014-04-18 23:17 - 00000150 _____ () C:\Windows\SysWOW64\SWCTL.DLL 2014-04-17 11:57 - 2014-04-18 18:03 - 00000918 _____ () C:\Windows\PFRO.log 2014-04-17 11:27 - 2014-04-17 11:49 - 00000000 ____D () C:\Qoobox 2014-04-17 11:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-17 11:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-17 11:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-17 11:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-17 11:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-17 11:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-17 11:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-17 11:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-17 11:26 - 2014-04-17 11:47 - 00000000 ____D () C:\Windows\erdnt 2014-04-17 11:23 - 2014-04-17 11:23 - 05194807 ____R (Swearware) C:\Users\Steffen\Desktop\ComboFix.exe 2014-04-17 11:22 - 2014-04-17 11:23 - 05194807 _____ (Swearware) C:\Users\Steffen\Downloads\ComboFix.exe 2014-04-16 22:27 - 2014-04-16 22:27 - 00000000 ___RD () C:\Sandbox 2014-04-16 22:26 - 2014-04-18 18:06 - 00001916 _____ () C:\Windows\Sandboxie.ini 2014-04-16 22:26 - 2014-04-16 22:25 - 00000918 _____ () C:\Users\Steffen\Desktop\Sandboxed Web Browser.lnk 2014-04-16 22:25 - 2014-04-16 22:25 - 00000000 ____D () C:\Program Files\Sandboxie 2014-04-16 22:24 - 2014-04-16 22:25 - 02605768 _____ (Sandboxie Holdings, LLC) C:\Users\Steffen\Downloads\SandboxieInstall_4.0.8.exe 2014-04-16 21:12 - 2014-04-18 23:15 - 00000616 _____ () C:\Windows\setupact.log 2014-04-16 21:12 - 2014-04-16 21:12 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-16 10:59 - 2014-04-18 23:39 - 00000000 ____D () C:\FRST 2014-04-16 10:58 - 2014-04-18 23:39 - 02158592 _____ (Farbar) C:\Users\Steffen\Desktop\FRST64.exe 2014-04-14 14:19 - 2014-04-14 14:19 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\OBS 2014-04-14 14:18 - 2014-04-14 14:18 - 00000044 _____ () C:\Users\Steffen\Desktop\key.txt 2014-04-14 14:10 - 2014-04-14 14:20 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-04-14 14:10 - 2014-04-14 14:10 - 00000943 _____ () C:\Users\Steffen\Desktop\Open Broadcaster Software.lnk 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Program Files\OBS 2014-04-14 14:09 - 2014-04-14 14:10 - 07888419 _____ () C:\Users\Steffen\Downloads\OBS_0_613b_Installer.exe 2014-04-13 19:55 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-13 19:55 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-13 19:55 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 19:55 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-13 19:54 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-13 19:54 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-13 19:54 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-13 19:54 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-13 19:54 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-13 19:54 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-13 19:54 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-13 19:54 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-13 19:54 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-13 19:54 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-13 19:54 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-13 19:54 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-13 19:54 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-31 13:47 - 2014-03-31 13:47 - 00000000 ____D () C:\Users\Steffen\Desktop\Steffen 2014-03-31 13:32 - 2014-03-31 13:32 - 00001727 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 142.odb 2014-03-27 16:06 - 2014-03-27 16:06 - 00000000 ____D () C:\Users\Steffen\Desktop\Stick123 2014-03-23 17:00 - 2014-03-23 17:00 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 141.odb 2014-03-23 16:57 - 2014-03-23 16:57 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 140.odb 2014-03-23 14:09 - 2014-03-23 16:56 - 00000000 ____D () C:\Users\Steffen\Desktop\USB-Stick 2014-03-22 20:26 - 2014-03-22 20:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair.htm 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair (1).htm 2014-03-19 12:07 - 2014-03-19 12:07 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Template 2014-03-19 11:16 - 2014-03-19 11:16 - 01484080 _____ (Microsoft