|
Plagegeister aller Art und deren Bekämpfung: Probleme wegen Spammail?!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.06.2014, 18:03 | #1 |
| Probleme wegen Spammail?! Hi Leutz, ich habe heute eine fake Email mit einer Rechnung der Telekom bekommen. Ich habe sie geöffnet, da ich mit denen nichts am Hut habe. Nun meine Frage ist euch dazu was bekannt, dass diese Mail mit Trojanern und anderer Malware voll ist?? Wenn ja was mach ich nun am Besten? Gruß DooMer90 Danke schon mal wenn ihr mir weiterhelfen könnt. |
06.06.2014, 19:00 | #2 |
/// the machine /// TB-Ausbilder | Probleme wegen Spammail?! hi,
__________________stinknormaler Spam, kannste nix gegen machen. Hast Du auch den Anhang der Mail geöffnet?
__________________ |
06.06.2014, 19:46 | #3 |
| Probleme wegen Spammail?! Email geöffnet ein paar links ausgetestet in Anhang ganz unten.
__________________Aber die waren hauptsächlich auf die Telekomseite verknüpft einer auf nen Pixel das hab ich nicht verstanden. Den Rest hab ich ausgelassen, wie den angepriesenen Rechnungslink. |
07.06.2014, 17:15 | #4 |
/// the machine /// TB-Ausbilder | Probleme wegen Spammail?! gut, dann sollte alles ok sein, aber schauen wir mal: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.06.2014, 17:13 | #5 |
| Probleme wegen Spammail?! Hey entschuldige die späte Antwort. Ich habe beim Scan folgenden Fehler gehabt: 0x80030002 install.rdf fehlt Hat das damit zutun das ich win 7 N nutze? Hier die Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-06-2014 Ran by Haribo at 2014-06-09 18:03:06 Running from C:\Users\Haribo\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.6 - Sereby Corporation) AutoCAD 2012 - Deutsch (HKLM\...\AutoCAD 2012 - Deutsch) (Version: 18.2.51.0 - Autodesk) AutoCAD 2012 - Deutsch (Version: 18.2.51.0 - Autodesk) Hidden AutoCAD 2012 Language Pack - Deutsch (Version: 18.2.51.0 - Autodesk) Hidden Autodesk Content Service (HKLM-x32\...\{086F9A69-CD39-4893-A9FB-D3A0634CE3F7}) (Version: 2.0.90 - Autodesk) Autodesk Inventor Fusion 2012 (HKLM\...\Autodesk Inventor Fusion 2012) (Version: 1.0.0.79 - Autodesk, Inc.) Autodesk Inventor Fusion 2012 (Version: 1.0.0.79 - Autodesk, Inc.) Hidden Autodesk Inventor Fusion 2012 Language Pack (Version: 1.0.0.79 - Autodesk, Inc.) Hidden Autodesk Inventor Fusion plug-in for AutoCAD 2012 (HKLM\...\Autodesk Inventor Fusion Plugin for AutoCAD 2012) (Version: 0.0.1.138 - Autodesk) Autodesk Inventor Fusion Plugin for AutoCAD 2012 (Version: 0.0.1.138 - Autodesk) Hidden Autodesk Inventor Fusion Plugin Language Pack for AutoCAD 2012 (Version: 0.0.1.138 - Autodesk) Hidden Autodesk Material Library 2012 (HKLM-x32\...\{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}) (Version: 2.5.0.8 - Autodesk) Autodesk Material Library Base Resolution Image Library 2012 (HKLM-x32\...\{65420DC9-306E-4371-905F-F4DC3B418E52}) (Version: 2.5.0.8 - Autodesk) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Avira SearchFree Toolbar (HKLM-x32\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4487 - APN, LLC) Canon MG5200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5200_series) (Version: - ) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4746 - CDBurnerXP) DirectX 9.0c Extra Files (x86, x64) (HKLM\...\{8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1) (Version: 1.10.06.0 - Sereby Corporation) FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production) Free Driver Scout (HKLM-x32\...\{1e7e6e40-febe-4058-a85a-5a80722b86d7}) (Version: 1.0.0.141 - Covus Freemium) Free Driver Scout (Version: 1.0.0.141 - Covus Freemium) Hidden Greenshot 1.1.5.2643 (HKLM\...\Greenshot_is1) (Version: 1.1.5.2643 - Greenshot) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.3.1520 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.8.251 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.27.798.1 - Intel Corporation) Hidden Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM-x32\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM-x32\...