|
Log-Analyse und Auswertung: Windows 7: angeklickt flash player nicht aktuellWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.06.2014, 18:47 | #1 |
| Windows 7: angeklickt flash player nicht aktuell Hallo, meine Freundin hat leider auf diese irreführende "Werbung" geklickt die besagt das der Flash player nicht mehr aktuell ist oder java nicht mehr aktuell ist und hat sich damit leider ganz schön viel mist installiert habe bisher adwcleaner und mbam durchlaufen lassen und avira nicht komplett. ich hoffe ihr könnt mir helfen da sicher zu gehen das alles weg ist. Anbei die ganzen logfiles. Da die logfile von mbam viel zu groß ist hab ich sie mal angehängt als zip. Danke schonmal für die hilfe. Avira Code:
ATTFilter Exported events: 05.06.2014 19:25 [System Scanner] Malware found The file 'C:\AdwCleaner\Quarantine\C\Program Files (x86)\ScanTack\bin\ScanTackBAApp.dll.vir' contained a virus or unwanted program 'TR/Trash.Gen' [trojan] Action(s) taken: The file was moved to the quarantine directory under the name '0efb0cd8.qua'! Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014 Ran by Rike (administrator) on RIKE-PC on 05-06-2014 19:24:51 Running from E:\Downloads Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Fuyu LIMITED) C:\ProgramData\WindowsProtectManger\wprotectmanager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHTU.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202008 2013-10-17] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [GrooveMonitor] => E:\Programme\Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [182352 2014-05-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Windows Servelet System Component] => C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe [640512 2014-05-23] () HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\MountPoints2: H - H:\Autorun.exe HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\MountPoints2: {0d5449de-b3bf-11e3-8de3-448a5b5dbd6b} - F:\pushinst.exe HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\MountPoints2: {0da6ec01-bcc1-11e3-89fa-448a5b5dbd6b} - H:\autorun.exe HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DAEMON Tools Lite] => E:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: H - H:\Autorun.exe HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0d5449de-b3bf-11e3-8de3-448a5b5dbd6b} - F:\pushinst.exe HKU\S-1-5-21-1763780752-3024800267-2526177901-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {0da6ec01-bcc1-11e3-89fa-448a5b5dbd6b} - H:\autorun.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Programme\Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Programme\Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - E:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: about:newtab?source=home CHR RestoreOnStartup: "about:newtab?source=home" CHR StartupUrls: "about:newtab?source=home" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (YouTube) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Google Mail) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-06-03] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [124496 2014-05-05] (Avira Operations GmbH & Co. KG) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 Microsoft Office Groove Audit Service; E:\Programme\Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation) R2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe [573344 2014-05-27] (Fuyu LIMITED) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-05] (Disc Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-05] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-05-22] (StdLib) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-05 19:24 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-05 19:05 - 2014-06-05 19:14 - 00000000 ____D () C:\AdwCleaner 2014-06-05 19:00 - 2014-06-05 19:08 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-05 18:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-05 18:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-05 18:55 - 2014-06-05 19:24 - 01101824 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-05 18:53 - 2014-04-09 17:39 - 00000426 _____ () C:\AVScanner.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 22:21 - 2014-05-22 18:19 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager 2014-06-03 17:23 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-03 17:23 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-03 17:08 - 2014-06-05 18:59 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-04-09 07:55 - 00034376 _____ () C:\Windows\Launcher.exe 2014-05-27 22:30 - 2014-06-03 18:07 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:19 - 2014-05-27 22:19 - 00000000 ____D () C:\ProgramData\WindowsProtectManger 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-27 22:15 - 2014-06-05 19:06 - 00000000 ____D () C:\temp 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-15 23:41 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 23:41 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 23:41 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 23:41 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 18:25 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 18:25 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 18:25 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 18:25 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 18:25 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 18:25 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 18:25 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 18:25 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 18:25 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll ==================== One Month Modified Files and Folders ======= 2014-06-05 19:24 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST 2014-06-05 19:24 - 2014-06-05 18:55 - 01101824 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-05 19:24 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike\AppData\Local\Temp 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:23 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike 2014-06-05 19:15 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-05 19:15 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-05 19:14 - 2014-06-05 19:05 - 00000000 ____D () C:\AdwCleaner 2014-06-05 19:12 - 2014-03-20 14:58 - 00699092 _____ () C:\Windows\system32\perfh007.dat 2014-06-05 19:12 - 2014-03-20 14:58 - 00149232 _____ () C:\Windows\system32\perfc007.dat 2014-06-05 19:12 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-05 19:11 - 2014-03-20 07:29 - 01307177 _____ () C:\Windows\WindowsUpdate.log 2014-06-05 19:08 - 2014-06-05 19:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 19:08 - 2014-03-20 07:50 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-05 19:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-05 19:08 - 2009-07-14 06:51 - 00008281 _____ () C:\Windows\setupact.log 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-06-05 19:07 - 2010-11-21 05:47 - 00379404 _____ () C:\Windows\PFRO.log 2014-06-05 19:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas 2014-06-05 19:06 - 2014-05-27 22:15 - 00000000 ____D () C:\temp 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-03 17:08 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-05 18:55 - 2014-03-20 07:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-05 18:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-05 18:53 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager 2014-06-03 18:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-06-03 18:07 - 2014-05-27 22:30 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-06-03 17:26 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-03 17:11 - 2014-04-03 20:07 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-03 17:11 - 2014-04-03 20:07 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-02 21:14 - 2014-03-20 07:50 - 00002317 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-03-20 07:29 - 00001425 _____ () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:19 - 2014-05-27 22:19 - 00000000 ____D () C:\ProgramData\WindowsProtectManger 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-22 18:19 - 2014-06-03 22:21 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-05-17 15:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-16 19:02 - 2014-04-09 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-16 07:40 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-16 07:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-15 23:41 - 2014-04-05 15:00 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 23:40 - 2014-04-05 18:24 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-15 23:40 - 2014-04-05 18:24 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-13 17:05 - 2014-04-03 19:59 - 00001133 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-05-13 17:05 - 2014-04-03 19:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-13 17:05 - 2014-04-03 19:59 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-13 17:05 - 2014-03-20 07:37 - 00000000 ____D () C:\ProgramData\Package Cache 2014-05-12 07:26 - 2014-06-05 18:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-05 18:59 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-05 18:59 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 08:14 - 2014-06-03 17:23 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-06-03 17:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-06 06:40 - 2014-05-15 23:41 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 23:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 23:41 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 23:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 23:41 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 23:41 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll Some content of TEMP: ==================== C:\Users\Rike\AppData\Local\Temp\1_Offer_4.exe C:\Users\Rike\AppData\Local\Temp\1_Offer_5.exe C:\Users\Rike\AppData\Local\Temp\1_Offer_6.exe C:\Users\Rike\AppData\Local\Temp\amsetup_activeris_default_010414_installer.exe C:\Users\Rike\AppData\Local\Temp\AutoRun.exe C:\Users\Rike\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Rike\AppData\Local\Temp\avgnt.exe C:\Users\Rike\AppData\Local\Temp\BackupSetup.exe C:\Users\Rike\AppData\Local\Temp\cloud_backup_setup.exe C:\Users\Rike\AppData\Local\Temp\devcon64.exe C:\Users\Rike\AppData\Local\Temp\eauninstall.exe C:\Users\Rike\AppData\Local\Temp\lly_webssearches.exe C:\Users\Rike\AppData\Local\Temp\MSIAFTERBURNERSETUP.EXE C:\Users\Rike\AppData\Local\Temp\nsuB1D7.exe C:\Users\Rike\AppData\Local\Temp\ose00000.exe C:\Users\Rike\AppData\Local\Temp\SETUP_AFTERBURNER.EXE C:\Users\Rike\AppData\Local\Temp\speedupmypc.exe C:\Users\Rike\AppData\Local\Temp\SpOrder.dll C:\Users\Rike\AppData\Local\Temp\The Sims 2 Deluxe_uninst.exe C:\Users\Rike\AppData\Local\Temp\UninstallEADM.dll C:\Users\Rike\AppData\Local\Temp\vcredist_x64.exe C:\Users\Rike\AppData\Local\Temp\vopackage.exe C:\Users\Rike\AppData\Local\Temp\VP6Install.exe C:\Users\Rike\AppData\Local\Temp\VP6VFW.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-31 15:51 ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-06-05 19:31:01 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T0L0-1 ADATA_SP900 rev.5.0.7b 119,24GB Running: olz5zuq7.exe; Driver: C:\Users\Rike\AppData\Local\Temp\kxldrpow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80003001000 8 bytes [00, 00, 22, 00, 43, 63, 53, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544 fffff80003001010 47 bytes [90, 94, AA, 0A, 80, FA, FF, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[1740] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[1740] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[1984] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 ? C:\Windows\system32\mssprxy.dll [2256] entry point in ".rdata" section 00000000665271e6 .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[2200] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[2200] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 ? C:\Windows\system32\mssprxy.dll [4836] entry point in ".rdata" section 00000000665271e6 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000076f2f9b1 7 bytes {MOV EDX, 0xfcbe28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000076f2fbf5 7 bytes {MOV EDX, 0xfcbe68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000076f2fc25 7 bytes {MOV EDX, 0xfcbda8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000076f2fc3d 7 bytes {MOV EDX, 0xfcbd28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000076f2fc55 7 bytes {MOV EDX, 0xfcbf28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000076f2fc85 7 bytes {MOV EDX, 0xfcbf68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000076f2fd05 7 bytes {MOV EDX, 0xfcbee8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000076f2fd1d 7 bytes {MOV EDX, 0xfcbea8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000076f2fd69 7 bytes {MOV EDX, 0xfcbc68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000076f2fe61 7 bytes {MOV EDX, 0xfcbca8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000076f300b9 7 bytes {MOV EDX, 0xfcbc28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000076f310c5 7 bytes {MOV EDX, 0xfcbde8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000076f3113d 7 bytes {MOV EDX, 0xfcbd68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000076f31341 7 bytes {MOV EDX, 0xfcbce8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3372] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000076f2f9b1 7 bytes {MOV EDX, 0x1075e28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000076f2fbf5 7 bytes {MOV EDX, 0x1075e68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000076f2fc25 7 bytes {MOV EDX, 0x1075da8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000076f2fc3d 7 bytes {MOV EDX, 0x1075d28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000076f2fc55 7 bytes {MOV EDX, 0x1075f28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000076f2fc85 7 bytes {MOV