Corporation) C:\Users\Steffen\Downloads\WorksConv.exe 2014-03-19 11:16 - 2014-03-19 11:16 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-03-19 11:10 - 2014-03-19 11:10 - 04745216 _____ () C:\Users\Steffen\Downloads\Works632_de-DE.msi 2014-03-19 10:50 - 2014-03-19 10:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 ==================== One Month Modified Files and Folders ======= 2014-04-18 23:40 - 2014-04-18 23:39 - 00021041 _____ () C:\Users\Steffen\Desktop\FRST.txt 2014-04-18 23:39 - 2014-04-18 23:39 - 00000000 ____D () C:\Users\Steffen\Desktop\FRST-OlderVersion 2014-04-18 23:39 - 2014-04-16 10:59 - 00000000 ____D () C:\FRST 2014-04-18 23:39 - 2014-04-16 10:58 - 02158592 _____ (Farbar) C:\Users\Steffen\Desktop\FRST64.exe 2014-04-18 23:38 - 2014-04-18 23:38 - 00001843 _____ () C:\Users\Steffen\Desktop\JRT.txt 2014-04-18 23:24 - 2013-04-21 19:51 - 00000000 ____D () C:\Windows\ERUNT 2014-04-18 23:24 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 23:24 - 2009-07-14 06:45 - 00016752 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 23:23 - 2014-04-18 23:23 - 01016261 _____ (Thisisu) C:\Users\Steffen\Desktop\JRT.exe 2014-04-18 23:20 - 2014-04-18 23:20 - 00002539 _____ () C:\Users\Steffen\Desktop\AdwCleaner[S0].txt 2014-04-18 23:20 - 2014-04-18 23:20 - 00000000 ____D () C:\Users\Steffen\Desktop\Scans 2014-04-18 23:19 - 2013-04-21 21:35 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Dropbox 2014-04-18 23:18 - 2013-04-21 21:37 - 00000000 ___RD () C:\Users\Steffen\Dropbox 2014-04-18 23:17 - 2014-04-17 11:57 - 00000150 _____ () C:\Windows\SysWOW64\SWCTL.DLL 2014-04-18 23:15 - 2014-04-16 21:12 - 00000616 _____ () C:\Windows\setupact.log 2014-04-18 23:15 - 2013-01-07 15:49 - 00000000 ____D () C:\Users\Steffen\AppData\Local\HTC MediaHub 2014-04-18 23:15 - 2012-04-24 22:15 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-18 23:14 - 2011-06-24 16:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-18 23:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-18 23:13 - 2012-07-19 14:27 - 01701069 _____ () C:\Windows\WindowsUpdate.log 2014-04-18 23:12 - 2014-04-18 23:09 - 00000000 ____D () C:\AdwCleaner 2014-04-18 23:09 - 2014-04-18 23:09 - 00001158 _____ () C:\Users\Steffen\Desktop\MWBT.txt 2014-04-18 23:03 - 2012-04-24 22:15 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-18 18:27 - 2014-04-18 18:27 - 01426178 _____ () C:\Users\Steffen\Desktop\adwcleaner.exe 2014-04-18 18:14 - 2014-04-18 18:11 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-18 18:11 - 2014-04-18 18:11 - 00001110 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-18 18:11 - 2014-04-18 18:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-18 18:11 - 2012-05-27 23:27 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-18 18:11 - 2011-06-19 19:00 - 00703176 _____ () C:\Windows\system32\perfh007.dat 2014-04-18 18:11 - 2011-06-19 19:00 - 00150784 _____ () C:\Windows\system32\perfc007.dat 2014-04-18 18:10 - 2009-07-14 07:13 - 01629276 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-18 18:09 - 2014-04-18 18:09 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Steffen\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-18 18:06 - 2014-04-16 22:26 - 00001916 _____ () C:\Windows\Sandboxie.ini 2014-04-18 18:03 - 2014-04-17 11:57 - 00000918 _____ () C:\Windows\PFRO.log 2014-04-18 17:55 - 2013-04-21 20:27 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-04-17 15:57 - 2013-02-08 23:21 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-04-17 15:17 - 2014-02-03 17:17 - 00000000 ____D () C:\Users\Steffen\AppData\Local\DayZ 2014-04-17 11:49 - 2014-04-17 11:27 - 00000000 ____D () C:\Qoobox 2014-04-17 11:49 - 2014-02-01 18:31 - 00185856 ___SH () C:\Users\Steffen\Desktop\Thumbs.db 2014-04-17 11:47 - 2014-04-17 11:26 - 00000000 ____D () C:\Windows\erdnt 2014-04-17 11:45 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-17 11:23 - 2014-04-17 11:23 - 05194807 ____R (Swearware) C:\Users\Steffen\Desktop\ComboFix.exe 2014-04-17 11:23 - 2014-04-17 11:22 - 05194807 _____ (Swearware) C:\Users\Steffen\Downloads\ComboFix.exe 2014-04-16 22:27 - 2014-04-16 22:27 - 00000000 ___RD () C:\Sandbox 2014-04-16 22:25 - 2014-04-16 22:26 - 00000918 _____ () C:\Users\Steffen\Desktop\Sandboxed Web Browser.lnk 2014-04-16 22:25 - 