\M2833941) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM-x32\...\M979906) (Version: - ) Microsoft .NET Framework 1.1 SP1 (HKLM\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: - ) Microsoft .NET Framework 1.1 SP1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61186 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60830 (HKLM-x32\...\{c7ed0d4c-89c5-47fc-9e89-1088affe63f3}) (Version: 11.0.60830.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60830 (HKLM-x32\...\{9dba0447-b749-41ea-90bc-2aa19a9eb580}) (Version: 11.0.60830.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60830 (Version: 11.0.60830 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60830 (Version: 11.0.60830 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60830 (x32 Version: 11.0.60830 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60830 (x32 Version: 11.0.60830 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 (Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE (x64)) (Version: - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (x64) (Version: 2.0.50728 - Microsoft Corporation) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) NVIDIA Grafiktreiber 311.44 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.44 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.109.706 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.11.3 (Version: 1.11.3 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.44 (Version: 311.44 - NVIDIA Corporation) Hidden NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden OpenOffice 4.0.0 (HKLM-x32\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) PDF24 Creator 6.0.1 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Protegere (HKLM-x32\...\Protegere) (Version: - ) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Qualcomm Atheros) Realtek Card Reader (HKLM-x32\...\{F0A8BF4A-972F-41E0-9800-1EFE3BF28266}) (Version: 1.1.9200.15 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.57.403.2012 - Realtek) Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.3.0 - Samsung Electronics) VLC media player 2.1.0-rc2 (HKLM\...\VLC media player) (Version: 2.1.0-rc2 - VideoLAN) Web Check (HKLM-x32\...\Web Check) (Version: - ) Web Optimizer (HKLM-x32\...\Web Optimizer) (Version: - ) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ___AH C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0FBE3D6B-985A-42C6-90E5-4C2B3DF2A00F} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2013-12-18] () Task: {1A0CEB99-8FA0-4334-86F2-70B36C9177CC} - System32\Tasks\FreeDriverScout => C:\Program Files\Covus Freemium\Free Driver Scout\1Click.exe [2013-08-16] () Task: {DEB6FF8F-859F-481D-842E-A12BCB94A474} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe [2013-12-18] () Task: {EB124BE9-AF10-4823-A004-ADA7FE2F1955} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) ==================== Loaded Modules (whitelisted) ============= 2013-09-07 00:08 - 2013-03-14 08:28 - 00087328 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2011-02-02 15:08 - 2011-02-02 15:08 - 00018656 _____ () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe 2012-12-14 02:42 - 2012-12-14 02:42 - 00094208 ____H () C:\Windows\System32\IccLibDll_x64.dll 2014-06-06 21:16 - 2013-11-28 12:14 - 00013824 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll 2014-06-06 21:16 - 2013-11-28 18:59 - 00098816 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\PAL.dll 2014-06-06 21:16 - 2013-11-28 18:59 - 00034304 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SATA.dll 2014-06-06 21:16 - 2013-11-28 18:59 - 00032768 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAT.dll 2014-06-06 21:16 - 2013-11-28 19:00 - 00031232 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SMINI.dll 2014-06-06 21:16 - 2013-11-28 18:59 - 00029696 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAS.dll 2014-05-17 21:43 - 2014-05-17 21:44 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2014-06-06 21:13 - 2014-06-06 21:13 - 16361136 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll 2013-09-07 01:01 - 2013-05-09 04:23 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: PCI-Gerät Description: PCI-Gerät Class Guid: {4d36e970-e325-11ce-bfc1-08002be10318} Manufacturer: Realtek Semiconduct Corp. Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: PCI-Datensammlungs- und Signalverarbeitungscontroller Description: PCI-Datensammlungs- und Signalverarbeitungscontroller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/09/2014 06:00:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl) konnten nicht installiert werden. Der Fehlercode ist das erste DWORD im Datenbereich. Error: (06/09/2014 06:00:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht aktualisiert werden. Das erste DWORD im Datenbereich enthält den Fehlercode. Error: (06/09/2014 05:56:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/08/2014 00:14:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl) konnten nicht installiert werden. Der Fehlercode ist das erste DWORD im Datenbereich. Error: (06/08/2014 00:14:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht aktualisiert werden. Das erste DWORD im Datenbereich enthält den Fehlercode. Error: (06/08/2014 00:13:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl) konnten nicht installiert werden. Der Fehlercode ist das erste DWORD im Datenbereich. Error: (06/08/2014 00:13:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht aktualisiert werden. Das erste DWORD im Datenbereich enthält den Fehlercode. Error: (06/08/2014 00:12:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/07/2014 07:23:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl) konnten nicht installiert werden. Der Fehlercode ist das erste DWORD im Datenbereich. Error: (06/07/2014 07:23:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren, die für die Sprach-ID "007" definiert wurden, können nicht aktualisiert werden. Das erste DWORD im Datenbereich enthält den Fehlercode. System errors: ============= Error: (06/08/2014 01:37:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Netzwerklistendienst" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/08/2014 01:37:05 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "netprofm" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/08/2014 01:37:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Diagnosediensthost" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (06/08/2014 01:37:05 PM) (Source: Service Control Manager) (EventID: 7038) (User: ) Description: Der Dienst "WdiServiceHost" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (06/08/2014 01:37:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Netzwerkverbindungen" wurde aufgrund folgenden Fehlers nicht gestartet: %%1115 Error: (06/08/2014 01:37:05 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Anwendungsinformationen" wurde aufgrund folgenden Fehlers nicht gestartet: %%1115 Error: (06/08/2014 00:18:51 PM) (Source: MEIx64) (EventID: 3) (User: ) Description: Intel(R) Management Engine Interface driver has failed to perform handshake with the Firmware. Error: (06/06/2014 07:04:44 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 06.06.2014 um 19:03:36 unerwartet heruntergefahren. Error: (06/05/2014 09:37:26 PM) (Source: MEIx64) (EventID: 3) (User: ) Description: Intel(R) Management Engine Interface driver has failed to perform handshake with the Firmware. Error: (06/04/2014 10:20:31 PM) (Source: MEIx64) (EventID: 3) (User: ) Description: Intel(R) Management Engine Interface driver has failed to perform handshake with the Firmware. Microsoft Office Sessions: ========================= Error: (06/09/2014 06:00:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl805000000C9120000 Error: (06/09/2014 