EDX, 0x1075f68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000076f2fd05 7 bytes {MOV EDX, 0x1075ee8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000076f2fd1d 7 bytes {MOV EDX, 0x1075ea8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000076f2fd69 7 bytes {MOV EDX, 0x1075c68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000076f2fe61 7 bytes {MOV EDX, 0x1075ca8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000076f300b9 7 bytes {MOV EDX, 0x1075c28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000076f310c5 7 bytes {MOV EDX, 0x1075de8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000076f3113d 7 bytes {MOV EDX, 0x1075d68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000076f31341 7 bytes {MOV EDX, 0x1075ce8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe[2884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe[2884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000076f2f9b1 7 bytes {MOV EDX, 0xdaa28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000076f2fbf5 7 bytes {MOV EDX, 0xdaa68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000076f2fc25 7 bytes {MOV EDX, 0xda9a8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000076f2fc3d 7 bytes {MOV EDX, 0xda928; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000076f2fc55 7 bytes {MOV EDX, 0xdab28; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000076f2fc85 7 bytes {MOV EDX, 0xdab68; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000076f2fd05 7 bytes {MOV EDX, 0xdaae8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000076f2fd1d 7 bytes {MOV EDX, 0xdaaa8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000076f2fd69 7 bytes {MOV EDX, 0xda868; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000076f2fe61 7 bytes {MOV EDX, 0xda8a8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000076f300b9 7 bytes {MOV EDX, 0xda828; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000076f310c5 7 bytes {MOV EDX, 0xda9e8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000076f3113d 7 bytes {MOV EDX, 0xda968; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000076f31341 7 bytes {MOV EDX, 0xda8e8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000076f2f9b1 7 bytes {MOV EDX, 0xf51228; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000076f2fbf5 7 bytes {MOV EDX, 0xf51268; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000076f2fc25 7 bytes {MOV EDX, 0xf511a8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000076f2fc3d 7 bytes {MOV EDX, 0xf51128; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000076f2fc55 7 bytes {MOV EDX, 0xf51328; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000076f2fc85 7 bytes {MOV EDX, 0xf51368; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000076f2fd05 7 bytes {MOV EDX, 0xf512e8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000076f2fd1d 7 bytes {MOV EDX, 0xf512a8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000076f2fd69 7 bytes {MOV EDX, 0xf51068; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000076f2fe61 7 bytes {MOV EDX, 0xf510a8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000076f300b9 7 bytes {MOV EDX, 0xf51028; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000076f310c5 7 bytes {MOV EDX, 0xf511e8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000076f3113d 7 bytes {MOV EDX, 0xf51168; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000076f31341 7 bytes {MOV EDX, 0xf510e8; JMP RDX} .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762a1465 2 bytes [2A, 76] .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762a14bb 2 bytes [2A, 76] .text ... * 2 ---- EOF - GMER 2.1 ---- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-06-2014 Ran by Rike at 2014-06-05 19:25:02 Running from E:\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 9.0.124.0 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) AMD Accelerated Video Transcoding (Version: 13.20.100.31206 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Ihr Firmenname) Hidden AMD Catalyst Install Manager (HKLM\...\{308051DA-0048-7A07-FE8B-9B6EC119A9E8}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden AMD Media Foundation Decoders (Version: 1.0.81206.1620 - Advanced Micro Devices, Inc.) Hidden AMD Wireless Display v3.0 (Version: 1.0.0.14 - Advanced Micro Devices, Inc.) Hidden ANNO 1404 - Königsedition (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 3.10.0000 - Ubisoft) Avira (HKLM-x32\...\{70a79d1f-686d-4d5c-962b-07aa1294eae0}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.50.56 - Electronic Arts) Die Sims™ 3 70er, 80er & 90er Accessoires (HKLM-x32\...\{E1868CAE-E3B9-4099-8C18-AA8944D336FD}) (Version: 17.0.77 - Electronic Arts) Die Sims™ 3 Design-Garten-Accessoires (HKLM-x32\...\{117B6BF6-82C3-420C-B284-9247C8568E53}) (Version: 7.0.55 - Electronic Arts) Die Sims™ 3 Diesel Accessoires (HKLM-x32\...\{1C9B6173-6DC9-4EEE-9EFC-6BA115CFBE43}) (Version: 14.0.48 - Electronic Arts) Die Sims™ 3 Einfach tierisch (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts) Die Sims™ 3 Gib Gas-Accessoires (HKLM-x32\...\{ED436EA8-4145-4703-AE5D-4D09DD24AF5A}) (Version: 5.0.44 - Electronic Arts) Die Sims™ 3 Jahreszeiten (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts) Die Sims™ 3 Katy Perry Süße Welt (HKLM-x32\...\{9B2506E3-9A3F-45B5-96BF-509CAD584650}) (Version: 13.0.62 - Electronic Arts) Die Sims™ 3 Late Night (HKLM-x32\...\{45057FCE-5784-48BE-8176-D9D00AF56C3C}) (Version: 6.0.81 - Electronic Arts) Die Sims™ 3 Lebensfreude (HKLM-x32\...\{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}) (Version: 8.0.152 - Electronic Arts) Die Sims™ 3 Luxus-Accessoires (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts) Die Sims™ 3 Reiseabenteuer (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts) Die Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts) Die Sims™ 3 Stadt-Accessoires (HKLM-x32\...\{7B11296A-F894-449C-8DF6-6AAAA7D4D118}) (Version: 9.0.73 - Electronic Arts) Die Sims™ 3 Supernatural (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts) Die Sims™ 3 Traumkarrieren (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts) Die Sims™ 3 Traumsuite-Accessoires (HKLM-x32\...\{08A25478-C5DD-4EA7-B168-3D687CA987FF}) (Version: 11.0.84 - Electronic Arts) Die Sims™ 3 Wildes Studentenleben (HKLM-x32\...\{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}) (Version: 18.0.126 - Electronic Arts) Die*Sims™*3 Erstelle einen Sim (HKLM-x32\...\{89173B88-384A-459B-B687-9C0BBC934EF4}) (Version: 1.0.25 - Electronic Arts) EPSON BX535WD Series Printer Uninstall (HKLM\...\EPSON BX535WD Series) (Version: - SEIKO EPSON Corporation) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 26.0.1410.40 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle) Java 8 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418000FF}) (Version: 8.0.0 - Oracle Corporation) Java Auto Updater (x32 Version: 2.8.00.132 - Oracle, Inc.) Hidden Java SE Development Kit 8 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180000}) (Version: 8.0.0 - Oracle Corporation) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7069 - Realtek Semiconductor Corp.) SupraSavings (Version: 1.0.0.0 - SupraSavings) Hidden <==== ATTENTION TERA (HKLM-x32\...\{A2F166A0-F031-4E27-A057-C69733219434}_is1) (Version: 7 - Gameforge Productions GmbH) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2880505) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{2720451F-5D04-43EC-AB1F-26D948FD971B}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) WindowsProtectManger20.0.0.339 (HKLM-x32\...\WindowsProtectManger) (Version: 20.0.0.339 - Fuyu LIMITED) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 16-05-2014 17:19:05 Windows 7 Upgrade Advisor wird entfernt 25-05-2014 13:00:26 Geplanter Prüfpunkt 27-05-2014 20:15:00 Uniblue SpeedUpMyPC installation 28-05-2014 15:53:16 Windows Update 29-05-2014 17:44:42 Uniblue SpeedUpMyPC installation 03-06-2014 15:11:42 Windows 7 Upgrade Advisor wird installiert 03-06-2014 15:29:56 Windows 7 Upgrade Advisor wird entfernt 03-06-2014 20:52:52 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {3CA0BDA4-F691-4B4A-88BD-C3B2845FD68E} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {3D0C9D22-EE20-493E-92FB-BC73441C03D7} - \pricemeterwatcher No Task File <==== ATTENTION Task: {60931F6D-E815-4C87-9496-F3604D509BC6} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {63A38366-90C8-469B-BB67-EF64FD413970} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.) Task: {69ECAADD-4631-4AA8-8330-A6E0DC00619D} - \Browser Updater\Browser Updater No Task File <==== ATTENTION Task: {830435D2-63A9-4EAA-95E4-0D7B8D268103} - \pricemetertask No Task File <==== ATTENTION Task: {885674BE-AC97-41C5-8525-D35C15E927C6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20] (Google Inc.) Task: {8B7C3666-0168-45EC-8D9A-C00FDA29577F} - \PCHelpers_period No Task File <==== ATTENTION Task: {990C68CD-B079-425A-B425-D003C2120148} - \PCHelpers1st No Task File <==== ATTENTION Task: {B1DCDD67-ED3D-4B6A-9657-6020215D921A} - \ProtectedSearch\Protected Search No Task File <==== ATTENTION Task: {C534D9B9-EA45-404E-A926-B04760126944} - System32\Tasks\SystemSockets\SystemSockets => C:\Program Files (x86)\HomeTab\WBrokerHandler.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-06-03 18:24 - 2014-05-23 13:11 - 00640512 _____ () C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe 2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll 2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll 2014-04-03 20:07 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\Rike\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll 2014-06-03 18:24 - 2014-03-14 22:25 - 00236544 _____ () C:\Program Files (x86)\Flash Component Manager\sqlite3.dll 2014-03-20 07:50 - 2013-03-20 08:03 - 00598480 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libglesv2.dll 2014-03-20 07:50 - 2013-03-20 08:03 - 00124368 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\libegl.dll 2014-03-20 07:50 - 2013-03-20 08:04 - 04050896 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll 2014-03-20 07:50 - 2013-03-20 08:04 - 00390096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll 2014-03-20 07:50 - 2013-03-20 08:03 - 01606096 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ffmpegsumo.dll 2014-03-20 07:50 - 2013-03-20 08:04 - 12662224 _____ () C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SecureAssist => ""="service" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: USB (Universal Serial Bus)-Controller Description: USB (Universal Serial Bus)-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/05/2014 07:09:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/05/2014 06:52:34 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/03/2014 06:07:18 PM) (Source: MsiInstaller) (EventID: 11606) (User: Rike-PC) Description: Produkt: Driver Detective -- Fehler 1606. Zugriff auf die Netzwerkadresse hxxp://c4213555.r55.cf2.rackcdn.com/Produc~1.cab war nicht möglich. Error: (06/03/2014 05:20:24 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/03/2014 05:06:24 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/02/2014 05:43:59 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/01/2014 00:42:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/31/2014 03:27:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/29/2014 07:49:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: BlockAndSurfIx171.exe, Version: 1.171.0.0, Zeitstempel: 0x537e5167 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00038e19 ID des fehlerhaften Prozesses: 0x5d8 Startzeit der fehlerhaften Anwendung: 0xBlockAndSurfIx171.exe0 Pfad der fehlerhaften Anwendung: BlockAndSurfIx171.exe1 Pfad des fehlerhaften Moduls: BlockAndSurfIx171.exe2 Berichtskennung: BlockAndSurfIx171.exe3 Error: (05/29/2014 07:32:01 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (06/05/2014 07:06:59 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: ComputerstandardLokalAktivierung{EBE666C3-F26C-4CF6-8ABA-3D5F5D2625E1}Nicht verfügbarNT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC) Error: (06/05/2014 07:06:59 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: ComputerstandardLokalAktivierung{EBE666C3-F26C-4CF6-8ABA-3D5F5D2625E1}Nicht verfügbarNT-AUTORITÄTNETZWERKDIENSTS-1-5-20LocalHost (unter Verwendung von LRPC) Error: (06/05/2014 06:56:58 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Service Component of VO" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/03/2014 06:06:47 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Search Protect Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/03/2014 05:26:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Computer Backup (MyPC Backup)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (06/02/2014 05:43:29 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/02/2014 05:43:29 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (05/29/2014 07:49:00 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "BlockAndSurf" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/29/2014 07:28:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Wajam Internet Enhancer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (05/29/2014 07:28:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "IePlugin Services" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 20% Total physical RAM: 8119.99 MB Available physical RAM: 6426.7 MB Total Pagefile: 16238.16 MB Available Pagefile: 13939.59 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.14 GB) (Free:75.63 GB) NTFS Drive e: (Standard Laufwerk) (Fixed) (Total:931.51 GB) (Free:812.63 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 37FEC212) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 9FDCDD08) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=119 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
05.06.2014, 19:10 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell hi,
__________________Scan mit Combofix
__________________ |
05.06.2014, 19:20 | #3 |
| Windows 7: angeklickt flash player nicht aktuellCode:
ATTFilter ComboFix 14-06-04.01 - Rike 05.06.2014 20:16:21.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.8120.6365 [GMT 2:00] ausgeführt von:: c:\users\Rike\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Rike\AppData\Local\Microsoft\Windows\Temporary Internet Files\msi.png c:\users\Rike\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll . . ((((((((((((((((((((((( Dateien erstellt von 2014-05-05 bis 2014-06-05 )))))))))))))))))))))))))))))) . . 2014-06-05 17:24 . 2014-06-05 17:25 -------- d-----w- C:\FRST 2014-06-05 17:14 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll 2014-06-05 17:05 . 2014-06-05 17:14 -------- d-----w- C:\AdwCleaner 2014-06-05 17:00 . 2014-06-05 17:45 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-06-05 16:59 . 2014-06-05 16:59 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-06-05 16:59 . 2014-06-05 16:59 -------- d-----w- c:\programdata\Malwarebytes 2014-06-05 16:59 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-06-05 16:59 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-06-05 16:59 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-06-03 20:52 . 2014-06-03 20:52 -------- d-s---w- c:\windows\system32\CompatTel 2014-06-03 20:21 . 2014-05-22 16:19 61112 ----a-w- c:\windows\system32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-06-03 16:24 . 2014-06-03 16:24 -------- d-----w- c:\program files (x86)\Flash Component Manager 2014-06-03 15:23 . 2014-05-09 06:14 477184 ----a-w- c:\windows\system32\aepdu.dll 2014-06-03 15:23 . 2014-05-09 06:11 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-05-29 17:28 . 2014-04-09 05:55 34376 ----a-w- c:\windows\Launcher.exe 2014-05-27 20:19 . 2014-05-27 20:19 -------- d-----w- c:\programdata\WindowsProtectManger 2014-05-27 20:17 . 2014-05-27 20:17 -------- d-----w- c:\users\Rike\AppData\Local\com 2014-05-27 20:15 . 2014-06-05 17:06 -------- d-----w- C:\temp 2014-05-16 17:08 . 2014-05-16 17:08 -------- d-----w- c:\users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 17:04 . 2014-05-16 17:04 -------- d-sh--w- c:\users\Rike\AppData\Local\EmieUserList 2014-05-16 17:04 . 2014-05-16 17:04 -------- d-sh--w- c:\users\Rike\AppData\Local\EmieSiteList 2014-05-15 21:41 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll 2014-05-15 21:41 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-05-15 21:41 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-15 21:41 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-06-03 15:11 . 2014-04-03 18:07 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-06-03 15:11 . 2014-04-03 18:07 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-05-15 21:40 . 2014-04-05 16:24 93223848 ----a-w- c:\windows\system32\MRT.exe 2014-04-24 11:43 . 2014-04-24 11:45 10752 ----a-w- c:\windows\system32\E_GCINST.DLL 2014-04-24 11:43 . 2014-04-24 11:45 120320 ----a-w- c:\windows\system32\E_YLMHTU.DLL 2014-04-24 11:43 . 2014-04-24 11:45 83968 ----a-w- c:\windows\system32\E_YD4BHTU.DLL 2014-04-10 21:30 . 2014-04-10 21:30 312728 ----a-w- c:\windows\system32\javaws.exe 2014-04-10 21:30 . 2014-04-10 21:30 191384 ----a-w- c:\windows\system32\javaw.exe 2014-04-10 21:30 . 2014-04-10 21:30 190872 ----a-w- c:\windows\system32\java.exe 2014-04-10 21:30 . 2014-04-10 21:30 111000 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2014-04-10 20:05 . 2014-04-10 20:05 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-04-05 12:56 . 2014-04-05 12:56 283064 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2014-04-04 09:44 . 2014-04-04 09:44 84720 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL 2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2014-03-27 14:50 . 2014-03-27 14:50 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll 2014-03-25 21:04 . 2014-03-25 21:04 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2014-03-25 21:04 . 2014-03-25 21:04 942592 ----a-w- c:\windows\system32\jsIntl.dll 2014-03-25 21:04 . 2014-03-25 21:04 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2014-03-25 21:04 . 2014-03-25 21:04 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2014-03-25 21:04 . 2014-03-25 21:04 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2014-03-25 21:04 . 2014-03-25 21:04 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-03-25 21:04 . 2014-03-25 21:04 81408 ----a-w- c:\windows\system32\icardie.dll 2014-03-25 21:04 . 2014-03-25 21:04 774144 ----a-w- c:\windows\system32\jscript.dll 2014-03-25 21:04 . 2014-03-25 21:04 77312 ----a-w- c:\windows\system32\tdc.ocx 2014-03-25 21:04 . 2014-03-25 21:04 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2014-03-25 21:04 . 2014-03-25 21:04 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2014-03-25 21:04 . 2014-03-25 21:04 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2014-03-25 21:04 . 2014-03-25 21:04 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2014-03-25 21:04 . 2014-03-25 21:04 62464 ----a-w- c:\windows\system32\pngfilt.dll 2014-03-25 21:04 . 2014-03-25 21:04 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-03-25 21:04 . 2014-03-25 21:04 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2014-03-25 21:04 . 2014-03-25 21:04 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2014-03-25 21:04 . 2014-03-25 21:04 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2014-03-25 21:04 . 2014-03-25 21:04 48640 ----a-w- c:\windows\system32\mshtmler.dll 2014-03-25 21:04 . 2014-03-25 21:04 48128 ----a-w- c:\windows\system32\imgutil.dll 2014-03-25 21:04 . 2014-03-25 21:04 413696 ----a-w- c:\windows\system32\html.iec 2014-03-25 21:04 . 2014-03-25 21:04 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2014-03-25 21:04 . 2014-03-25 21:04 337408 ----a-w- c:\windows\SysWow64\html.iec 2014-03-25 21:04 . 2014-03-25 21:04 30208 ----a-w- c:\windows\system32\licmgr10.dll 2014-03-25 21:04 . 2014-03-25 21:04 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2014-03-25 21:04 . 2014-03-25 21:04 247808 ----a-w- c:\windows\system32\msls31.dll 2014-03-25 21:04 . 2014-03-25 21:04 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2014-03-25 21:04 . 2014-03-25 21:04 243200 ----a-w- c:\windows\system32\webcheck.dll 2014-03-25 21:04 . 2014-03-25 21:04 235520 ----a-w- c:\windows\system32\url.dll 2014-03-25 21:04 . 2014-03-25 21:04 235008 ----a-w- c:\windows\system32\elshyph.dll 2014-03-25 21:04 . 2014-03-25 21:04 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2014-03-25 21:04 . 2014-03-25 21:04 167424 ----a-w- c:\windows\system32\iexpress.exe 2014-03-25 21:04 . 2014-03-25 21:04 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2014-03-25 21:04 . 2014-03-25 21:04 147968 ----a-w- c:\windows\system32\occache.dll 2014-03-25 21:04 . 2014-03-25 21:04 143872 ----a-w- c:\windows\system32\wextract.exe 2014-03-25 21:04 . 2014-03-25 21:04 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2014-03-25 21:04 . 2014-03-25 21:04 13824 ----a-w- c:\windows\system32\mshta.exe 2014-03-25 21:04 . 2014-03-25 21:04 135680 ----a-w- c:\windows\system32\iepeers.dll 2014-03-25 21:04 . 2014-03-25 21:04 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2014-03-25 21:04 . 2014-03-25 21:04 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2014-03-25 21:04 . 2014-03-25 21:04 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2014-03-25 21:04 . 2014-03-25 21:04 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-03-25 21:04 . 2014-03-25 21:04 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2014-03-25 21:04 . 2014-03-25 21:04 105984 ----a-w- c:\windows\system32\iesysprep.dll 2014-03-25 21:04 . 2014-03-25 21:04 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-03-25 21:04 . 2014-03-25 21:04 101376 ----a-w- c:\windows\system32\inseng.dll 2014-03-25 13:51 . 2014-03-25 13:51 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2014-03-25 13:51 . 2014-03-25 13:51 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2014-03-25 13:51 . 2014-03-25 13:51 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2014-03-25 13:51 . 2014-03-25 13:51 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2014-03-25 13:51 . 2014-03-25 13:51 363008 ----a-w- c:\windows\system32\dxgi.dll 2014-03-25 13:51 . 2014-03-25 13:51 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2014-03-25 13:51 . 2014-03-25 13:51 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 296960 ----a-w- c:\windows\system32\d3d10core.dll 2014-03-25 13:51 . 2014-03-25 13:51 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2014-03-25 13:51 . 2014-03-25 13:51 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2014-03-25 13:51 . 2014-03-25 13:51 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2014-03-25 13:51 . 2014-03-25 13:51 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2014-03-25 13:51 . 2014-03-25 13:51 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2014-03-25 13:51 . 2014-03-25 13:51 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2014-03-25 13:51 . 2014-03-25 13:51 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2014-03-25 13:51 . 2014-03-25 13:51 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2014-03-25 13:51 . 2014-03-25 13:51 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2014-03-25 13:51 . 2014-03-25 13:51 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2014-03-25 13:51 . 2014-03-25 13:51 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll 2014-03-25 13:51 . 2014-03-25 13:51 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2014-03-25 13:51 . 2014-03-25 13:51 1643520 ----a-w- c:\windows\system32\DWrite.dll 2014-03-25 13:51 . 2014-03-25 13:51 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2014-03-25 13:51 . 2014-03-25 13:51 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2014-03-25 13:51 . 2014-03-25 13:51 1238528 ----a-w- c:\windows\system32\d3d10.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE" [2014-04-24 241280] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-12-06 766208] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-06-03 737872] "GrooveMonitor"="e:\programme\Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-05-05 182352] "Windows Servelet System Component"="c:\program files (x86)\Flash Component Manager\srvhelper32.exe" [2014-05-23 640512] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 MSICDSetup;MSICDSetup;d:\cdriver64.sys;d:\CDriver64.sys [x] R3 NTIOLib_1_0_C;NTIOLib_1_0_C;d:\ntiolib_x64.sys;d:\NTIOLib_X64.sys [x] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] S1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64;{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64;c:\windows\system32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys;c:\windows\SYSNATIVE\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe;c:\program files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [x] S2 WindowsProtectManger;WindowsProtectManger Service;c:\programdata\WindowsProtectManger\wprotectmanager.exe;c:\programdata\WindowsProtectManger\wprotectmanager.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-03-20 05:50 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.40\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20 05:50] . 2014-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-20 05:50] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-10-17 7202008] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:newtab uDefault_Search_URL = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mDefault_Page_URL = www.google.com mStart Page = about:newtab mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com mSearch Bar = hxxp://www.google.com uSearchURL,(Default) = hxxp://www.google.com/ IE: Nach Microsoft E&xel exportieren - e:\progra~1\Office\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 192.168.2.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-Activeris AntiMalware_is1 - c:\program files (x86)\Activeris AntiMalware\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1763780752-3024800267-2526177901-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.9" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}] @Denied: (A 2) (Everyone) @="IFlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Google\Chrome\Application\chrome.exe c:\program files (x86)\Google\Chrome\Application\chrome.exe c:\program files (x86)\Google\Chrome\Application\chrome.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-06-05 20:19:48 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-06-05 18:19 . Vor Suchlauf: 14 Verzeichnis(se), 81.942.360.064 Bytes frei Nach Suchlauf: 19 Verzeichnis(se), 81.884.700.672 Bytes frei . - - End Of File - - ED97F4E98A4980FB29FDB50AD1EFA9FA A36C5E4F47E84449FF07ED3517B43A31 |
06.06.2014, 18:33 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.06.2014, 01:00 | #5 |
