|
Log-Analyse und Auswertung: Mail-Anhang wurde geöffnet 11-suche.xml (Win.Trojan.Agent-516645, Win.Trojan.Delf-12000)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.04.2014, 22:18 | #1 |
| Mail-Anhang wurde geöffnet 11-suche.xml (Win.Trojan.Agent-516645, Win.Trojan.Delf-12000) Hallo, wie im Titel beschrieben, wurde ein Mail-Anhang "11-suche.xml" geöffnet. Leider wurden schon einige Versuche unternommen Schadsoftware von diesem infizierten Rechner zu entfernen, mein Halbwissen lässt vermuten dass sich noch andere unbeliebten Gäste auf diesem Rechner breit gemacht haben. Ich habe versucht die log-Dateien der unterschiedlichen Entfernungssoftware zusammenzutragen. Vielleicht lässt sich noch etwas retten, nach Möglichkeit möchte ich eine Neuinstallation umgehen. Folgende Log-Dateien wurden chronologisch (älteste zuerst) sortiert. clamav 13.04.2014 11:49 (auf FOUNDS gekürzt) Code:
ATTFilter /mnt/sda2/Users/steffen/AppData/Roaming/Thunderbird/Profiles/yeiq49ps.default/Mail/pop3.web.de/Inbox: Heuristics.Phishing.Email.SpoofedDomainFOUND /mnt/sda2/Users/steffen/AppData/Roaming/Thunderbird/Profiles/yeiq49ps.default/Mail/pop3.web.de/Trash: Heuristics.Phishing.Email.SpoofedDomain FOUND /mnt/sda2/Program Files (x86)/InstallShield Installation Information/{F193FC0E-9E18-40FC-A974-509A1BDD240A}/ISSetup.dll: Win.Trojan.Agent-516645 FOUND /mnt/sda2/Program Files (x86)/InstallShield Installation Information/{F193FC0E-9E18-40FC-A974-509A1BDD240A}/setup.exe: Win.Trojan.Agent-516645 FOUND /mnt/sda2/Program Files (x86)/Samsung/Samsung New PC Studio/NPSCDRipper.exe: Win.Trojan.Delf-12000 FOUND TDSSKiller 14.04.2014 08:55 Code:
ATTFilter 20:39:50.0520 0x0b4c TDSS rootkit removing tool 3.0.0.31 Apr 11 2014 08:55:10 20:39:57.0540 0x0b4c ============================================================ 20:39:57.0540 0x0b4c Current date / time: 2014/04/14 20:39:57.0540 20:39:57.0540 0x0b4c SystemInfo: 20:39:57.0540 0x0b4c 20:39:57.0540 0x0b4c OS Version: 6.1.7601 ServicePack: 1.0 20:39:57.0540 0x0b4c Product type: Workstation 20:39:57.0540 0x0b4c ComputerName: STEFFEN-HP 20:39:57.0540 0x0b4c UserName: steffen 20:39:57.0540 0x0b4c Windows directory: C:\Windows 20:39:57.0540 0x0b4c System windows directory: C:\Windows 20:39:57.0540 0x0b4c Running under WOW64 20:39:57.0540 0x0b4c Processor architecture: Intel x64 20:39:57.0540 0x0b4c Number of processors: 2 20:39:57.0540 0x0b4c Page size: 0x1000 20:39:57.0540 0x0b4c Boot type: Normal boot 20:39:57.0540 0x0b4c ============================================================ 20:40:07.0306 0x0b4c KLMD registered as C:\Windows\system32\drivers\87199212.sys 20:40:29.0504 0x0b4c System UUID: {749449C3-4E9F-E536-ECE5-26B29C0EAF45} 20:40:39.0800 0x0b4c Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 20:40:45.0260 0x0b4c Drive \Device\Harddisk1\DR1 - Size: 0x1D1A00000 (7.28 Gb), SectorSize: 0x200, Cylinders: 0x3B5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 20:40:45.0276 0x0b4c ============================================================ 20:40:45.0276 0x0b4c \Device\Harddisk0\DR0: 20:40:45.0292 0x0b4c MBR partitions: 20:40:45.0292 0x0b4c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800 20:40:45.0292 0x0b4c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x234EB800 20:40:45.0292 0x0b4c \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x2354F800, BlocksNum 0x1EAB000 20:40:45.0292 0x0b4c \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x253FA800, BlocksNum 0x33AB0 20:40:45.0292 0x0b4c \Device\Harddisk1\DR1: 20:40:45.0292 0x0b4c MBR partitions: 20:40:45.0292 0x0b4c \Device\Harddisk1\DR1\Partition1: MBR, Type 0xB, StartLBA 0x800, BlocksNum 0xE8C800 20:40:45.0292 0x0b4c ============================================================ 20:40:45.0463 0x0b4c C: <-> \Device\Harddisk0\DR0\Partition2 20:40:45.0526 0x0b4c D: <-> \Device\Harddisk0\DR0\Partition3 20:40:45.0572 0x0b4c H: <-> \Device\Harddisk0\DR0\Partition4 20:40:45.0572 0x0b4c ============================================================ 20:40:45.0572 0x0b4c Initialize success 20:40:45.0572 0x0b4c ============================================================ 20:40:50.0954 0x0f98 Deinitialize success AdwCleaner 14.04.2014 20:45 Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 14/04/2014 um 20:45:11 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : steffen - STEFFEN-HP # Gestartet von : C:\___\Anti\AdwCleaner.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\Users\steffen\AppData\Roaming\Mozilla\Firefox\Profiles\9smjhw2i.default\searchplugins\11-suche.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\steffen\AppData\Roaming\Mozilla\Firefox\Profiles\9smjhw2i.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1105 octets] - [14/04/2014 20:45:11] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1165 octets] ########## ComboFix 14.04.2014 00:38 Code:
ATTFilter ComboFix 14-04-12.01 - steffen 15.04.2014 0:38:54.2.2 - x64 MINIMAL Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.1643.865 [GMT 2:00] ausgeführt von:: C:\___\Anti\ComboFix.exe * Neuer Wiederherstellungspunkt wurde erstellt (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) C:\ProgramData\TEMP C:\Windows\SysWow64\sfcfiles.dll . . . fehlt!! C:\Windows\SysWow64\sfcfiles.dll . . . fehlt!! C:\Windows\system32\drivers\ipsec.sys . . . fehlt!! C:\Windows\system32\drivers\psched.sys . . . fehlt!! HijackThis 16.04.2014 19:40 Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 19:40:37, on 16.04.2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.16521) FIREFOX: 28.0 (de) Boot mode: Normal Running processes: C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFwAdmin.exe C:\___\Anti\HiJackThis2\hijackthis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.1und1.de/starthp?src=s_startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe O4 - HKLM\..\Run: [G Data AntiVirus Tray] C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe O4 - HKLM\..\Run: [UIExec] "C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe" O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O17 - HKLM\System\CCS\Services\Tcpip\..\{5A42A7C1-9B3B-4788-8E49-EAE37F0362D3}: NameServer = 139.7.30.126 139.7.30.125 O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe O23 - Service: G Data Scheduler (AVKService) - G Data Software AG - C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKService.exe O23 - Service: G Data Dateisystem Wächter (AVKWCtl) - G Data Software AG - C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKWCtlX64.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: G Data Backup Service (GDBackupSvc) - G Data Software AG - C:\Program Files (x86)\G Data\TotalProtection\AVKBackup\AVKBackupService.exe O23 - Service: G Data Personal Firewall (GDFwSvc) - G Data Software AG - C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFwSvcx64.exe O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe O23 - Service: G Data Tuner Service (GDTunerSvc) - G Data Software AG - C:\Program Files (x86)\G Data\TotalProtection\AVKTuner\AVKTunerService.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: G Data Datensafe Service (TSNxGService) - G Data Software - C:\Program Files (x86)\G Data\TotalProtection\TSNxG\TSNxGService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 7682 bytes GMER 17.04.2014 21:59 Code:
ATTFilter GMER 2.1.19355 - hxxp://www.gmer.net Rootkit scan 2014-04-17 21:59:58 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000006d SAMSUNG_ rev.2AJ1 298,09GB Running: gmer.exe; Driver: C:\Users\steffen\AppData\Local\Temp\FreeCommanderPortableTemp\kwdiqkob.sys ---- User code sections - GMER 2.1 ---- .text C:\___\fc\App\FreeCommanderXE\FreeCommander.exe[1456] C:\Windows\syswow64\kernel32.dll!CreateThread + 28 0000000076c934b1 4 bytes {CALL 0xffffffff8983d5b8} ---- Processes - GMER 2.1 ---- Library C:\Users\steffen\AppData\Local\Temp\nsy2740.tmp\System.dll (*** suspicious ***) @ C:\___\fc\FreeCommanderPortable.exe [1380](2014-04-17 0000000075580000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74de2b95290b Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74de2b95290b@606bbd0ca228 0x15 0x58 0xB1 0xF0 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74de2b95290b@34c3acea6b15 0x73 0xC0 0x8D 0x9C ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74de2b95290b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74de2b95290b@606bbd0ca228 0x15 0x58 0xB1 0xF0 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74de2b95290b@34c3acea6b15 0x73 0xC0 0x8D 0x9C ... ---- EOF - GMER 2.1 ---- |
18.04.2014, 09:19 | #2 |
/// the machine /// TB-Ausbilder | Mail-Anhang wurde geöffnet 11-suche.xml (Win.Trojan.Agent-516645, Win.Trojan.Delf-12000) hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
18.04.2014, 21:03 | #3 |
| Mail-Anhang wurde geöffnet 11-suche.xml (Win.Trojan.Agent-516645, Win.Trojan.Delf-12000) Hallo,
__________________danke für die schnelle Antwort. "Farbars Recovery Scan Tool" habe ich versucht nach folgender Anleitung zu gebrauchen. http://www.trojaner-board.de/132035-...scan-tool.html Dabei ist unter den Wiederherstellungsoptionen keine Eingabeaufforderung zu finden. FRST 64-Bit habe ich nun ganz normal im Windows "Als Administrator ausgeführt". FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by steffen (administrator) on STEFFEN-HP on 18-04-2014 21:40:47 Running from F:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKWCtlX64.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKService.exe (G Data Software AG) C:\Program Files (x86)\G Data\TotalProtection\AVKBackup\AVKBackupService.exe (G Data Software AG) C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GdBgInx64.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G DATA\AVKProxy\GDKBFltExe32.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (G Data Software AG) C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe () C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (G Data Software) C:\Program Files (x86)\G Data\TotalProtection\TSNxG\TSNxGService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (G Data Software AG) C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFwSvcx64.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7466600 2011-09-15] (Realtek Semiconductor) HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe [1724728 2013-12-19] (G Data Software AG) HKLM-x32\...\Run: [UIExec] => C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe [156448 2012-05-04] () HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{5A42A7C1-9B3B-4788-8E49-EAE37F0362D3}: [NameServer]139.7.30.126 139.7.30.125 FireFox: ======== FF ProfilePath: C:\Users\steffen\AppData\Roaming\Mozilla\Firefox\Profiles\9smjhw2i.default FF DefaultSearchEngine: GMX Suche FF SelectedSearchEngine: GMX Suche FF Homepage: hxxp://www.google.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [365568 2011-07-05] (Advanced Micro Devices, Inc.) S4 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros) R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2244728 2014-02-12] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\TotalProtection\AVK\AVKWCtlX64.exe [2723400 2014-03-25] (G Data Software AG) R2 GDBackupSvc; C:\Program Files (x86)\G Data\TotalProtection\AVKBackup\AVKBackupService.exe [3831416 2014-03-20] (G Data Software AG) R3 GDFwSvc; C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFwSvcx64.exe [2992760 2014-01-30] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700024 2014-02-03] (G Data Software AG) S3 GDTunerSvc; C:\Program Files (x86)\G Data\TotalProtection\AVKTuner\AVKTunerService.exe [1637496 2013-12-19] (G Data Software AG) S4 lxdn_device; C:\Windows\system32\lxdncoms.exe [1039872 2007-11-28] ( ) R2 TSNxGService; C:\Program Files (x86)\G Data\TotalProtection\TSNxG\TSNxGService.exe [255608 2014-02-03] (G Data Software) S4 UI Assistant Service; C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe [274208 2012-05-04] () ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [57344 2014-04-16] (G Data Software AG) R3 gddcd; C:\Windows\system32\drivers\gddcd64.sys [78848 2014-04-16] (G Data Software AG) R1 gddcv; C:\Windows\system32\drivers\gddcv64.sys [58880 2014-04-16] (G Data Software AG) R3 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [22016 2014-04-16] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [135168 2014-04-16] (G Data Software AG) S3 GdNetMon; C:\Windows\system32\drivers\GdNetMon64.sys [31608 2012-04-05] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [68608 2014-04-16] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64000 2014-04-16] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-01-05] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65024 2014-04-16] (G Data Software AG) R0 TS4NT; C:\Windows\System32\Drivers\TS4nt.sys [98760 2014-04-16] (G Data Software) S3 motmodem; system32\DRIVERS\motmodem.