06:00:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: 0078050000005A0D0000 Error: (06/09/2014 05:56:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/08/2014 00:14:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl805000000C9120000 Error: (06/08/2014 00:14:42 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: 0078050000005A0D0000 Error: (06/08/2014 00:13:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl805000000C9120000 Error: (06/08/2014 00:13:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: 0078050000005A0D0000 Error: (06/08/2014 00:12:19 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/07/2014 07:23:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT-AUTORITÄT) Description: WmiApRplWmiApRpl805000000C9120000 Error: (06/07/2014 07:23:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3013) (User: NT-AUTORITÄT) Description: 0078050000005A0D0000 ==================== Memory info =========================== Percentage of memory in use: 22% Total physical RAM: 8077.55 MB Available physical RAM: 6261.95 MB Total Pagefile: 8275.73 MB Available Pagefile: 6519.05 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:214.45 GB) (Free:175.6 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-06-2014 Ran by Haribo (administrator) on Haribo-PC on 09-06-2014 18:01:20 Running from C:\Users\Haribo\Desktop Platform: Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Greenshot) C:\Program Files\Greenshot\Greenshot.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Atheros) C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\Ath_WlanAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [499712 2013-05-20] (Greenshot) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-22] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [185896 2013-10-28] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-04-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-04-08] (NVIDIA Corporation) Startup: C:\Users\Haribo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe (Samsung Electronics.) ==================== Internet (Whitelisted) ==================== SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Web Optimizer - {bbb1d54d-cf70-4a80-bf2f-3bafca0225ce} - C:\Program Files (x86)\Web Optimizer\weboptimizer.dll (Web Optimizer) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files (x86)\Web Check\WebCheck.dll (Web Check) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Haribo\AppData\Roaming\Mozilla\Firefox\Profiles\7hhwyg8h.default FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0-rc2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF user.js: detected! => C:\Users\Haribo\AppData\Roaming\Mozilla\Firefox\Profiles\7hhwyg8h.default\user.js FF SearchPlugin: C:\Users\Haribo\AppData\Roaming\Mozilla\Firefox\Profiles\7hhwyg8h.default\searchplugins\trovi-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Haribo\AppData\Roaming\Mozilla\Firefox\Profiles\7hhwyg8h.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-07-26] FF Extension: NoScript - C:\Users\Haribo\AppData\Roaming\Mozilla\Firefox\Profiles\7hhwyg8h.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-09-08] FF Extension: No Name - C:\Program Files (x86)\Web Optimizer\weboptimizer.xpi [2013-08-27] FF HKLM-x32\...\Firefox\Extensions: [{52b0f3db-f988-4788-b9dc-861d016f4487}] - C:\Program Files (x86)\Web Check\WebCheck.xpi FF Extension: Web Check - C:\Program Files (x86)\Web Check\WebCheck.xpi [2013-08-12] FF HKLM-x32\...\Firefox\Extensions: [{ff0f24dd-184a-42ca-9ce8-8ca6184fd0ac}] - C:\Program Files (x86)\Web Optimizer\weboptimizer.xpi FF Extension: No Name - C:\Program Files (x86)\Web Optimizer\weboptimizer.xpi [2013-08-27] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-22] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-09] (Intel Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation\Ath_WlanAgent.exe [77824 2012-06-19] (Atheros) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-22] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-27] (Avira Operations GmbH & Co. KG) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99800 2013-05-09] (Intel Corporation) S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [408136 2013-05-08] (Realsil Semiconductor Corporation) S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X] S3 RSBASTOR; system32\DRIVERS\RtsBaStor.