| Windows 7: angeklickt flash player nicht aktuell mbam Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 07.06.2014 Suchlauf-Zeit: 01:49:16 Logdatei: mbam2.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.06.11 Rootkit Datenbank: v2014.06.02.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Rike Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 268192 Verstrichene Zeit: 2 Min, 8 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 07/06/2014 um 01:52:34 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Rike - RIKE-PC # Gestartet von : E:\Downloads\adwcleaner_3.212.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : WindowsProtectManger ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\WindowsProtectManger Datei Gelöscht : C:\Windows\System32\Tasks\Browser Updater Datei Gelöscht : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\nhjnmokdaalmckkikjklibeakholpham Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS Schlüssel Gelöscht : HKLM\Software\SupDp ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Google Chrome v26.0.1410.40 [ Datei : C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms} Gelöscht [Search Provider] : hxxp://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.3&ts=1401384488387&tguid=80415-23890-1401384488387-5AAF4764967E0034BB5FF62D067605A9&q={searchTerms} Gelöscht [Extension] : nhjnmokdaalmckkikjklibeakholpham ************************* AdwCleaner[R0].txt - [10134 octets] - [05/06/2014 19:07:06] AdwCleaner[R1].txt - [1029 octets] - [05/06/2014 19:14:12] AdwCleaner[R2].txt - [1549 octets] - [07/06/2014 01:52:20] AdwCleaner[S0].txt - [8583 octets] - [05/06/2014 19:07:27] AdwCleaner[S1].txt - [1735 octets] - [07/06/2014 01:52:34] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1795 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Professional x64 Ran by Rike on 07.06.2014 at 1:54:04,73 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 07.06.2014 at 1:57:29,76 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-06-2014 Ran by Rike (administrator) on RIKE-PC on 07-06-2014 01:58:20 Running from E:\Downloads Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHTU.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202008 2013-10-17] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [GrooveMonitor] => E:\Programme\Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Windows Servelet System Component] => C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe [640512 2014-05-23] () HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Programme\Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Programme\Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - E:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: about:newtab?source=home CHR RestoreOnStartup: "about:newtab?source=home" CHR StartupUrls: "about:newtab?source=home" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (YouTube) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Google Mail) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 Microsoft Office Groove Audit Service; E:\Programme\Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-05] (Disc Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-07] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-05-22] (StdLib) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-07 01:57 - 2014-06-07 01:57 - 00000624 _____ () C:\Users\Rike\Desktop\JRT.txt 2014-06-07 01:54 - 2014-06-07 01:54 - 00000000 ____D () C:\Windows\ERUNT 2014-06-05 20:19 - 2014-06-05 20:19 - 00023715 _____ () C:\ComboFix.txt 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\Qoobox 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\ComboFix 2014-06-05 20:15 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-05 20:15 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-05 20:15 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-05 20:14 - 2014-06-05 20:14 - 05205146 ____R (Swearware) C:\Users\Rike\Desktop\ComboFix.exe 2014-06-05 19:24 - 2014-06-07 01:58 - 00000000 ____D () C:\FRST 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-05 19:05 - 2014-06-07 01:52 - 00000000 ____D () C:\AdwCleaner 2014-06-05 19:00 - 2014-06-07 01:53 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-05 18:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-05 18:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-05 18:55 - 2014-06-07 01:57 - 01150976 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-05 18:53 - 2014-04-09 17:39 - 00000426 _____ () C:\AVScanner.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 22:21 - 2014-05-22 18:19 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager 2014-06-03 17:23 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-03 17:23 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-03 17:08 - 2014-06-05 18:59 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-04-09 07:55 - 00034376 _____ () C:\Windows\Launcher.exe 2014-05-27 22:30 - 2014-06-03 18:07 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-27 22:15 - 2014-06-05 19:06 - 00000000 ____D () C:\temp 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-15 23:41 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 23:41 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 23:41 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 23:41 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 18:25 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 18:25 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 18:25 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 18:25 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 18:25 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 18:25 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 18:25 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 18:25 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 18:25 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll ==================== One Month Modified Files and Folders ======= 2014-06-07 01:58 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST 2014-06-07 01:58 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike\AppData\Local\Temp 2014-06-07 01:57 - 2014-06-07 01:57 - 00000624 _____ () C:\Users\Rike\Desktop\JRT.txt 2014-06-07 01:57 - 2014-06-05 18:55 - 01150976 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-07 01:57 - 2014-03-20 14:58 - 00699092 _____ () C:\Windows\system32\perfh007.dat 2014-06-07 01:57 - 2014-03-20 14:58 - 00149232 _____ () C:\Windows\system32\perfc007.dat 2014-06-07 01:57 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-07 01:55 - 2014-03-20 07:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-07 01:54 - 2014-06-07 01:54 - 00000000 ____D () C:\Windows\ERUNT 2014-06-07 01:53 - 2014-06-05 19:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-07 01:53 - 2014-03-20 07:50 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-07 01:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-07 01:53 - 2009-07-14 06:51 - 00008561 _____ () C:\Windows\setupact.log 2014-06-07 01:52 - 2014-06-05 19:05 - 00000000 ____D () C:\AdwCleaner 2014-06-07 01:52 - 2014-03-20 07:29 - 01387669 _____ () C:\Windows\WindowsUpdate.log 2014-06-07 01:52 - 2010-11-21 05:47 - 00380836 _____ () C:\Windows\PFRO.log 2014-06-07 01:52 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-07 01:52 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-05 22:36 - 2014-04-05 19:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\.minecraft 2014-06-05 22:31 - 2014-03-20 07:37 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-05 20:19 - 2014-06-05 20:19 - 00023715 _____ () C:\ComboFix.txt 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\Qoobox 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\ComboFix 2014-06-05 20:18 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-05 20:14 - 2014-06-05 20:14 - 05205146 ____R (Swearware) C:\Users\Rike\Desktop\ComboFix.exe 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:23 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-06-05 19:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas 2014-06-05 19:06 - 2014-05-27 22:15 - 00000000 ____D () C:\temp 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-03 17:08 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-05 18:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-05 18:53 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager 2014-06-03 18:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-06-03 18:07 - 2014-05-27 22:30 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-06-03 17:26 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-02 21:14 - 2014-03-20 07:50 - 00002317 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-03-20 07:29 - 00001425 _____ () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-22 18:19 - 2014-06-03 22:21 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-05-17 15:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-16 19:02 - 2014-04-09 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-16 07:40 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-16 07:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-15 23:41 - 2014-04-05 15:00 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 23:40 - 2014-04-05 18:24 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-15 23:40 - 2014-04-05 18:24 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-12 07:26 - 2014-06-05 18:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-05 18:59 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-05 18:59 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 08:14 - 2014-06-03 17:23 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-06-03 17:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll Some content of TEMP: ==================== C:\Users\Rike\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-31 15:51 ==================== End Of Log ============================ --- --- --- |
07.06.2014, 18:56 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuellESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7: angeklickt flash player nicht aktuell |
09.06.2014, 18:26 | #7 |
| Windows 7: angeklickt flash player nicht aktuell ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=01c6414ee49ff749b80971cb56fec3a3 # engine=18633 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-06-09 05:18:36 # local_time=2014-06-09 07:18:36 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 280471 153964166 0 0 # scanned=151866 # found=10 # cleaned=0 # scan_time=995 sh=B992ED7A1B4DF30F6AF8A911FBFDE92ED9F77519 ft=1 fh=5dac4dde3cd39976 vn="Variante von MSIL/DomaIQ.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Uninstaller\Uninstall.exe.vir" sh=9BA6DC699104472080E202066F9A6194C861BBC4 ft=1 fh=644180d9ce5cd441 vn="Win32/AnyProtect.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Rike\AppData\Local\AnyProtectScannerSetup.exe.vir" sh=3780AB283C5F6D27714C3688E9BB5A35C3D999C9 ft=1 fh=0c867f66af9d310c vn="Win32/VOPackage.H evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Rike\AppData\Roaming\VOPackage\runasu.exe.vir" sh=A81F02B40EBAACA1AF310DDCFA18C16C234F13DA ft=1 fh=53234b49fd8c4d85 vn="Variante von Win32/Tivmonk.B Trojaner" ac=I fn="C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe" sh=ED72BED62EDF66FF58D4E363FCE190896E4A3A90 ft=1 fh=4c1bb94b1f76afc1 vn="Variante von Win32/DomaIQ.BB evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000000" sh=4FCC57C805813D32AC74A2194D724998A02C1ECB ft=1 fh=cf4cec33969fc1f9 vn="Variante von Win32/DomaIQ.BH evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000002" sh=FFA0968CA7CBA76FD373270CA584604438191162 ft=1 fh=51e4cde2e7dee00a vn="Variante von Win32/DomaIQ.BB evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\File System\003\t\00\00000004" sh=8AA2390BBA16C77FFF6ABB55416A996061F64B3A ft=1 fh=04ec2d34ccd92a1d vn="Variante von Win32/SoftPulse.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\File System\004\t\00\00000000" sh=0730F3D050959A72D0552A8231A803A2807CA7BB ft=1 fh=fd26318becbcfbc5 vn="Variante von Win32/Tivmonk.B Trojaner" ac=I fn="C:\Users\Rike\Downloads\Flash-3-Update5232014.exe" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Tivmonk.B Trojaner" ac=I fn="${Memory}" Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 51 Java version out of Date! Adobe Reader XI Google Chrome 26.0.1410.40 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 02 Ran by Rike (administrator) on RIKE-PC on 09-06-2014 19:31:51 Running from E:\Downloads Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHTU.EXE (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202008 2013-10-17] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [GrooveMonitor] => E:\Programme\Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Windows Servelet System Component] => C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe [640512 2014-05-23] () HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Programme\Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Programme\Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - E:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: about:newtab?source=home CHR RestoreOnStartup: "about:newtab?source=home" CHR StartupUrls: "about:newtab?source=home" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (YouTube) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Google Mail) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 Microsoft Office Groove Audit Service; E:\Programme\Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-05] (Disc Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-09] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-05-22] (StdLib) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-09 19:21 - 2014-06-09 19:21 - 00854367 _____ () C:\Users\Rike\Desktop\SecurityCheck.exe 2014-06-09 18:50 - 2014-06-09 18:50 - 00001178 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\TeamViewer 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-06-07 01:54 - 2014-06-07 01:54 - 00000000 ____D () C:\Windows\ERUNT 2014-06-05 20:19 - 2014-06-05 20:19 - 00023715 _____ () C:\ComboFix.txt 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\Qoobox 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\ComboFix 2014-06-05 20:15 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-05 20:15 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-05 20:15 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-05 19:24 - 2014-06-09 19:31 - 00000000 ____D () C:\FRST 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-05 19:05 - 2014-06-07 01:52 - 00000000 ____D () C:\AdwCleaner 2014-06-05 19:00 - 2014-06-09 18:30 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-05 18:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-05 18:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-05 18:55 - 2014-06-09 19:28 - 01208320 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-05 18:53 - 2014-04-09 17:39 - 00000426 _____ () C:\AVScanner.