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-18 21:40 - 2014-04-18 21:40 - 00000000 ____D () C:\FRST 2014-04-18 01:13 - 2014-04-18 01:13 - 00022924 _____ () C:\Windows\PFRO.log 2014-04-18 00:58 - 2013-05-10 07:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-04-18 00:58 - 2013-05-10 07:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-04-18 00:58 - 2013-05-10 06:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-04-18 00:58 - 2013-05-10 06:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-04-18 00:30 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2014-04-18 00:30 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-18 00:30 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-04-18 00:30 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2014-04-18 00:30 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2014-04-18 00:30 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-04-18 00:30 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2014-04-18 00:30 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-04-18 00:30 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2014-04-18 00:30 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2014-04-18 00:30 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2014-04-18 00:30 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2014-04-18 00:30 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-04-18 00:30 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-04-18 00:30 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-04-18 00:30 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-04-18 00:30 - 2013-10-01 22:57 - 06578176 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-04-18 00:30 - 2013-10-01 22:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-04-18 00:27 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-18 00:27 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-18 00:27 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-18 00:27 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-18 00:27 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-18 00:27 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-18 00:27 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-18 00:27 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-18 00:27 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-18 00:27 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-18 00:27 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-18 00:27 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-18 00:27 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-18 00:27 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-18 00:27 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-18 00:27 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-18 00:27 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-18 00:27 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-18 00:27 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-18 00:27 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-18 00:27 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-18 00:27 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-18 00:27 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-18 00:27 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-18 00:27 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-18 00:27 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-18 00:27 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-18 00:27 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-18 00:27 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-18 00:27 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-18 00:27 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-18 00:27 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-18 00:27 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-18 00:27 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-18 00:27 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-18 00:27 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-18 00:27 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-18 00:27 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-18 00:27 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-18 00:27 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-18 00:27 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-18 00:27 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-18 00:27 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-18 00:27 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-18 00:27 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-18 00:27 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-18 00:26 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-18 00:26 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-18 00:09 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-04-18 00:09 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2014-04-18 00:09 - 2012-08-23 16:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2014-04-18 00:09 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2014-04-18 00:09 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2014-04-18 00:09 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2014-04-18 00:09 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-04-18 00:06 - 2012-07-26 05:08 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll 2014-04-18 00:06 - 2012-07-26 05:08 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe 2014-04-18 00:06 - 2012-07-26 05:08 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll 2014-04-18 00:06 - 2012-07-26 05:08 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll 2014-04-18 00:06 - 2012-07-26 05:08 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll 2014-04-18 00:06 - 2012-07-26 04:26 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys 2014-04-18 00:06 - 2012-07-26 04:26 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys 2014-04-18 00:06 - 2012-06-02 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2014-04-17 23:42 - 2012-10-03 19:44 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2014-04-17 23:42 - 2012-10-03 19:44 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll 2014-04-17 23:42 - 2012-10-03 19:44 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2014-04-17 23:42 - 2012-10-03 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2014-04-17 23:42 - 2012-10-03 19:44 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll 2014-04-17 23:42 - 2012-10-03 19:42 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2014-04-17 23:42 - 2012-10-03 18:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll 2014-04-17 23:42 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll 2014-04-17 23:42 - 2012-10-03 18:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll 2014-04-17 23:42 - 2012-10-03 18:07 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-04-17 23:42 - 2012-04-07 14:31 - 03216384 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-04-17 23:42 - 2012-04-07 13:26 - 02342400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-04-17 23:42 - 2012-01-13 09:12 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll 2014-04-17 23:41 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-04-17 23:41 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2014-04-17 23:41 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2014-04-17 23:41 - 2012-12-07 15:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2014-04-17 23:41 - 2012-12-07 15:15 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2014-04-17 23:41 - 2012-12-07 14:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2014-04-17 23:41 - 2012-12-07 14:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2014-04-17 23:41 - 2012-12-07 13:20 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs 2014-04-17 23:41 - 2012-12-07 13:20 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs 2014-04-17 23:41 - 2012-12-07 13:20 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs 2014-04-17 23:41 - 2012-12-07 13:20 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs 2014-04-17 23:41 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs 2014-04-17 23:41 - 2012-12-07 13:20 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs 2014-04-17 23:41 - 2012-12-07 13:19 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs 2014-04-17 23:41 - 2012-12-07 13:19 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs 2014-04-17 23:41 - 2012-12-07 13:19 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs 2014-04-17 23:41 - 2012-12-07 13:19 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs 2014-04-17 23:41 - 2012-12-07 13:19 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs 2014-04-17 23:41 - 2012-12-07 13:19 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00051712 _____ (Microsoft) C:\Windows\SysWOW64\esrb.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00046592 _____ (Microsoft) C:\Windows\SysWOW64\fpb.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00045568 _____ (Microsoft) C:\Windows\SysWOW64\oflc-nz.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00044544 _____ (Microsoft) C:\Windows\SysWOW64\pegibbfc.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00043520 _____ (Microsoft) C:\Windows\SysWOW64\csrr.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00040960 _____ (Microsoft) C:\Windows\SysWOW64\cob-au.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00030720 _____ (Microsoft) C:\Windows\SysWOW64\usk.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00021504 _____ (Microsoft) C:\Windows\SysWOW64\grb.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-pt.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi.rs 2014-04-17 23:41 - 2012-12-07 12:46 - 00015360 _____ (Microsoft) C:\Windows\SysWOW64\djctq.rs 2014-04-17 23:40 - 2013-12-04 04:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll 2014-04-17 23:40 - 2013-12-04 04:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll 2014-04-17 23:40 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll 2014-04-17 23:40 - 2013-12-04 04:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll 2014-04-17 23:40 - 2013-12-04 04:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll 2014-04-17 23:40 - 2013-12-04 04:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe 2014-04-17 23:40 - 2013-12-04 04:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe 2014-04-17 23:40 - 2013-12-04 04:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe 2014-04-17 23:40 - 2013-12-04 04:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe 2014-04-17 23:40 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll 2014-04-17 23:40 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll 2014-04-17 23:40 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll 2014-04-17 23:40 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll 2014-04-17 23:40 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll 2014-04-17 23:40 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe 2014-04-17 23:40 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe 2014-04-17 23:40 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe 2014-04-17 23:40 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe 2014-04-17 23:40 - 2012-12-07 13:20 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs 2014-04-17 23:40 - 2012-12-07 13:19 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs 2014-04-17 23:40 - 2012-12-07 12:46 - 00055296 _____ (Microsoft) C:\Windows\SysWOW64\cero.rs 2014-04-17 23:40 - 2012-12-07 12:46 - 00023552 _____ (Microsoft) C:\Windows\SysWOW64\oflc.rs 2014-04-17 23:40 - 2012-12-07 12:46 - 00020480 _____ (Microsoft) C:\Windows\SysWOW64\pegi-fi.rs 2014-04-17 23:39 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-17 23:39 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-17 23:39 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-17 23:39 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-17 23:39 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-17 23:39 - 2013-11-23 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2014-04-17 23:39 - 2013-11-23 19:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2014-04-17 23:39 - 2013-10-30 04:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2014-04-17 23:39 - 2013-10-30 04:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll 2014-04-17 23:39 - 2013-10-04 04:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2014-04-17 23:39 - 2013-10-04 04:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2014-04-17 23:39 - 2013-10-04 04:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-04-17 23:39 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2014-04-17 23:39 - 2013-10-04 03:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-04-17 23:39 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2014-04-17 23:39 - 2012-10-09 20:17 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll 2014-04-17 23:39 - 2012-10-09 20:17 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll 2014-04-17 23:39 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll 2014-04-17 23:39 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll 2014-04-17 23:39 - 2012-08-21 23:01 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe 2014-04-17 23:38 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-04-17 23:38 - 2014-01-01 01:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls 2014-04-17 23:38 - 2014-01-01 01:04 - 00420008 _____ () C:\Windows\system32\locale.nls 2014-04-17 23:38 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2014-04-17 23:38 - 2013-07-04 14:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-04-17 23:38 - 2013-07-04 14:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-04-17 23:38 - 2013-07-04 13:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-04-17 23:38 - 2013-07-04 13:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-04-17 23:38 - 2013-07-04 12:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2014-04-17 23:38 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2014-04-17 23:38 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2014-04-17 23:38 - 2013-04-01 08:03 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_AuthenticAMD.dll 2014-04-17 23:38 - 2013-03-19 07:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2014-04-17 23:38 - 2013-01-24 08:01 - 00223752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2014-04-17 23:38 - 2012-11-22 07:44 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-04-17 23:38 - 2012-11-22 06:45 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-04-17 23:38 - 2012-08-22 20:12 - 00950128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2014-04-17 23:38 - 2012-07-04 22:26 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys 2014-04-17 23:38 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-04-17 23:38 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-04-17 23:38 - 2012-05-01 07:40 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2014-04-17 23:37 - 2012-07-06 22:07 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2014-04-17 23:34 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2014-04-17 23:30 - 2012-05-05 10:36 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-04-17 23:30 - 2012-05-05 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-04-17 23:27 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-04-17 23:27 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-04-17 23:27 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-17 22:46 - 2014-04-17 22:46 - 00001006 _____ () C:\Windows\Synaptics.log 2014-04-17 22:42 - 2010-12-16 11:06 - 00047232 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys 2014-04-17 22:34 - 2014-04-17 22:36 - 00000000 ____D () C:\Program Files (x86)\AMD High-Definition Graphics Driver 2014-04-17 22:28 - 2011-09-17 10:17 - 03073256 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2014-04-17 22:28 - 2011-09-17 08:18 - 00098408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInst64.dll 2014-04-17 22:28 - 2011-09-17 07:09 - 03209320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2014-04-17 22:28 - 2011-09-17 02:39 - 02519656 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2014-04-17 22:28 - 2011-08-20 06:54 - 01881704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2014-04-17 22:28 - 2011-07-23 11:35 - 01247848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2014-04-17 22:28 - 2011-07-01 08:14 - 01560168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2014-04-17 22:07 - 2014-04-18 21:33 - 00000878 _____ () C:\Windows\setupact.log 2014-04-17 22:07 - 2014-04-17 22:07 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-17 22:06 - 2014-04-18 21:43 - 00650421 _____ () C:\Windows\WindowsUpdate.log 2014-04-17 15:29 - 2014-04-17 15:29 - 00000000 ____D () C:\Windows\ERUNT 2014-04-16 21:41 - 2014-04-16 21:41 - 00000000 ____D () C:\ProgramData\Sophos 2014-04-16 20:06 - 2014-04-16 20:06 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf 2014-04-16 20:05 - 2014-04-16 20:05 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys 2014-04-16 16:54 - 2014-04-16 20:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 06:11 - 2014-04-16 06:12 - 00000085 _____ () C:\Windows\wininit.ini 2014-04-15 22:34 - 2014-04-15 22:34 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-04-15 22:31 - 2014-04-16 16:21 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-04-15 22:31 - 2014-04-16 06:12 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-04-15 00:36 - 2014-04-15 01:47 - 00000000 ____D () C:\ComboFix 2014-04-14 22:29 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-04-14 22:29 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-04-14 22:29 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-04-14 22:29 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-04-14 22:29 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-04-14 22:29 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-04-14 22:29 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-04-14 22:29 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-04-14 22:27 - 2014-04-14 22:28 - 00000000 ____D () C:\Qoobox 2014-04-14 22:23 - 2014-04-14 22:23 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 21:55 - 2014-04-15 22:32 - 00000000 ____D () C:\ProgramData\PDFC 2014-04-14 21:37 - 2014-04-14 21:37 - 00000000 ____D () C:\Users\steffen\AppData\Local\Xobni 2014-04-14 20:44 - 2014-04-15 21:51 - 00000000 ____D () C:\AdwCleaner 2014-04-14 20:33 - 2014-04-14 20:33 - 00001117 _____ () C:\Users\steffen\Desktop\fc.lnk 2014-04-14 17:34 - 2014-04-14 17:34 - 00000000 ____D () C:\Users\steffen\AppData\Roaming\SUPERAntiSpyware.com 2014-04-14 17:34 - 2014-04-14 17:34 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com 2014-04-13 10:10 - 2014-04-14 16:49 - 00000000 ____D () C:\___ 2014-04-13 09:55 - 2014-04-13 09:56 - 00000000 ____D () C:\Users\steffen\Music\Documents\Youcam 2014-04-12 18:20 - 2014-04-12 18:21 - 292360192 _____ () C:\REMOVE_THIS_FILE.livecd.swap 2014-04-09 21:09 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 21:09 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 21:09 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 21:09 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 21:09 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 21:09 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 21:09 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 21:09 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 21:09 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 21:09 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 21:09 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-03-30 21:23 - 2014-03-30 21:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-04-18 21:43 - 2014-04-17 22:06 - 00650421 _____ () C:\Windows\WindowsUpdate.log 2014-04-18 21:43 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 21:43 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 21:40 - 2014-04-18 21:40 - 00000000 ____D () C:\FRST 2014-04-18 21:39 - 2011-08-02 22:29 - 00700134 _____ () C:\Windows\system32\perfh007.dat 2014-04-18 21:39 - 2011-08-02 22:29 - 00149984 _____ () C:\Windows\system32\perfc007.dat 2014-04-18 21:39 - 2009-07-14 07:13 - 01622236 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-18 21:33 - 2014-04-17 22:07 - 00000878 _____ () C:\Windows\setupact.log 2014-04-18 21:33 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-18 01:13 - 2014-04-18 01:13 - 00022924 _____ () C:\Windows\PFRO.log 2014-04-18 01:13 - 2009-07-14 06:45 - 00276904 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-04-18 01:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-18 00:55 - 2012-11-04 12:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-18 00:46 - 2012-04-04 13:22 - 01589164 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-04-18 00:01 - 2013-04-11 10:25 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2BB54941-BD0E-43F0-9F44-AF7AEACACF7B} 2014-04-17 22:46 - 2014-04-17 22:46 - 00001006 _____ () C:\Windows\Synaptics.log 2014-04-17 22:44 - 2011-02-10 21:23 - 00000000 ____D () C:\SWSetup 2014-04-17 22:36 - 2014-04-17 22:34 - 00000000 ____D () C:\Program Files (x86)\AMD High-Definition Graphics Driver 2014-04-17 22:36 - 2011-02-10 21:23 - 00000000 ____D () C:\SYSTEM.SAV 2014-04-17 22:28 - 2011-11-14 12:19 - 00000000 ____D () C:\Windows\SysWOW64\RTCOM 2014-04-17 22:07 - 2014-04-17 22:07 - 00000000 _____ () C:\Windows\setuperr.log 2014-04-17 16:25 - 2012-04-04 13:39 - 00000000 ____D () C:\Users\steffen\AppData\Roaming\Macromedia 2014-04-17 16:18 - 2012-04-04 22:04 - 00000000 ____D () C:\Users\steffen\AppData\Local\CrashDumps 2014-04-17 16:16 - 2012-05-29 20:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-17 16:16 - 2012-04-04 13:43 - 00000000 ____D () C:\Program Files (x86)\Motorola 2014-04-17 16:12 - 2012-04-05 16:08 - 00000000 ____D () C:\Program Files (x86)\Thunderbird 2014-04-17 15:29 - 2014-04-17 15:29 - 00000000 ____D () C:\Windows\ERUNT 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\winrm 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\WCN 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\sysprep 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\slmgr 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\SysWOW64\Printing_Admin_Scripts 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\winrm 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\WCN 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\slmgr 2014-04-17 05:41 - 2010-11-21 09:06 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts 2014-04-17 05:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\oobe 2014-04-17 05:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-04-17 05:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-04-17 05:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-04-17 01:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-17 00:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-04-17 00:58 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\com 2014-04-16 21:41 - 2014-04-16 21:41 - 00000000 ____D () C:\ProgramData\Sophos 2014-04-16 20:20 - 2014-04-16 16:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-16 20:06 - 2014-04-16 20:06 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_GDKBFlt64_01007.Wdf 2014-04-16 20:06 - 2012-04-05 15:16 - 00068608 _____ (G Data Software AG) C:\Windows\system32\Drivers\PktIcpt.sys 2014-04-16 20:06 - 2012-04-05 15:15 - 00098760 _____ (G Data Software) C:\Windows\system32\Drivers\TS4nt.sys 2014-04-16 20:05 - 2014-04-16 20:05 - 00022016 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDKBFlt64.sys 2014-04-16 20:05 - 2013-04-10 10:17 - 00078848 _____ (G Data Software AG) C:\Windows\system32\Drivers\gddcd64.sys 2014-04-16 20:05 - 2013-04-10 10:17 - 00058880 _____ (G Data Software AG) C:\Windows\system32\Drivers\gddcv64.sys 2014-04-16 20:05 - 2012-04-05 15:14 - 00065024 _____ (G Data Software AG) C:\Windows\system32\Drivers\HookCentre.sys 2014-04-16 20:05 - 2012-04-05 15:14 - 00064000 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys 2014-04-16 20:04 - 2012-04-05 15:14 - 00135168 _____ (G Data Software AG) C:\Windows\system32\Drivers\MiniIcpt.sys 2014-04-16 20:04 - 2012-04-05 15:14 - 00057344 _____ (G Data Software AG) C:\Windows\system32\Drivers\GDBehave.sys 2014-04-16 20:02 - 2012-04-04 14:18 - 00000000 ____D () C:\ProgramData\G DATA 2014-04-16 16:52 - 2014-04-16 16:52 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-16 16:21 - 2014-04-15 22:31 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-04-16 06:12 - 2014-04-16 06:11 - 00000085 _____ () C:\Windows\wininit.ini 2014-04-16 06:12 - 2014-04-15 22:31 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-04-15 22:34 - 2014-04-15 22:34 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-04-15 22:33 - 2012-04-02 17:10 - 00000000 ____D () C:\Users\steffen 2014-04-15 22:32 - 2014-04-14 21:55 - 00000000 ____D () C:\ProgramData\PDFC 2014-04-15 21:51 - 2014-04-14 20:44 - 00000000 ____D () C:\AdwCleaner 2014-04-15 01:47 - 2014-04-15 00:36 - 00000000 ____D () C:\ComboFix 2014-04-15 01:47 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-04-14 22:28 - 2014-04-14 22:27 - 00000000 ____D () C:\Qoobox 2014-04-14 22:23 - 2014-04-14 22:23 - 00000000 ____D () C:\Windows\erdnt 2014-04-14 21:54 - 2012-05-04 12:06 - 00000000 ____D () C:\Program Files (x86)\Winamp 2014-04-14 21:52 - 2012-04-02 17:11 - 00000000 ____D () C:\ProgramData\WinZip 2014-04-14 21:37 - 2014-04-14 21:37 - 00000000 ____D () C:\Users\steffen\AppData\Local\Xobni 2014-04-14 21:36 - 2011-08-02 13:14 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 2014-04-14 21:26 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-04-14 21:23 - 2011-08-02 13:33 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-14 21:20 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-04-14 20:33 - 2014-04-14 20:33 - 00001117 _____ () C:\Users\steffen\Desktop\fc.lnk 2014-04-14 17:34 - 2014-04-14 17:34 - 00000000 ____D () C:\Users\steffen\AppData\Roaming\SUPERAntiSpyware.com 2014-04-14 17:34 - 2014-04-14 17:34 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com 2014-04-14 17:15 - 2007-01-02 03:25 - 00000000 ____D () C:\Windows\Panther 2014-04-14 17:14 - 2012-04-18 22:24 - 00000000 ____D () C:\Windows\Minidump 2014-04-14 16:49 - 2014-04-13 10:10 - 00000000 ____D () C:\___ 2014-04-13 09:56 - 2014-04-13 09:55 - 00000000 ____D () C:\Users\steffen\Music\Documents\Youcam 2014-04-12 18:21 - 2014-04-12 18:20 - 292360192 _____ () C:\REMOVE_THIS_FILE.livecd.swap 2014-04-11 11:10 - 2012-04-02 19:06 - 00000000 ____D () C:\Users\steffen\AppData\Roaming\SoftGrid Client 2014-04-10 21:25 - 2013-08-08 21:15 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 21:20 - 2012-04-05 15:38 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-08 13:13 - 2012-10-07 23:44 - 00000000 ____D () C:\ProgramData\lx_Cats 2014-03-30 21:24 - 2014-03-30 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-30 21:05 - 2014-02-14 18:35 - 00018895 _____ () C:\Users\steffen\Music\Documents\KM Arbeit.xlsx 2014-03-19 21:39 - 2012-04-05 13:11 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-03-19 21:38 - 2014-02-01 23:52 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-12 09:38 ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 01 Ran by steffen at 2014-04-18 21:47:00 Running from F:\ Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: G Data TotalProtection (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0} AV: Norton Internet Security (Disabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: G Data TotalProtection (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Disabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: G Data Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B} FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 1&1 Surf-Stick (HKLM-x32\...\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.2 - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) AMD APP SDK Runtime (Version: 2.4.650.9 - Advanced Micro Devices Inc.) Hidden AMD Fuel (Version: 2011.0705.1115.18310 - Ihr Firmenname) Hidden AMD Media Foundation Decoders (Version: 1.0.60705.1113 - ATI Technologies Inc.) Hidden AMD VISION Engine Control Center (x32 Version: 2011.0705.1115.18310 - Ihr Firmenname) Hidden Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) ATI Catalyst Install Manager (HKLM\...\{B3C4ADC9-637E-DDD9-A66C-782AE5E2E667}) (Version: 3.0.829.0 - ATI Technologies, Inc.) Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.02.000.55 - Atheros Communications) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0705.1115.18310 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.0705.1115.18310 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2011.0705.1115.18310 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Czech (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Danish (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Dutch (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help English (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Finnish (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help French (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help German (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Greek (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Hungarian (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Italian (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Japanese (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Korean (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Norwegian (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Polish (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Portuguese (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Russian (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Spanish (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Swedish (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Thai (x32 Version: 2011.0705.1114.18310 - ATI) Hidden CCC Help Turkish (x32 Version: 2011.0705.1114.18310 - ATI) Hidden ccc-utility64 (Version: 2011.0705.1115.18310 - ATI) Hidden Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.2.1.3922 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.2.1.3922 - CyberLink Corp.) Hidden Energy Star Digital Logo (HKLM-x32\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{E96CAA2A-0244-4A2A-8403-0C3C9534778B}) (Version: 2.1.1 - Hewlett-Packard) G Data TotalProtection (HKLM-x32\...\{6715BEB5-01F1-41AC-B44B-0A78CD50C433}) (Version: 25.0.1.2 - G Data Software AG) Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{B97E3520-C726-475E-BC0C-7561952633AB}) (Version: 1.2.1 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{03046EBB-CB7C-4B98-BEFB-690EB955DA22}) (Version: 8.5.4526.3645 - Hewlett-Packard Company) HP Software Framework (HKLM-x32\...\{D2462056-BA75-4B2C-8267-DFEA2B6AC4AE}) (Version: 4.6.10.1 - Hewlett-Packard Company) HP Wireless Assistant (HKLM\...\{9EA86AD9-FB32-4B9E-BD56-3068F9B8031F}) (Version: 4.0.10.0 - Hewlett-Packard) Java Auto Updater (x32 Version: 2.0.7.1 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 22 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416022FF}) (Version: 6.0.220 - Oracle) Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5128.5002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation) MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.8 - Google, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.42.304.