2014-04-16 22:25 - 00000000 ____D () C:\Program Files\Sandboxie 2014-04-16 22:25 - 2014-04-16 22:24 - 02605768 _____ (Sandboxie Holdings, LLC) C:\Users\Steffen\Downloads\SandboxieInstall_4.0.8.exe 2014-04-16 21:12 - 2014-04-16 21:12 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-16 14:12 - 2013-04-01 14:01 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\TS3Client 2014-04-16 14:10 - 2014-02-11 17:40 - 00000000 ____D () C:\Windows\Minidump 2014-04-14 16:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-14 14:20 - 2014-04-14 14:10 - 00000000 ____D () C:\Program Files (x86)\OBS 2014-04-14 14:19 - 2014-04-14 14:19 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\OBS 2014-04-14 14:18 - 2014-04-14 14:18 - 00000044 _____ () C:\Users\Steffen\Desktop\key.txt 2014-04-14 14:10 - 2014-04-14 14:10 - 00000943 _____ () C:\Users\Steffen\Desktop\Open Broadcaster Software.lnk 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software 2014-04-14 14:10 - 2014-04-14 14:10 - 00000000 ____D () C:\Program Files\OBS 2014-04-14 14:10 - 2014-04-14 14:09 - 07888419 _____ () C:\Users\Steffen\Downloads\OBS_0_613b_Installer.exe 2014-04-14 12:23 - 2012-05-12 12:37 - 00000000 ____D () C:\Program Files\Dl_cats 2014-04-13 22:44 - 2013-08-09 16:06 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Spotify 2014-04-13 22:39 - 2012-07-06 22:39 - 00000000 ____D () C:\Users\Steffen\AppData\Local\Spotify 2014-04-13 20:10 - 2012-04-27 12:41 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-13 20:09 - 2013-07-13 11:39 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-13 20:09 - 2012-04-24 22:16 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-13 20:05 - 2011-06-19 14:08 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-12 18:54 - 2013-06-03 17:26 - 00000000 ____D () C:\Users\Steffen\AppData\Local\CyberLink 2014-04-04 19:00 - 2006-01-01 14:27 - 00000000 ____D () C:\Users\Steffen\Desktop\DCIM 2014-04-03 09:51 - 2014-04-18 18:11 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-18 18:11 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-18 18:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 14:51 - 2013-04-24 15:32 - 00000000 ____D () C:\Users\Steffen\Documents\VirtualDJ 2014-04-02 14:22 - 2014-02-12 19:30 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\FileZilla 2014-03-31 13:47 - 2014-03-31 13:47 - 00000000 ____D () C:\Users\Steffen\Desktop\Steffen 2014-03-31 13:32 - 2014-03-31 13:32 - 00001727 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 142.odb 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-13 19:55 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-13 19:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-13 19:55 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-13 19:55 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 13:58 - 2012-04-24 22:15 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-29 13:58 - 2012-04-24 22:15 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 13:34 - 2012-07-01 19:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-27 16:06 - 2014-03-27 16:06 - 00000000 ____D () C:\Users\Steffen\Desktop\Stick123 2014-03-23 17:04 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2014-03-23 17:00 - 2014-03-23 17:00 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 141.odb 2014-03-23 16:57 - 2014-03-23 16:57 - 00001724 _____ () C:\Users\Steffen\Documents\Tabelle Stadtturnfest 140.odb 2014-03-23 16:56 - 2014-03-23 14:09 - 00000000 ____D () C:\Users\Steffen\Desktop\USB-Stick 2014-03-22 21:07 - 2014-01-27 18:03 - 00000000 ____D () C:\Users\Steffen\Desktop\Facharbeit 2014-03-22 20:27 - 2014-03-22 20:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-22 19:25 - 2012-04-24 22:23 - 00153904 _____ () C:\Users\Steffen\AppData\Local\GDIPFONTCACHEV1.DAT 2014-03-22 19:22 - 2009-07-14 06:45 - 05160968 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair.htm 2014-03-21 15:04 - 2014-03-21 15:04 - 00036054 _____ () C:\Users\Steffen\Downloads\download_repair (1).htm 2014-03-19 12:07 - 2014-03-19 12:07 - 00000000 ____D () C:\Users\Steffen\AppData\Roaming\Template 2014-03-19 11:40 - 2012-04-29 12:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works 2014-03-19 11:16 - 2014-03-19 11:16 - 01484080 _____ (Microsoft Corporation) C:\Users\Steffen\Downloads\WorksConv.exe 