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 22:21 - 2014-05-22 18:19 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager 2014-06-03 17:23 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-03 17:23 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-03 17:08 - 2014-06-05 18:59 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-04-09 07:55 - 00034376 _____ () C:\Windows\Launcher.exe 2014-05-27 22:30 - 2014-06-03 18:07 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-27 22:15 - 2014-06-05 19:06 - 00000000 ____D () C:\temp 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-15 23:41 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 23:41 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 23:41 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 23:41 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 18:25 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 18:25 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 18:25 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 18:25 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 18:25 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 18:25 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 18:25 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 18:25 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 18:25 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll ==================== One Month Modified Files and Folders ======= 2014-06-09 19:31 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST 2014-06-09 19:31 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike\AppData\Local\Temp 2014-06-09 19:28 - 2014-06-05 18:55 - 01208320 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-09 19:21 - 2014-06-09 19:21 - 00854367 _____ () C:\Users\Rike\Desktop\SecurityCheck.exe 2014-06-09 18:55 - 2014-03-20 07:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-09 18:50 - 2014-06-09 18:50 - 00001178 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\TeamViewer 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-06-09 18:30 - 2014-06-05 19:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-09 13:03 - 2014-03-20 07:29 - 01441430 _____ () C:\Windows\WindowsUpdate.log 2014-06-09 12:43 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-09 12:43 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-09 12:42 - 2014-03-20 14:58 - 00699092 _____ () C:\Windows\system32\perfh007.dat 2014-06-09 12:42 - 2014-03-20 14:58 - 00149232 _____ () C:\Windows\system32\perfc007.dat 2014-06-09 12:42 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-09 12:36 - 2014-03-20 07:50 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-09 12:36 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-09 12:36 - 2009-07-14 06:51 - 00008785 _____ () C:\Windows\setupact.log 2014-06-08 17:52 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-07 01:54 - 2014-06-07 01:54 - 00000000 ____D () C:\Windows\ERUNT 2014-06-07 01:52 - 2014-06-05 19:05 - 00000000 ____D () C:\AdwCleaner 2014-06-07 01:52 - 2010-11-21 05:47 - 00380836 _____ () C:\Windows\PFRO.log 2014-06-05 22:36 - 2014-04-05 19:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\.minecraft 2014-06-05 22:31 - 2014-03-20 07:37 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-05 20:19 - 2014-06-05 20:19 - 00023715 _____ () C:\ComboFix.txt 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\Qoobox 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\ComboFix 2014-06-05 20:18 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:23 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-06-05 19:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas 2014-06-05 19:06 - 2014-05-27 22:15 - 00000000 ____D () C:\temp 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-03 17:08 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-05 18:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-05 18:53 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 18:24 - 2014-06-03 18:24 - 01350991 _____ (Openersoft ) C:\Users\Rike\Downloads\Flash-3-Update5232014.exe 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\Program Files (x86)\Flash Component Manager 2014-06-03 18:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-06-03 18:07 - 2014-05-27 22:30 - 00000444 __RSH () C:\ProgramData\ntuser.pol 2014-06-03 17:26 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-02 21:14 - 2014-03-20 07:50 - 00002317 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-03-20 07:29 - 00001425 _____ () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-22 18:19 - 2014-06-03 22:21 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys 2014-05-17 15:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-16 19:02 - 2014-04-09 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-16 07:40 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-16 07:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-15 23:41 - 2014-04-05 15:00 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 23:40 - 2014-04-05 18:24 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-15 23:40 - 2014-04-05 18:24 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-12 07:26 - 2014-06-05 18:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-05 18:59 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-05 18:59 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys Some content of TEMP: ==================== C:\Users\Rike\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-08 18:58 ==================== End Of Log ============================ wars das dann? wenn ja dann bedanke ich mich mal für die Hilfe dabei wollte ich gleich mal fragen ob wir beim laptop meiner Tante weiter machen können? Sie hat von ihrer Bank einen Brief erhalten das ihr Online Banking gesperrt wurde, weil ihre Daten auf einem fremden Server gefunden wurden, deswegen sollte man mal ihren Laptop untersuchen. Geändert von Seppiro (09.06.2014 um 18:34 Uhr) |
10.06.2014, 14:16 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell Java updaten. Flash Component Manager deinstallierne. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Program Files (x86)\Flash Component Manager C:\Users\Rike\Downloads\Flash-3-Update5232014.exe HKLM-x32\...\Run: [Windows Servelet System Component] => C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe [640512 2014-05-23] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-05-22] (StdLib) C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. Wenn wir hier fertig sind können wir den Rechner der Tante anschauen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.06.2014, 19:52 | #9 |
| Windows 7: angeklickt flash player nicht aktuell leider hab ich das Programm "Flash Component Manager" nich in "Programme und Funktionen" gefunden nur einen Ordner in Programme(x86) der sich nicht löschen ließ Fix Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-06-2014 02 Ran by Rike at 2014-06-10 20:28:47 Run:1 Running from E:\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Program Files (x86)\Flash Component Manager C:\Users\Rike\Downloads\Flash-3-Update5232014.exe HKLM-x32\...\Run: [Windows Servelet System Component] => C:\Program Files (x86)\Flash Component Manager\srvhelper32.exe [640512 2014-05-23] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION R1 {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64; C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys [61112 2014-05-22] (StdLib) C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys ***************** C:\Program Files (x86)\Flash Component Manager => Moved successfully. C:\Users\Rike\Downloads\Flash-3-Update5232014.exe => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Windows Servelet System Component => value deleted successfully. C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64 => Service stopped successfully. {9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64 => Service deleted successfully. C:\Windows\System32\drivers\{9acd1534-e8f8-40cb-b5ac-4996fe01175b}w64.sys => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 02 Ran by Rike (administrator) on RIKE-PC on 10-06-2014 20:49:51 Running from E:\Downloads Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHTU.EXE (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202008 2013-10-17] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [GrooveMonitor] => E:\Programme\Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKU\S-1-5-21-1763780752-3024800267-2526177901-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE [241280 2014-04-24] (SEIKO EPSON CORPORATION) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Programme\Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Programme\Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF Plugin: @java.com/DTPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.0.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - E:\Programme\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: about:newtab?source=home CHR RestoreOnStartup: "about:newtab?source=home" CHR StartupUrls: "about:newtab?source=home" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.40\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Extension: (Google Docs) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20] CHR Extension: (Google Drive) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20] CHR Extension: (YouTube) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20] CHR Extension: (Google-Suche) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20] CHR Extension: (Google Mail) - C:\Users\Rike\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20] ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 Microsoft Office Groove Audit Service; E:\Programme\Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-04-05] (Disc Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-10] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-09 19:21 - 2014-06-09 19:21 - 00854367 _____ () C:\Users\Rike\Desktop\SecurityCheck.exe 2014-06-09 18:50 - 2014-06-09 18:50 - 00001178 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\TeamViewer 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-06-07 01:54 - 2014-06-07 01:54 - 00000000 ____D () C:\Windows\ERUNT 2014-06-05 20:19 - 2014-06-05 20:19 - 00023715 _____ () C:\ComboFix.txt 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\Qoobox 2014-06-05 20:15 - 2014-06-05 20:19 - 00000000 ____D () C:\ComboFix 2014-06-05 20:15 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-06-05 20:15 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-06-05 20:15 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-06-05 20:15 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-06-05 19:24 - 2014-06-10 20:49 - 00000000 ____D () C:\FRST 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-05 19:05 - 2014-06-07 01:52 - 00000000 ____D () C:\AdwCleaner 2014-06-05 19:00 - 2014-06-10 20:30 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-05 18:59 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-05 18:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-06-05 18:55 - 2014-06-10 20:16 - 01216512 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-05 18:53 - 2014-04-09 17:39 - 00000426 _____ () C:\AVScanner.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 17:23 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-03 17:23 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-03 17:08 - 2014-06-05 18:59 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-05-29 19:28 - 2014-06-05 19:07 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-04-09 07:55 - 00034376 _____ () C:\Windows\Launcher.exe 2014-05-27 22:30 - 2014-06-10 20:30 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-27 22:15 - 2014-06-05 19:06 - 00000000 ____D () C:\temp 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-15 23:41 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 23:41 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 23:41 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 23:41 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 23:41 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-15 18:25 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-15 18:25 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-15 18:25 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-15 18:25 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-15 18:25 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-15 18:25 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-15 18:25 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-15 18:25 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-15 18:25 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-15 18:25 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-15 18:25 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-15 18:25 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-15 18:25 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-15 18:25 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll ==================== One Month Modified Files and Folders ======= 2014-06-10 20:49 - 2014-06-05 19:24 - 00000000 ____D () C:\FRST 2014-06-10 20:49 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike\AppData\Local\Temp 2014-06-10 20:37 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-10 20:37 - 2009-07-14 06:45 - 00025872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-10 20:34 - 2014-03-20 14:58 - 00699092 _____ () C:\Windows\system32\perfh007.dat 2014-06-10 20:34 - 2014-03-20 14:58 - 00149232 _____ () C:\Windows\system32\perfc007.dat 2014-06-10 20:34 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-10 20:30 - 2014-06-05 19:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-10 20:30 - 2014-05-27 22:30 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-06-10 20:30 - 2014-03-20 07:50 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-10 20:30 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-10 20:30 - 2009-07-14 06:51 - 00008897 _____ () C:\Windows\setupact.log 2014-06-10 20:29 - 2014-03-20 07:29 - 01586436 _____ () C:\Windows\WindowsUpdate.log 2014-06-10 20:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-10 20:16 - 2014-06-05 18:55 - 01216512 _____ () C:\Users\Rike\AppData\Local\ChromeHitoryDB 2014-06-10 19:55 - 2014-03-20 07:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-10 19:45 - 2014-03-20 07:42 - 00109296 _____ () C:\Users\Rike\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-10 19:45 - 2010-11-21 05:47 - 00381670 _____ () C:\Windows\PFRO.log 2014-06-10 19:45 - 2009-07-14 06:45 - 00415048 