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-09 18:01 - 2014-06-09 18:02 - 00012362 _____ () C:\Users\Haribo\Desktop\FRST.txt 2014-06-09 18:00 - 2014-06-09 18:02 - 00000000 ____D () C:\FRST 2014-06-08 12:12 - 2014-06-08 12:12 - 00000000 ____D () C:\Users\Haribo\AppData\Local\Adobe 2014-06-07 18:25 - 2014-06-07 18:25 - 02072576 _____ (Farbar) C:\Users\Haribo\Desktop\FRST64.exe 2014-06-06 21:16 - 2014-06-06 21:16 - 00000000 ____D () C:\ProgramData\Samsung 2014-06-06 21:16 - 2014-06-06 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2014-06-06 21:16 - 2014-06-06 21:16 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-06-06 21:13 - 2014-06-06 21:14 - 15617656 _____ (Samsung Electronics ) C:\Users\Haribo\Downloads\Samsung_Magician_v43.exe 2014-06-06 21:13 - 2014-06-06 21:13 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-06 21:13 - 2014-06-06 21:13 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-04 17:49 - 2014-06-04 17:49 - 00000000 ____D () C:\Users\Haribo\Downloads\Wehrle Martin - Geheime Tricks fur mehr Gehalt 2014-06-04 17:48 - 2014-06-04 17:48 - 00000000 ____D () C:\Users\Haribo\Downloads\Jenke Von Wilmsdorff - Wer Wagt, Gewinnt Leben Als Experiment (4CD) (2014) 2014-06-04 17:46 - 2014-05-28 17:44 - 00000000 ____D () C:\Users\Haribo\Downloads\David Perlmutter 2014-06-02 19:41 - 2014-06-02 21:06 - 00043672 _____ () C:\Users\Haribo\Desktop\Anschreiben Melan m.odt 2014-06-02 19:25 - 2014-06-02 19:25 - 00043907 _____ () C:\Users\Haribo\Desktop\Anschreiben Melan.odt 2014-06-02 18:45 - 2014-06-02 18:45 - 00046285 _____ () C:\Users\Haribo\Desktop\Anschreiben Hotel Krone.odt 2014-06-02 18:43 - 2014-06-02 18:43 - 00046273 _____ () C:\Users\Haribo\Desktop\Anschreiben ibis aachen.odt 2014-06-02 18:41 - 2014-06-02 18:41 - 00046357 _____ () C:\Users\Haribo\Desktop\Anschreiben Mercure Hotel.odt 2014-06-02 17:47 - 2014-06-02 18:35 - 00046209 _____ () C:\Users\Haribo\Desktop\Anschreiben Eiscafe Annabella.odt 2014-06-02 17:09 - 2014-06-02 17:42 - 00046166 _____ () C:\Users\Haribo\Desktop\Anschreiben Art Hotel.odt 2014-05-30 23:38 - 2014-06-09 18:00 - 01678982 _____ () C:\Windows\system32\PerfStringBackup.TMP 2014-05-30 00:57 - 2014-05-30 00:57 - 00000000 _____ () C:\Users\Haribo\AppData\Roaming\AVSDVDPlayer.m3u 2014-05-30 00:44 - 2014-05-30 00:44 - 00000000 ____D () C:\ProgramData\AVS4YOU 2014-05-30 00:43 - 2014-05-30 01:05 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU 2014-05-30 00:43 - 2007-09-27 15:22 - 00638976 ____H (DivXNetworks, Inc.) C:\Windows\SysWOW64\divx.dll 2014-05-30 00:43 - 2007-09-27 15:22 - 00524288 ____H () C:\Windows\SysWOW64\xvidcore.dll 2014-05-30 00:43 - 2007-09-27 15:22 - 00413760 ____H (Microsoft Corporation) C:\Windows\SysWOW64\mpg4c32.dll 2014-05-30 00:43 - 2007-09-27 15:22 - 00261632 ____H (MainConcept) C:\Windows\SysWOW64\mcdvd_32.dll 2014-05-30 00:43 - 2007-09-27 15:22 - 00139264 ____H () C:\Windows\SysWOW64\xvidvfw.dll 2014-05-30 00:43 - 2004-09-06 17:06 - 00053248 ____H () C:\Windows\SysWOW64\xvid.ax 2014-05-30 00:43 - 2004-02-04 22:11 - 00081920 ____H (fccHandler) C:\Windows\SysWOW64\AC3ACM.acm 2014-05-30 00:43 - 2003-06-05 18:30 - 00316640 ____H () C:\Windows\WMSysPr9.prx 2014-05-30 00:43 - 2003-05-22 13:26 - 00221215 ____H (DivXNetworks, Inc.) C:\Windows\SysWOW64\divxdec.ax 2014-05-30 00:43 - 2003-05-22 00:50 - 01700352 ____H (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2014-05-30 00:43 - 2003-05-22 00:50 - 00156910 ____H () C:\Windows\WMSysPr8.prx 2014-05-30 00:43 - 2003-05-22 00:50 - 00082944 ____H (Voxware, Inc.) C:\Windows\SysWOW64\vct3216.acm 2014-05-30 00:43 - 2003-05-22 00:50 - 00038912 ____H (NCT Company) C:\Windows\SysWOW64\alf2cd.acm 2014-05-30 00:43 - 2003-05-21 13:50 - 00024576 ____H (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2014-05-30 00:43 - 2003-03-25 06:49 - 00098304 ____H (Fraunhofer Institut Integrierte Schaltungen IIS) C:\Windows\SysWOW64\L3CODECX.AX 2014-05-30 00:43 - 2000-03-14 21:55 - 00013239 ____H (SHARP Corporation) C:\Windows\SysWOW64\Scg726.acm 2014-05-29 23:29 - 2014-05-29 23:52 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\dvdcss 2014-05-26 17:57 - 2014-05-26 17:58 - 00017996 _____ () C:\Users\Haribo\Desktop\Anschreiben Continental.odt 2014-05-26 17:24 - 2014-05-26 17:27 - 00046518 _____ () C:\Users\Haribo\Desktop\Anschreiben Kisters.odt 2014-05-24 20:48 - 2014-05-24 21:36 - 00017563 _____ () C:\Users\Haribo\Desktop\Grünenthal alex Bewerbung.odt 2014-05-24 20:42 - 2014-05-24 21:37 - 00017225 _____ () C:\Users\Haribo\Desktop\Phillips Bewerbung.odt 2014-05-18 02:29 - 2014-05-18 02:29 - 00001949 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-05-18 02:29 - 2014-05-18 02:29 - 00001899 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-05-18 02:29 - 2014-05-18 02:29 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\Canneverbe Limited 2014-05-18 02:29 - 2014-05-18 02:29 - 00000000 ____D () C:\ProgramData\Canneverbe Limited 2014-05-18 02:29 - 2014-05-18 02:29 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-05-18 02:21 - 2014-05-18 02:21 - 00000000 ____D () C:\Users\Haribo\AppData\Local\ashampoo 2014-05-18 02:19 - 2014-05-18 02:21 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-05-17 21:43 - 2014-05-17 21:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-16 00:22 - 2014-05-16 00:23 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-05-16 00:22 - 2014-05-16 00:22 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\TuneUp Software 2014-05-16 00:22 - 2014-05-16 00:22 - 00000000 ____D () C:\Users\Haribo\AppData\Local\TuneUp Software 2014-05-16 00:21 - 2014-05-16 00:22 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-05-16 00:21 - 2014-05-16 00:21 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\OpenCandy 2014-05-16 00:20 - 2014-05-16 00:30 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\DVDVideoSoft 2014-05-15 01:35 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 01:35 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 01:35 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 01:35 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 01:35 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 01:35 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 23:35 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 23:35 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 23:35 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 23:35 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 23:35 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 23:35 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 23:35 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 23:35 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 23:35 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 23:35 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 23:35 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 23:35 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 23:35 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 23:35 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 23:35 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 23:35 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 23:35 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 23:35 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 23:35 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 23:35 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 