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6461 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.77 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 1.0.22 - Hewlett-Packard) Hidden Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.29.0 - Synaptics Incorporated) Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Xobni Core (x32 Version: 1.0.0 - Xobni, Inc.) Hidden ==================== Restore Points ========================= 16-04-2014 19:38:38 Installed Sophos Virus Removal Tool. 16-04-2014 22:49:28 Sprachpaketdeinstallation 17-04-2014 13:54:10 Removed Sophos Virus Removal Tool. 17-04-2014 21:43:31 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {3B9290AD-0D9B-4F06-900D-7C8675096CE2} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-03-23] (CyberLink) Task: {94325D40-067F-4B7F-AD81-87F2CFD15D54} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2012-10-07 23:44 - 2009-08-13 12:06 - 00177152 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdndrpp.dll 2011-07-05 12:27 - 2011-07-05 12:27 - 00073728 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll 2013-04-23 14:07 - 2012-05-04 17:19 - 00156448 _____ () C:\Program Files (x86)\1&1 Surf-Stick\UIExec.exe 2013-12-19 04:42 - 2013-12-19 04:42 - 00350840 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll 2010-07-21 14:33 - 2010-07-21 14:33 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\steffen\Music\Documents\Winterreifen.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\Services: Atheros Bt&Wlan Coex Agent => 2 MSCONFIG\Services: AtherosSvc => 2 MSCONFIG\Services: gusvc => 3 MSCONFIG\Services: HP Support Assistant Service => 2 MSCONFIG\Services: MotoHelper => 2 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: XobniService => 2 MSCONFIG\startupreg: AthBtTray => "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" MSCONFIG\startupreg: HP Quick Launch => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe MSCONFIG\startupreg: HPOSD => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe MSCONFIG\startupreg: HPWirelessAssistant => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden MSCONFIG\startupreg: NCPluginUpdater => "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/18/2014 09:36:12 PM) (Source: Application Hang) (User: ) Description: Programm FRST64.exe, Version 3.3.10.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1618 Startzeit: 01cf5b3d40c9374b Endzeit: 47 Anwendungspfad: F:\FRST64.exe Berichts-ID: 9d9627fe-c730-11e3-bbca-74de2b95290b Error: (04/18/2014 09:34:05 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 01:14:33 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 11:01:41 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 10:46:11 PM) (Source: Dell-System-Update) (User: ) Description: Synaptics MUP installation Utilies Description: Synaptics Pointing device driver Log file: C:\Windows\Synaptics.log Exit code: 1603 Error: (04/17/2014 10:15:39 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 10:09:09 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/18/2014 09:37:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "HP Support Assistant Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/18/2014 09:37:47 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst HP Support Assistant Service erreicht. Error: (04/18/2014 09:36:41 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht. Error: (04/18/2014 01:26:21 AM) (Source: DCOM) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (04/18/2014 01:11:07 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "G Data Personal Firewall" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/18/2014 01:11:07 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst G Data Personal Firewall erreicht. Error: (04/18/2014 01:11:08 AM) (Source: DCOM) (User: ) Description: 1053GDFwSvc-Service{1DED95CA-C567-464A-B405-087EDDF0B095} Error: (04/18/2014 01:10:35 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst Windows Modules Installer konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (04/18/2014 01:05:15 AM) (Source: DCOM) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (04/18/2014 00:35:49 AM) (Source: VDS Basic Provider) (User: ) Description: Unerwarteter Fehler. Fehlercode: D@01010004 Microsoft Office Sessions: ========================= Error: (04/18/2014 09:36:12 PM) (Source: Application Hang)(User: ) Description: FRST64.exe3.3.10.2161801cf5b3d40c9374b47F:\FRST64.exe9d9627fe-c730-11e3-bbca-74de2b95290b Error: (04/18/2014 09:34:05 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/18/2014 01:14:33 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 11:01:41 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 10:46:11 PM) (Source: Dell-System-Update)(User: ) Description: Synaptics MUP installation Utilies Description: Synaptics Pointing device driver Log file: C:\Windows\Synaptics.log Exit code: 1603 Error: (04/17/2014 10:15:39 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/17/2014 10:09:09 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 49% Total physical RAM: 1642.91 MB Available physical RAM: 835.89 MB Total Pagefile: 5738.91 MB Available Pagefile: 3867.84 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:282.46 GB) (Free:238.36 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:15.33 GB) (Free:1.85 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (AVK_16APR14) (Removable) (Total:3.74 GB) (Free:3.22 GB) FAT32 Drive h: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0EFD49B7) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=282 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ======================================================== Disk: 1 (Size: 4 GB) (Disk ID: 001E7F21) Partition 1: (Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ |
19.04.2014, 12:32 | #4 |
/// the machine /// TB-Ausbilder | Mail-Anhang wurde geöffnet 11-suche.xml (Win.Trojan.Agent-516645, Win.Trojan.Delf-12000) Combofix, wenn noch vorhanden, bitte löschen. Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Mail-Anhang wurde geöffnet 11-suche.xml (Win.Trojan.Agent-516645, Win.Trojan.Delf-12000) |
adobe, adobe flash player, antivirus, bho, browser, computer, entfernen, explorer, firefox, firewall, flash player, helper, home, infizierte, internet, internet explorer, launch, logfile, mozilla, ordner, proxy, realtek, registrierungsdatenbank, registry, rootkit, windows, wmp |