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-09 19:21 - 2014-06-09 19:21 - 00854367 _____ () C:\Users\Rike\Desktop\SecurityCheck.exe 2014-06-09 18:50 - 2014-06-09 18:50 - 00001178 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00001166 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\TeamViewer 2014-06-09 18:50 - 2014-06-09 18:50 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-06-08 17:52 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-07 01:54 - 2014-06-07 01:54 - 00000000 ____D () C:\Windows\ERUNT 2014-06-07 01:52 - 2014-06-05 19:05 - 00000000 ____D () C:\AdwCleaner 2014-06-05 22:36 - 2014-04-05 19:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\.minecraft 2014-06-05 22:31 - 2014-03-20 07:37 - 00000000 ____D () C:\ProgramData\Package Cache 2014-06-05 20:19 - 2014-06-05 20:19 - 00023715 _____ () C:\ComboFix.txt 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:19 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\Windows\erdnt 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\Qoobox 2014-06-05 20:19 - 2014-06-05 20:15 - 00000000 ____D () C:\ComboFix 2014-06-05 20:18 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-06-05 19:23 - 2014-06-05 19:23 - 00000148 _____ () C:\Users\Rike\defogger_reenable 2014-06-05 19:23 - 2014-03-20 07:29 - 00000000 ____D () C:\Users\Rike 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\ProtectedSearch 2014-06-05 19:07 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater 2014-06-05 19:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\schemas 2014-06-05 19:06 - 2014-05-27 22:15 - 00000000 ____D () C:\temp 2014-06-05 18:59 - 2014-06-05 18:59 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-05 18:59 - 2014-06-05 18:59 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-05 18:59 - 2014-06-03 17:08 - 00105580 _____ () C:\Windows\SysWOW64\console.log 2014-06-05 18:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-05 18:53 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini 2014-06-03 22:52 - 2014-06-03 22:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-03 18:24 - 2014-06-03 18:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flash Component Manager 2014-06-03 18:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-06-03 17:26 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-02 21:14 - 2014-06-02 21:14 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-02 21:14 - 2014-03-20 07:50 - 00002317 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-05-29 19:28 - 2014-05-29 19:28 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets 2014-05-29 19:28 - 2014-03-20 07:29 - 00001425 _____ () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-05-27 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-05-27 22:29 - 2014-05-27 22:29 - 00000000 ____D () C:\Users\Rike\AppData\Roaming\Macromedia 2014-05-27 22:23 - 2014-05-27 22:23 - 00003112 _____ () C:\Windows\System32\Tasks\{094D1062-7EF6-4178-B435-6D5112E30493} 2014-05-27 22:17 - 2014-05-27 22:17 - 00000000 ____D () C:\Users\Rike\AppData\Local\com 2014-05-17 15:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-16 19:08 - 2014-05-16 19:08 - 00000000 ____D () C:\Users\Rike\AppData\Local\Microsoft Corporation 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieUserList 2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 __SHD () C:\Users\Rike\AppData\Local\EmieSiteList 2014-05-16 19:02 - 2014-04-09 16:18 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-16 07:40 - 2014-03-20 07:29 - 00000000 ___RD () C:\Users\Rike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-16 07:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-05-15 23:41 - 2014-04-05 15:00 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-15 23:40 - 2014-04-05 18:24 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-15 23:40 - 2014-04-05 18:24 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-12 07:26 - 2014-06-05 18:59 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-05 18:59 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-06-05 18:59 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys Some content of TEMP: ==================== C:\Users\Rike\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-08 18:58 ==================== End Of Log ============================ |
11.06.2014, 19:57 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.06.2014, 20:05 | #11 |
| Windows 7: angeklickt flash player nicht aktuell alles klar dann danke für die Hilfe können wir dann beim Laptop meiner Tante weitermachen? |
12.06.2014, 08:16 | #12 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell jup, poste mal FRST logs
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.06.2014, 11:03 | #13 |
| Windows 7: angeklickt flash player nicht aktuell k vielen dank nochmal FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014 Ran by eva (administrator) on EVA-HP on 12-06-2014 11:57:09 Running from C:\Users\eva\Desktop Platform: Microsoft Windows 7 Home Premium (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\stacsv.exe (AMD) C:\Windows\System32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Windows\System32\atibtmon.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\AEstSrv.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe (PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe () C:\Program Files\FindRight\updateFindRight.exe () C:\Program Files\FindRight\bin\utilFindRight.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe (Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company) HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard) HKLM\...\Run: [Microsoft Default Manager] => C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM\...\Run: [McAfee Managed Services Tray] => C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.Exe [476480 2010-02-17] (McAfee, Inc.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-05] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-17] (IDT, Inc.) HKLM\...\Run: [NortonOnlineBackupReminder] => C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKU\S-1-5-21-2839968430-3032943032-2816752695-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company) HKU\S-1-5-21-2839968430-3032943032-2816752695-1001\...\MountPoints2: {1c3f02cb-556b-11e3-a9c1-806e6f6e6963} - F:\Setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/10 BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100909125144.dll (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.) BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - @C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.) Handler: myrm - {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\myRmProt5.1.0.325.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @Microsoft.com/NpWinExt,version=5.0 - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) FF HKLM\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\Firefox FF Extension: Bing Bar - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-09-09] FF HKLM\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ FF Extension: Search Helper Extension - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [] FF HKLM\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ FF Extension: Default Manager - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [] FF HKLM\...\Firefox\Extensions: [{B7082FAA-CB62-4872-9106-E42DD88EDE45}] - C:\Program Files\McAfee\SiteAdvisor Enterprise\ FF Extension: McAfee SiteAdvisor Enterprise - C:\Program Files\McAfee\SiteAdvisor Enterprise\ [] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-01] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-01] ========================== Services (Whitelisted) ================= R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [121344 2010-07-01] (Hewlett-Packard Company) [File not signed] R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard) R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed] R2 McAfee SiteAdvisor Enterprise Service; C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe [222528 2009-08-07] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [170144 2010-02-04] (McAfee, Inc.) R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [141792 2010-02-08] (McAfee, Inc.) R2 MpfService; C:\Program Files\McAfee\MPF\MPFSrv.exe [893112 2009-05-09] (McAfee, Inc.) R2 myAgtSvc; C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe [282824 2010-02-17] (McAfee, Inc.) R2 Net Driver HPZ12; C:\windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc) R2 Pml Driver HPZ12; C:\windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\STacSV.exe [229458 2010-03-17] (IDT, Inc.) R2 Update FindRight; C:\Program Files\FindRight\updateFindRight.exe [317728 2014-06-11] () R2 Util FindRight; C:\Program Files\FindRight\bin\utilFindRight.exe [317728 2014-06-11] () ==================== Drivers (Whitelisted) ==================== R3 mfeapfk; C:\windows\System32\drivers\mfeapfk.sys [95728 2010-02-08] (McAfee, Inc.) R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [152736 2010-02-08] (McAfee, Inc.) R3 mfebopk; C:\windows\System32\drivers\mfebopk.sys [51720 2010-02-08] (McAfee, Inc.) R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [385184 2010-02-08] (McAfee, Inc.) S3 mferkdet; C:\windows\System32\drivers\mferkdet.sys [83912 2010-02-08] (McAfee, Inc.) R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [160912 2010-02-08] (McAfee, Inc.) R1 MPFP; C:\windows\System32\Drivers\Mpfp.sys [130424 2009-04-09] (McAfee, Inc.) R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-04-27] () R1 {42e50651-9669-456e-9081-d5a836274274}w; C:\windows\System32\drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys [52920 2014-05-30] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-12 11:57 - 2014-06-12 11:57 - 00014195 _____ () C:\Users\eva\Desktop\FRST.txt 2014-06-12 11:57 - 2014-06-12 11:57 - 00000000 ____D () C:\FRST 2014-06-12 11:56 - 2014-06-12 11:56 - 01073152 _____ (Farbar) C:\Users\eva\Desktop\FRST.exe 2014-06-02 09:25 - 2014-05-30 14:25 - 00052920 _____ (StdLib) C:\windows\system32\Drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys ==================== One Month Modified Files and Folders ======= 2014-06-12 11:58 - 2013-11-24 18:05 - 00000000 ____D () C:\Users\eva\AppData\Local\Temp 2014-06-12 11:57 - 2014-06-12 11:57 - 00014195 _____ () C:\Users\eva\Desktop\FRST.txt 2014-06-12 11:57 - 2014-06-12 11:57 - 00000000 ____D () C:\FRST 2014-06-12 11:56 - 2014-06-12 11:56 - 01073152 _____ (Farbar) C:\Users\eva\Desktop\FRST.exe 2014-06-12 11:56 - 2013-11-24 18:05 - 00167457 _____ () C:\windows\WindowsUpdate.log 2014-06-12 11:52 - 2010-09-09 21:57 - 00010988 _____ () C:\windows\PFRO.log 2014-06-12 11:52 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-12 11:52 - 2009-07-14 06:39 - 00101930 _____ () C:\windows\setupact.log 2014-06-11 21:31 - 2010-09-09 21:52 - 00006923 _____ () C:\windows\system32\Config.MPF 2014-06-11 21:14 - 2009-07-14 06:34 - 00019536 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-11 21:14 - 2009-07-14 06:34 - 00019536 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-11 21:11 - 2010-09-09 20:53 - 01472002 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-11 21:09 - 2009-07-14 04:04 - 00000540 _____ () C:\windows\win.ini 2014-06-11 21:08 - 2010-09-09 21:09 - 00000000 ____D () C:\ProgramData\PDFC 2014-06-03 16:35 - 2013-12-01 21:35 - 00000284 _____ () C:\windows\Tasks\UpdaterEX.job 2014-05-30 14:25 - 2014-06-02 09:25 - 00052920 _____ (StdLib) C:\windows\system32\Drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys Some content of TEMP: ==================== C:\Users\eva\AppData\Local\Temp\CpqMC.dll C:\Users\eva\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\eva\AppData\Local\Temp\HPQSi.exe C:\Users\eva\AppData\Local\Temp\lowproc.exe C:\Users\eva\AppData\Local\Temp\stubhelper.dll ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-03-13 22:23 ==================== End Of Log ============================ Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:12-06-2014 Ran by eva at 2014-06-12 11:58:06 Running from C:\Users\eva\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: McAfee® Total Protection™ Service (Disabled - Out of date) {86355677-4064-3EA7-ABB3-1B136EB04637} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee® Total Protection™ Service (Disabled - Out of date) {3D54B793-665E-3129-9103-206115370C8A} FW: McAfee® Total Protection™ Service (Disabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C} ==================== Installed Programs ====================== 32 Bit HP CIO Components Installer (Version: 6.1.1 - Hewlett-Packard) Hidden 4500_G510nz_Help (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz (Version: 000.0.439.000 - Hewlett-Packard) Hidden 4500G510nz_Software_Min (Version: 000.0.423.000 - Hewlett-Packard) Hidden ActiveCheck component for HP Active Support Library (Version: 3.0.0.3 - Hewlett-Packard) Hidden Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated) Aff Packages (HKCU\...\Aff Packages) (Version: - ) <==== ATTENTION ATI Catalyst Install Manager (HKLM\...