2014-03-19 11:16 - 2014-03-19 11:16 - 00000000 ____D () C:\Program Files (x86)\MSECache 2014-03-19 11:10 - 2014-03-19 11:10 - 04745216 _____ () C:\Users\Steffen\Downloads\Works632_de-DE.msi 2014-03-19 10:53 - 2012-04-29 12:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office 2014-03-19 10:53 - 2011-04-12 10:28 - 00000000 ____D () C:\Windows\ShellNew 2014-03-19 10:53 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-03-19 10:50 - 2014-03-19 10:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8 Files to move or delete: ==================== C:\Users\Steffen\AppData\Roaming\CamLayout.ini C:\Users\Steffen\AppData\Roaming\CamShapes.ini C:\Users\Steffen\sicherung.bat Some content of TEMP: ==================== C:\Users\Steffen\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-14 16:46 ==================== End Of Log ============================ --- --- --- Gruß Steffen Hallo, muss noch einmal was ergänzen: Heute morgen wurden wieder einmal Emails verschickt, obwohl Computer nicht an war. Könnte es vielleicht auch am Handy liegen? Achja und Passwort habe ich auch schon öfters wieder geändert. Gruß Steffen |
19.04.2014, 19:35 | #8 |
/// the machine /// TB-Ausbilder | Emails mit Link werden verschickt: AOL Könnte. Email Account auf dem Handy mal löschen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicyUsers\S-1-5-21-3580909774-2373009125-3570030466-1056\User: Group Policy restriction detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.04.2014, 10:06 | #9 |
| Emails mit Link werden verschickt: AOL Hi, Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-04-2014 Ran by Steffen at 2014-04-19 21:29:18 Run:1 Running from C:\Users\Steffen\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicyUsers\S-1-5-21-3580909774-2373009125-3570030466-1056\User: Group Policy restriction detected <======= ATTENTION ***************** C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3580909774-2373009125-3570030466-1056\User => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6844 # api_version=3.0.2 # EOSSerial=a234bbf46e66e844b2396542bbbae6d7 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-01-10 05:58:38 # local_time=2013-01-10 06:58:38 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1036 16777214 0 1 19699064 22383619 0 0 # compatibility_mode=1799 16775165 100 98 6042 223264008 1098 0 # compatibility_mode=5893 16776574 100 94 8542801 109470568 0 0 # scanned=25615 # found=0 # cleaned=0 # scan_time=1340 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a234bbf46e66e844b2396542bbbae6d7 # engine=13649 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-18 09:00:18 # local_time=2013-04-18 11:00:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1036 16777214 0 1 28177164 30861719 0 0 # compatibility_mode=1799 16775165 100 98 19481 231742108 12257 0 # compatibility_mode=5893 16776574 100 94 17020901 117948668 0 0 # scanned=234715 # found=1 # cleaned=0 # scan_time=10385 sh=2C1931D7FA11E0C8B646EDFCDADD2AB85FE83391 ft=0 fh=0000000000000000 vn="Win32/Ponmocup.AA trojan" ac=I fn="C:\Users\Steffen\Downloads\goog1e_kamera_run_slider.zip" ESETSmartInstaller@High as downloader log: all ok Aus irgendeinem Grund konnte ich die aktuelle Version von SecurityCheck nicht downloaden, habe dann die ältere Version gewählt. Checkup: Code:
ATTFilter Results of screen317's Security Check version 0.99.81 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 51 Adobe Flash Player 11.7.700.202 Flash Player out of Date! Mozilla Firefox (28.0) Google Chrome 33.0.1750.154 Google Chrome 34.0.1847.116 ````````Process Check: objlist.exe by Laurent```````` system32 AvastSvc.exe -?- system32 AvastUI.exe -?- AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Auf jeden Fall schon einmal vielen Dank für deine kompetente Hilfe! Das Forum ist echt super Gruß Steffen |
20.04.2014, 18:32 | #10 |
/// the machine /// TB-Ausbilder | Emails mit Link werden verschickt: AOL Den einen Download den ESET anmeckert löschen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Emails mit Link werden verschickt: AOL |
email, emails, gemerkt, heute, kontakte, laptop, link, mails, nichts, ordner, outlook, pup.optional.bundleinstaller.a, pup.optional.domalq, pup.optional.softonic.a, pup.optional.vittalia, verschickt, versendet |