\{D9273F52-B929-E315-D82B-EDF384D53924}) (Version: 3.0.778.0 - ATI Technologies, Inc.) Bing Bar (HKLM\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 6.0.2237.0 - Microsoft Corporation) Bing Bar Platform (Version: 6.0.2237.0 - Microsoft Corporation) Hidden Bing Rewards Client Installer (Version: 16.0.345.0 - Microsoft Corporation) Hidden Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.350.6 - Broadcom Corporation) BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden Catalyst Control Center InstallProxy (Version: 2010.0805.358.5180 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (Version: 2010.0805.358.5180 - ATI) Hidden CCC Help Chinese Standard (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Chinese Traditional (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Czech (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Danish (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Dutch (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help English (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Finnish (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help French (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help German (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Greek (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Hungarian (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Italian (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Japanese (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Korean (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Norwegian (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Polish (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Portuguese (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Russian (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Spanish (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Swedish (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Thai (Version: 2010.0805.0357.5180 - ATI) Hidden CCC Help Turkish (Version: 2010.0805.0357.5180 - ATI) Hidden ccc-core-static (Version: 2010.0805.358.5180 - ATI) Hidden ccc-utility (Version: 2010.0805.358.5180 - ATI) Hidden Corel Home Office - CS Templates (Version: 5.6.5 - 公司名称) Hidden Corel Home Office - CT Templates (Version: 5.6.5 - 您的公司名稱) Hidden Corel Home Office - IPM (Version: 5.6.5 - Corel Corporation) Hidden Corel Home Office - JP Templates (Version: 5.6.5 - 会社名) Hidden Corel Home Office - KR Templates (Version: 5.6.5 - 회사명) Hidden Corel Home Office - Launcher (Version: 5.6.5 - Corel Corporation) Hidden Corel Home Office - Templates RU (Version: 5.6.5 - Название организации) Hidden Corel Home Office - Templates1 (Version: 5.6.5 - Your Company Name) Hidden Corel Home Office (HKLM\...\_{36C95AD3-D330-4BAA-884A-9F3EFD15A5EA}) (Version: 5.0.87.621 - Corel Corporation) Corel Home Office (Version: 5.6.5 - Corel Corporation) Hidden Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden DocMgr (Version: 130.0.000.000 - Ihr Firmenname) Hidden DocProc (Version: 13.0.0.0 - Hewlett-Packard) Hidden Energy Star Digital Logo (HKLM\...\{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}) (Version: 1.0.1 - Hewlett-Packard) Extended Update (HKCU\...\UpdaterEX) (Version: - ) <==== ATTENTION Fax (Version: 130.0.418.000 - Hewlett-Packard) Hidden ffdshow v1.1.3425 [2010-05-08] (HKLM\...\ffdshow_is1) (Version: 1.1.3425.0 - ) FindRight (HKLM\...\FindRight) (Version: 2014.02.19.020818 - FindRight) <==== ATTENTION GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Advisor (HKLM\...\{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}) (Version: 3.4.10262.3295 - Hewlett-Packard) HP Customer Experience Enhancements (Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP) HP Documentation (HKLM\...\{C1DE827D-8A61-4A77-9CCF-31AD84CC1FB6}) (Version: 1.5.1.0 - Hewlett-Packard) HP ESU for Microsoft Windows 7 (HKLM\...\{D9989A13-B173-4048-B8A5-93C204DCB1B3}) (Version: 1.1.6.1 - Hewlett-Packard Company) HP HotKey Support (HKLM\...\{4BBA5224-C5B1-4B8C-AAA4-68DA6654B9C1}) (Version: 3.5.15.1 - Hewlett-Packard Company) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Officejet 4500 G510n-z (HKLM\...\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}) (Version: 13.0 - HP) HP Setup (HKLM\...\{96AC1B0B-02D1-4FAA-9C1E-C92ECA74921A}) (Version: 8.2.4130.3367 - Hewlett-Packard Company) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP SoftPaq Download Manager (HKLM\...\{2DA697D7-FED3-4DE2-A174-92A2A12F9688}) (Version: 3.0.5.0 - Hewlett-Packard Company) HP Software Framework (HKLM\...\{9CD3BB19-993E-469D-9E1F-B57A175C1411}) (Version: 4.0.51.1 - Hewlett-Packard Company) HP Software Setup (HKLM\...\{04801E42-B1A6-4C52-9F3D-CADB5A050433}) (Version: 7.0.1.6 - Hewlett-Packard Company) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Support Assistant (HKLM\...\{FC17E0A7-EAA9-4902-92F8-C83B9FD02246}) (Version: 5.0.14.2 - Hewlett-Packard Company) HP Update (HKLM\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard) HP Web Camera (Version: 1.0.0 - Hewlett-Packard) Hidden HP Webcam (HKLM\...\{1D61E881-43CD-447B-9E6B-D2C6138B2862}) (Version: 1.0.19.6 - Roxio) HP Webcam Driver (HKLM\...\{399C37FB-08AF-493B-BFED-20FBD85EDF7F}) (Version: 5.8.50014.0 - Sonix) HP Wireless Assistant (HKLM\...\{EC720706-3F19-4B7F-BDDD-E31D9B3921D2}) (Version: 4.0.6.0 - Hewlett-Packard) HPAsset component for HP Active Support Library (Version: 3.0.0.3 - Hewlett-Packard) Hidden HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden IDT Audio (HKLM\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6275.0 - IDT) LightScribe System Software (HKLM\...\{6AFDE3BE-BC01-45A4-9D06-BBF5AD207313}) (Version: 1.18.12.1 - LightScribe) MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden McAfee Browser Protection Service (HKLM\...\McAfeeBrowserProtection) (Version: 5.1.0.325 - McAfee, Inc.) <==== ATTENTION McAfee Firewall Protection Service (HKLM\...\McAfee Managed Firewall) (Version: 5.1.0.325 - McAfee, Inc.) McAfee SiteAdvisor Enterprise Plus (Version: 3.0.0.479 - McAfee, Inc.) Hidden McAfee Virus and Spyware Protection Service (HKLM\...\MVS) (Version: 5.1.0.325 - McAfee, Inc.) Microsoft Default Manager (Version: 2.2.114.0 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Search Enhancement Pack (Version: 3.0.126.0 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Network (Version: 130.0.374.000 - Hewlett-Packard) Hidden Norton Online Backup (HKLM\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 2.0.0.34 - Symantec) OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP) OpenOffice 4.0.1 (HKLM\...\{47F460DA-D1BE-4D85-8DF2-AA1F31D3445F}) (Version: 4.01.9714 - Apache Software Foundation) PC APP (HKLM\...\{26EDF173-CF61-466F-9E9C-F31D66FF5AFF}) (Version: 2.00.003 - ) PDF Complete Special Edition (HKLM\...\PDF Complete) (Version: 3.5.117 - PDF Complete, Inc) Realtek Ethernet Controller All-In-One Windows Driver (HKLM\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 1.12.0011 - Realtek) Roxio Activation Module (Version: 1.0 - Roxio) Hidden Roxio Creator Audio (Version: 3.8.0 - Roxio) Hidden Roxio Creator Business (HKLM\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.21 - Roxio) Roxio Creator Business v10 (Version: 3.8.0 - Roxio) Hidden Roxio Creator Copy (Version: 3.8.0 - Roxio) Hidden Roxio Creator Data (Version: 3.8.0 - Roxio) Hidden Roxio Creator Tools (Version: 3.8.0 - Roxio) Hidden Roxio Express Labeler 3 (Version: 3.2.2 - Roxio) Hidden Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype™ 4.2 (HKLM\...\{D103C4BA-F905-437A-8049-DB24763BBE36}) (Version: 4.2.163 - Skype Technologies S.A.) SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.10.0 - Synaptics Incorporated) Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden Visual C++ 8.0 x86 Runtime Setup Package (Version: 1.0.0.0 - McAfee Inc.) Hidden WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows 7 Default Setting (HKLM\...\{5BF8E079-D6E2-4323-B794-75152371122A}) (Version: 1.0.1.7 - Hewlett-Packard Company) Windows Live ID Sign-in Assistant (HKLM\...\{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}) (Version: 6.500.3165.0 - Microsoft Corporation) WinZip 14.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}) (Version: 14.5.9095 - WinZip Computing, S.L. ) ==================== Restore Points ========================= 24-11-2013 16:03:14 Initial Restore Point 24-11-2013 16:11:13 Installiert IDT Audio 24-11-2013 16:13:45 Installiert HP Webcam Driver 24-11-2013 16:17:24 Installed Norton Online Backup 25-12-2013 11:19:36 Microsoft Visual C++ 2005 Redistributable wird installiert 25-12-2013 11:20:40 Installiert PC APP 15-01-2014 16:29:28 Sprachpaketdeinstallation 15-01-2014 16:32:49 Geplanter Prüfpunkt 13-02-2014 10:03:31 Geplanter Prüfpunkt 19-02-2014 14:49:54 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 19-02-2014 14:50:49 Installed OpenOffice 4.0.1 ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0DEF225A-D132-4351-844E-B5F9A4475E60} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-07-01] (Hewlett-Packard Company) Task: {318D21B2-DE18-4F56-86E3-50E3018FD33D} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\HP Setup\RemEngine.exe [2010-04-22] () Task: {5F793093-31AE-4392-97D0-DC3BA311B19B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2010-07-01] (Hewlett-Packard Company) Task: {9AEC9C43-7190-4DA0-A056-B19F8C9C951D} - System32\Tasks\UpdaterEX => C:\Users\eva\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: C:\windows\Tasks\UpdaterEX.job => C:\Users\eva\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2010-02-22 20:19 - 2010-02-22 20:19 - 02121728 _____ () C:\Program Files\Common Files\LightScribe\QtCore4.dll 2010-02-22 20:19 - 2010-02-22 20:19 - 07745536 _____ () C:\Program Files\Common Files\LightScribe\QtGui4.dll 2010-02-22 20:19 - 2010-02-22 20:19 - 00135168 _____ () C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2014-02-19 04:08 - 2014-06-11 21:09 - 00317728 _____ () C:\Program Files\FindRight\updateFindRight.exe 2014-02-20 09:18 - 2014-06-11 21:08 - 00317728 _____ () C:\Program Files\FindRight\bin\utilFindRight.exe 2010-04-13 02:59 - 2010-04-13 02:59 - 00098304 ____R () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-08-05 13:57 - 2010-08-05 13:57 - 00270336 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-04-05 20:11 - 2010-04-05 20:11 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-04-05 20:12 - 2010-04-05 20:12 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2010-04-05 20:12 - 2010-04-05 20:12 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= Name: McAfee Inc. mfewfpk Description: McAfee Inc. mfewfpk Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: mfewfpk Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Officejet 4500 G510n-z Description: Officejet 4500 G510n-z Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (03/18/2014 07:21:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 8.0.7600.16385, Zeitstempel: 0x4a5bc69e Name des fehlerhaften Moduls: pdfcie.dll, Version: 3.5.1.1, Zeitstempel: 0x2a425e19 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00003c7e ID des fehlerhaften Prozesses: 0xc48 Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0 Pfad der fehlerhaften Anwendung: iexplore.exe1 Pfad des fehlerhaften Moduls: iexplore.exe2 Berichtskennung: iexplore.exe3 Error: (02/19/2014 05:10:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm iexplore.exe, Version 8.0.7600.16385 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 920 Startzeit: 01cf2d83591109e3 Endzeit: 156 Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe Berichts-ID: f5b71110-9977-11e3-94b8-70f395a0448c Error: (02/19/2014 04:50:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (02/19/2014 04:50:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (02/19/2014 04:49:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (02/19/2014 04:49:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (02/13/2014 00:03:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (02/13/2014 00:03:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (01/15/2014 06:32:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . Error: (01/15/2014 06:31:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert . System errors: ============= Error: (06/12/2014 11:53:37 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (04/13/2014 08:01:41 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 06.04.2014 um 13:24:09 unerwartet heruntergefahren. Error: (03/12/2014 10:59:58 PM) (Source: DCOM) (EventID: 10016) (User: eva-HP) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}eva-HPevaS-1-5-21-2839968430-3032943032-2816752695-1001LocalHost (unter Verwendung von LRPC) Error: (02/20/2014 09:17:19 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht. Error: (02/20/2014 09:17:20 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (02/13/2014 04:17:31 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80004005 Error: (01/24/2014 03:25:40 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (01/24/2014 03:25:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht. Error: (01/15/2014 08:55:49 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht. Error: (12/25/2013 04:31:22 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HP Wireless Assistant Service erreicht. Microsoft Office Sessions: ========================= Error: (03/18/2014 07:21:23 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: iexplore.exe8.0.7600.163854a5bc69epdfcie.dll3.5.1.12a425e19c000000500003c7ec4801cf42c84d943af6C:\Program Files\Internet Explorer\iexplore.exeC:\PROGRA~1\PDFCOM~1\pdfcie.dllba43ebab-aec1-11e3-a1b6-70f395a0448c Error: (02/19/2014 05:10:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: iexplore.exe8.0.7600.1638592001cf2d83591109e3156C:\Program Files\Internet Explorer\iexplore.exef5b71110-9977-11e3-94b8-70f395a0448c Error: (02/19/2014 04:50:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (02/19/2014 04:50:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (02/19/2014 04:49:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (02/19/2014 04:49:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (02/13/2014 00:03:31 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (02/13/2014 00:03:30 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (01/15/2014 06:32:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert Error: (01/15/2014 06:31:49 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: TraverseDir : Unable to FindFirstFile. System Error: Zugriff verweigert ==================== Memory info =========================== Percentage of memory in use: 87% Total physical RAM: 764.56 MB Available physical RAM: 97.73 MB Total Pagefile: 1788.56 MB Available Pagefile: 543.87 MB Total Virtual: 2047.88 MB Available Virtual: 1903.18 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:215.59 GB) (Free:184.55 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.99 GB) FAT32 Drive f: (OJ4500G510n-z) (CDROM) (Total:0.44 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: D38BD7F7) Partition 1: (Active) - (Size=300 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=216 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=2 GB) - (Type=0C) ==================== End Of Log ============================ |
12.06.2014, 11:48 | #14 |
/// the machine /// TB-Ausbilder | Windows 7: angeklickt flash player nicht aktuell Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.06.2014, 17:18 | #15 |
| Windows 7: angeklickt flash player nicht aktuell ADW Cleaner Code:
ATTFilter # AdwCleaner v3.212 - Bericht erstellt am 12/06/2014 um 17:48:09 # Aktualisiert 05/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium (32 bits) # Benutzername : eva - EVA-HP # Gestartet von : C:\Users\eva\Desktop\adwcleaner_3.212.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\eva\AppData\Roaming\1H1Q Ordner Gelöscht : C:\Users\eva\AppData\Roaming\UpdaterEX Datei Gelöscht : C:\Users\eva\AppData\Roaming\Mozilla\Firefox\Profiles\vu7osdcp.default\user.js ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7600.16385 -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\eva\AppData\Roaming\Mozilla\Firefox\Profiles\vu7osdcp.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1869 octets] - [12/06/2014 17:46:58] AdwCleaner[S0].txt - [1794 octets] - [12/06/2014 17:48:09] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1854 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 12.06.2014 Scan Time: 17:26:10 Logfile: mbam.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.12.06 Rootkit Database: v2014.06.02.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 CPU: x86 File System: NTFS User: eva Scan Type: Threat Scan Result: Completed Objects Scanned: 244534 Time Elapsed: 9 min, 40 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 1 PUP.Optional.BundleInstaller.A, C:\Users\eva\AppData\Roaming\1H1Q\Aff Packages\uninstaller.exe, 2308, Delete-on-Reboot, [aceadb9c88f34beb1f61d1b8dc2602fe] Modules: 0 (No malicious items detected) Registry Keys: 4 PUP.Optional.FindRight.A, HKU\S-1-5-21-2839968430-3032943032-2816752695-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{2C774641-5504-46A8-B63F-6715AE3FE376}, Quarantined, [286efe7998e38da91ddf83bb42c0ec14], PUP.Optional.FindRight.A, HKU\S-1-5-21-2839968430-3032943032-2816752695-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{2C774641-5504-46A8-B63F-6715AE3FE376}, Quarantined, [286efe7998e38da91ddf83bb42c0ec14], PUP.Optional.InstallCore.A, HKU\S-1-5-21-2839968430-3032943032-2816752695-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [fe98e88fc6b5f640d1e9dae4be44f010], PUP.Optional.InstallCore.A, HKU\S-1-5-21-2839968430-3032943032-2816752695-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [dfb75e197cff54e2289e2ca85fa431cf], Registry Values: 1 PUP.Optional.InstallCore.A, HKU\S-1-5-21-2839968430-3032943032-2816752695-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0B1G1O1S0V1G1F, Quarantined, [dfb75e197cff54e2289e2ca85fa431cf] Registry Data: 0 (No malicious items detected) Folders: 1 PUP.Optional.BundleInstaller.A, C:\Users\eva\AppData\Roaming\1H1Q\Aff Packages, Delete-on-Reboot, [aceadb9c88f34beb1f61d1b8dc2602fe], Files: 2 PUP.Optional.FindRight.A, C:\Users\eva\AppData\Local\Temp\is1242154493\1184335_stp\FindRightSetup.exe, Quarantined, [50468fe8245785b1d163ab9c838115eb], PUP.Optional.BundleInstaller.A, C:\Users\eva\AppData\Roaming\1H1Q\Aff Packages\uninstaller.exe, Delete-on-Reboot, [aceadb9c88f34beb1f61d1b8dc2602fe], Physical Sectors: 0 (No malicious items detected) (end) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows 7 Home Premium x86 Ran by eva on 12.06.2014 at 18:08:52,09 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.06.2014 at 18:12:26,89 Computer was rebooted End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:12-06-2014 Ran by eva (administrator) on EVA-HP on 12-06-2014 18:13:15 Running from C:\Users\eva\Desktop Platform: Microsoft Windows 7 Home Premium (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\stacsv.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (McAfee, Inc.) C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\AEstSrv.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.) C:\Program Files\McAfee\MPF\MpfSrv.exe (PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe (Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [QLBController] => C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company) HKLM\...\Run: [PDF Complete] => C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated) HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard) HKLM\...\Run: [Microsoft Default Manager] => C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation) HKLM\...\Run: [McAfee Managed Services Tray] => C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.Exe [476480 2010-02-17] (McAfee, Inc.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-08-05] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-17] (IDT, Inc.) HKLM\...\Run: [NortonOnlineBackupReminder] => C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKU\S-1-5-21-2839968430-3032943032-2816752695-1001\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company) HKU\S-1-5-21-2839968430-3032943032-2816752695-1001\...\MountPoints2: {1c3f02cb-556b-11e3-a9c1-806e6f6e6963} - F:\Setup.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM/10 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM/10 SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100909125144.dll (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - @C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\eva\AppData\Roaming\Mozilla\Firefox\Profiles\vu7osdcp.default FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @Microsoft.com/NpWinExt,version=5.0 - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll (Microsoft Corporation) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\Firefox FF Extension: Bing Bar - C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\Firefox [2010-09-09] FF HKLM\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ FF Extension: Search Helper Extension - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [] FF HKLM\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ FF Extension: Default Manager - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-01] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-12-01] ========================== Services (Whitelisted) ================= R2 HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [121344 2010-07-01] (Hewlett-Packard Company) [File not signed] R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard) R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-02-22] (Hewlett-Packard Company) [File not signed] R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [170144 2010-02-04] (McAfee, Inc.) R2 mfevtp; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [141792 2010-02-08] (McAfee, Inc.) R2 MpfService; C:\Program Files\McAfee\MPF\MPFSrv.exe [893112 2009-05-09] (McAfee, Inc.) R2 Net Driver HPZ12; C:\windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) [File not signed] R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc) R2 Pml Driver HPZ12; C:\windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) [File not signed] R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\STacSV.exe [229458 2010-03-17] (IDT, Inc.) S2 myAgtSvc; "C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe" /ServiceStart [X] ==================== Drivers (Whitelisted) ==================== R3 mfeapfk; C:\windows\System32\drivers\mfeapfk.sys [95728 2010-02-08] (McAfee, Inc.) R3 mfeavfk; C:\windows\System32\drivers\mfeavfk.sys [152736 2010-02-08] (McAfee, Inc.) R3 mfebopk; C:\windows\System32\drivers\mfebopk.sys [51720 2010-02-08] (McAfee, Inc.) R0 mfehidk; C:\windows\System32\drivers\mfehidk.sys [385184 2010-02-08] (McAfee, Inc.) S3 mferkdet; C:\windows\System32\drivers\mferkdet.sys [83912 2010-02-08] (McAfee, Inc.) R0 mfewfpk; C:\windows\System32\drivers\mfewfpk.sys [160912 2010-02-08] (McAfee, Inc.) R1 MPFP; C:\windows\System32\Drivers\Mpfp.sys [130424 2009-04-09] (McAfee, Inc.) R3 SNP2UVC; C:\windows\System32\DRIVERS\snp2uvc.sys [1763968 2010-04-27] () R1 {42e50651-9669-456e-9081-d5a836274274}w; C:\windows\System32\drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys [52920 2014-05-30] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-12 18:13 - 2014-06-12 18:13 - 00012474 _____ () C:\Users\eva\Desktop\FRST.txt 2014-06-12 18:12 - 2014-06-12 18:12 - 00000646 _____ () C:\Users\eva\Desktop\JRT.txt 2014-06-12 17:59 - 2014-06-12 17:59 - 00000000 ____D () C:\windows\ERUNT 2014-06-12 17:58 - 2014-06-12 17:58 - 01016261 _____ (Thisisu) C:\Users\eva\Desktop\JRT.exe 2014-06-12 17:56 - 2014-06-12 17:56 - 00001934 _____ () C:\Users\eva\Desktop\AdwCleaner[S0].txt 2014-06-12 17:46 - 2014-06-12 17:48 - 00000000 ____D () C:\AdwCleaner 2014-06-12 17:45 - 2014-06-12 17:45 - 00002611 _____ () C:\Users\eva\Desktop\mbam.txt 2014-06-12 17:26 - 2014-06-12 17:26 - 01333465 _____ () C:\Users\eva\Desktop\adwcleaner_3.212.exe 2014-06-12 17:25 - 2014-06-12 17:44 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-12 17:25 - 2014-06-12 17:25 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-12 17:25 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-06-12 17:25 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-06-12 17:25 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-06-12 17:24 - 2014-06-12 17:24 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\eva\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-12 17:08 - 2014-06-12 17:08 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\eva\Desktop\revosetup95.exe 2014-06-12 17:08 - 2014-06-12 17:08 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-06-12 17:06 - 2014-06-12 17:06 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Roaming\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Local\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-12 11:57 - 2014-06-12 18:13 - 00000000 ____D () C:\FRST 2014-06-12 11:56 - 2014-06-12 11:56 - 01073152 _____ (Farbar) C:\Users\eva\Desktop\FRST.exe 2014-06-02 09:25 - 2014-05-30 14:25 - 00052920 _____ (StdLib) C:\windows\system32\Drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys ==================== One Month Modified Files and Folders ======= 2014-06-12 18:13 - 2014-06-12 18:13 - 00012474 _____ () C:\Users\eva\Desktop\FRST.txt 2014-06-12 18:13 - 2014-06-12 11:57 - 00000000 ____D () C:\FRST 2014-06-12 18:13 - 2013-11-24 18:05 - 00000000 ____D () C:\Users\eva\AppData\Local\Temp 2014-06-12 18:12 - 2014-06-12 18:12 - 00000646 _____ () C:\Users\eva\Desktop\JRT.txt 2014-06-12 18:12 - 2010-09-09 20:53 - 01472002 _____ () C:\windows\system32\PerfStringBackup.INI 2014-06-12 18:12 - 2009-07-14 06:34 - 00019536 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-12 18:12 - 2009-07-14 06:34 - 00019536 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-12 18:05 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-06-12 18:05 - 2009-07-14 06:39 - 00102154 _____ () C:\windows\setupact.log 2014-06-12 18:04 - 2013-11-24 18:05 - 00182150 _____ () C:\windows\WindowsUpdate.log 2014-06-12 18:04 - 2010-09-09 21:52 - 00006923 _____ () C:\windows\system32\Config.MPF 2014-06-12 17:59 - 2014-06-12 17:59 - 00000000 ____D () C:\windows\ERUNT 2014-06-12 17:58 - 2014-06-12 17:58 - 01016261 _____ (Thisisu) C:\Users\eva\Desktop\JRT.exe 2014-06-12 17:56 - 2014-06-12 17:56 - 00001934 _____ () C:\Users\eva\Desktop\AdwCleaner[S0].txt 2014-06-12 17:56 - 2010-09-09 21:57 - 00014288 _____ () C:\windows\PFRO.log 2014-06-12 17:48 - 2014-06-12 17:46 - 00000000 ____D () C:\AdwCleaner 2014-06-12 17:45 - 2014-06-12 17:45 - 00002611 _____ () C:\Users\eva\Desktop\mbam.txt 2014-06-12 17:44 - 2014-06-12 17:25 - 00110296 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-12 17:26 - 2014-06-12 17:26 - 01333465 _____ () C:\Users\eva\Desktop\adwcleaner_3.212.exe 2014-06-12 17:25 - 2014-06-12 17:25 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-12 17:25 - 2014-06-12 17:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-06-12 17:24 - 2014-06-12 17:24 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\eva\Desktop\mbam-setup-2.0.2.1012.exe 2014-06-12 17:20 - 2010-09-09 21:50 - 00000000 ____D () C:\ProgramData\McAfee 2014-06-12 17:20 - 2010-09-09 21:50 - 00000000 ____D () C:\Program Files\McAfee 2014-06-12 17:08 - 2014-06-12 17:08 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\eva\Desktop\revosetup95.exe 2014-06-12 17:08 - 2014-06-12 17:08 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-06-12 17:06 - 2014-06-12 17:06 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Roaming\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Users\eva\AppData\Local\Mozilla 2014-06-12 17:06 - 2014-06-12 17:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-06-12 17:06 - 2009-07-14 04:04 - 00000540 _____ () C:\windows\win.ini 2014-06-12 11:56 - 2014-06-12 11:56 - 01073152 _____ (Farbar) C:\Users\eva\Desktop\FRST.exe 2014-06-11 21:08 - 2010-09-09 21:09 - 00000000 ____D () C:\ProgramData\PDFC 2014-05-30 14:25 - 2014-06-02 09:25 - 00052920 _____ (StdLib) C:\windows\system32\Drivers\{42e50651-9669-456e-9081-d5a836274274}w.sys Some content of TEMP: ==================== C:\Users\eva\AppData\Local\Temp\CpqMC.dll C:\Users\eva\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\eva\AppData\Local\Temp\HPQSi.exe C:\Users\eva\AppData\Local\Temp\lowproc.exe C:\Users\eva\AppData\Local\Temp\Quarantine.exe C:\Users\eva\AppData\Local\Temp\stubhelper.dll ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-03-13 22:23 ==================== End Of Log ============================ |
Themen zu Windows 7: angeklickt flash player nicht aktuell |
4d36e972-e325-11ce-bfc1-08002be10318, antivirus, association, branding, homepage, msil/domaiq.a, pup.optional.bundleinstaller.a, pup.optional.findright.a, pup.optional.installcore.a, realtek, software, super, svchost.exe, teredo, tr/trash.gen, vcredist, werbung, win32/anyprotect.d, win32/browsefox.e, win32/domaiq.bb, win32/domaiq.bh, win32/installcore.az, win32/installcore.jw, win32/softpulse.b, win32/tivmonk.b, win32/vopackage.h, win32/wajam.f, windowsprotectmanger |