23:35 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 23:35 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 23:35 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 23:35 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 23:35 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 23:35 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 23:35 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 23:35 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-13 16:13 - 2009-12-01 21:50 - 00000000 ____D () C:\Users\Haribo\Downloads\Robert T. Betz - Mach' endlich was aus Deinem Leben! ==================== One Month Modified Files and Folders ======= 2014-06-09 18:02 - 2014-06-09 18:01 - 00012362 _____ () C:\Users\Haribo\Desktop\FRST.txt 2014-06-09 18:02 - 2014-06-09 18:00 - 00000000 ____D () C:\FRST 2014-06-09 18:02 - 2013-09-04 03:10 - 00000000 ____D () C:\Users\Haribo\AppData\Local\Temp 2014-06-09 18:01 - 2009-07-14 06:50 - 00020112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-09 18:01 - 2009-07-14 06:50 - 00020112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-09 18:00 - 2014-05-30 23:38 - 01678982 _____ () C:\Windows\system32\PerfStringBackup.TMP 2014-06-09 18:00 - 2013-09-20 23:54 - 00000000 ____D () C:\Users\Haribo\AppData\Local\PMB Files 2014-06-09 18:00 - 2013-09-20 23:54 - 00000000 ____D () C:\ProgramData\PMB Files 2014-06-09 17:58 - 2013-10-24 15:29 - 01403492 ____H () C:\Windows\WindowsUpdate.log 2014-06-09 17:58 - 2013-09-06 19:32 - 00004196 _____ () C:\Windows\System32\Tasks\Software Updater 2014-06-09 17:54 - 2013-10-24 15:26 - 00064826 ____H () C:\Windows\setupact.log 2014-06-09 17:54 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-08 12:12 - 2014-06-08 12:12 - 00000000 ____D () C:\Users\Haribo\AppData\Local\Adobe 2014-06-07 18:25 - 2014-06-07 18:25 - 02072576 _____ (Farbar) C:\Users\Haribo\Desktop\FRST64.exe 2014-06-06 21:17 - 2013-10-24 15:26 - 00117676 ____H () C:\Windows\PFRO.log 2014-06-06 21:16 - 2014-06-06 21:16 - 00000000 ____D () C:\ProgramData\Samsung 2014-06-06 21:16 - 2014-06-06 21:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2014-06-06 21:16 - 2014-06-06 21:16 - 00000000 ____D () C:\Program Files (x86)\Samsung 2014-06-06 21:16 - 2013-09-04 03:10 - 00000000 ___RD () C:\Users\Haribo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-06 21:14 - 2014-06-06 21:13 - 15617656 _____ (Samsung Electronics ) C:\Users\Haribo\Downloads\Samsung_Magician_v43.exe 2014-06-06 21:13 - 2014-06-06 21:13 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-06 21:13 - 2014-06-06 21:13 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-06 21:09 - 2013-09-07 00:37 - 00000000 ___HD () C:\Windows\SysWOW64\Macromed 2014-06-06 18:43 - 2013-09-07 00:08 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp 2014-06-04 22:26 - 2013-12-12 19:44 - 00000000 ____D () C:\Users\Haribo\AppData\Local\Autodesk 2014-06-04 22:25 - 2013-12-13 16:26 - 00000000 ____D () C:\Users\Haribo\AppData\Local\cache 2014-06-04 17:49 - 2014-06-04 17:49 - 00000000 ____D () C:\Users\Haribo\Downloads\Wehrle Martin - Geheime Tricks fur mehr Gehalt 2014-06-04 17:48 - 2014-06-04 17:48 - 00000000 ____D () C:\Users\Haribo\Downloads\Jenke Von Wilmsdorff - Wer Wagt, Gewinnt Leben Als Experiment (4CD) (2014) 2014-06-04 17:05 - 2013-10-29 01:34 - 00000000 ____D () C:\Users\Haribo\Desktop\Umwelt Test 2014-06-02 21:06 - 2014-06-02 19:41 - 00043672 _____ () C:\Users\Haribo\Desktop\Anschreiben Melan m.odt 2014-06-02 20:23 - 2009-07-14 07:08 - 00032632 ____H () C:\Windows\Tasks\SCHEDLGU.TXT 2014-06-02 19:29 - 2014-01-25 16:18 - 00000000 ____D () C:\Users\Haribo\Desktop\2014_01_25 2014-06-02 19:25 - 2014-06-02 19:25 - 00043907 _____ () C:\Users\Haribo\Desktop\Anschreiben Melan.odt 2014-06-02 19:02 - 2014-04-22 21:56 - 00000000 ____D () C:\Users\Haribo\Desktop\2014_04_22 2014-06-02 18:45 - 2014-06-02 18:45 - 00046285 _____ () C:\Users\Haribo\Desktop\Anschreiben Hotel Krone.odt 2014-06-02 18:43 - 2014-06-02 18:43 - 00046273 _____ () C:\Users\Haribo\Desktop\Anschreiben ibis aachen.odt 2014-06-02 18:41 - 2014-06-02 18:41 - 00046357 _____ () C:\Users\Haribo\Desktop\Anschreiben Mercure Hotel.odt 2014-06-02 18:35 - 2014-06-02 17:47 - 00046209 _____ () C:\Users\Haribo\Desktop\Anschreiben Eiscafe Annabella.odt 2014-06-02 17:42 - 2014-06-02 17:09 - 00046166 _____ () C:\Users\Haribo\Desktop\Anschreiben Art Hotel.odt 2014-06-01 16:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-30 23:34 - 2013-09-04 03:14 - 00096432 _____ () C:\Users\Haribo\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-30 23:34 - 2009-07-14 06:50 - 00370576 ____H () C:\Windows\system32\FNTCACHE.DAT 2014-05-30 01:05 - 2014-05-30 00:43 - 00000000 ____D () C:\Program Files (x86)\AVS4YOU 2014-05-30 00:57 - 2014-05-30 00:57 - 00000000 _____ () C:\Users\Haribo\AppData\Roaming\AVSDVDPlayer.m3u 2014-05-30 00:44 - 2014-05-30 00:44 - 00000000 ____D () C:\ProgramData\AVS4YOU 2014-05-30 00:30 - 2013-09-14 16:49 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\vlc 2014-05-29 23:52 - 2014-05-29 23:29 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\dvdcss 2014-05-29 14:54 - 2011-04-12 10:14 - 00710340 ____H () C:\Windows\system32\perfh007.dat 2014-05-29 14:54 - 2011-04-12 10:14 - 00154638 ____H () C:\Windows\system32\perfc007.dat 2014-05-29 14:54 - 2009-07-14 07:12 - 01650002 ____H () C:\Windows\system32\PerfStringBackup.INI 2014-05-28 17:44 - 2014-06-04 17:46 - 00000000 ____D () C:\Users\Haribo\Downloads\David Perlmutter 2014-05-28 15:20 - 2013-10-29 01:31 - 00000000 ____D () C:\Users\Haribo\AppData\Local\Greenshot 2014-05-26 17:58 - 2014-05-26 17:57 - 00017996 _____ () C:\Users\Haribo\Desktop\Anschreiben Continental.odt 2014-05-26 17:27 - 2014-05-26 17:24 - 00046518 _____ () C:\Users\Haribo\Desktop\Anschreiben Kisters.odt 2014-05-24 21:37 - 2014-05-24 20:42 - 00017225 _____ () C:\Users\Haribo\Desktop\Phillips Bewerbung.odt 2014-05-24 21:36 - 2014-05-24 20:48 - 00017563 _____ () C:\Users\Haribo\Desktop\Grünenthal alex Bewerbung.odt 2014-05-24 10:59 - 2013-10-08 19:23 - 00027957 _____ () C:\Users\Haribo\Desktop\Mein Rezeptbuch din a5.odt 2014-05-22 14:42 - 2013-09-06 12:00 - 00130584 ____H (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-22 14:42 - 2013-09-06 12:00 - 00112080 ____H (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-18 20:03 - 2013-09-06 11:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-18 02:29 - 2014-05-18 02:29 - 00001949 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2014-05-18 02:29 - 2014-05-18 02:29 - 00001899 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2014-05-18 02:29 - 2014-05-18 02:29 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\Canneverbe Limited 2014-05-18 02:29 - 2014-05-18 02:29 - 00000000 ____D () C:\ProgramData\Canneverbe Limited 2014-05-18 02:29 - 2014-05-18 02:29 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2014-05-18 02:21 - 2014-05-18 02:21 - 00000000 ____D () C:\Users\Haribo\AppData\Local\ashampoo 2014-05-18 02:21 - 2014-05-18 02:19 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-05-17 21:44 - 2014-05-17 21:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-16 00:30 - 2014-05-16 00:20 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\DVDVideoSoft 2014-05-16 00:23 - 2014-05-16 00:22 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-05-16 00:22 - 2014-05-16 00:22 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\TuneUp Software 2014-05-16 00:22 - 2014-05-16 00:22 - 00000000 ____D () C:\Users\Haribo\AppData\Local\TuneUp Software 2014-05-16 00:22 - 2014-05-16 00:21 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-05-16 00:21 - 2014-05-16 00:21 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\OpenCandy 2014-05-15 22:31 - 2013-09-12 13:35 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-15 09:58 - 2013-09-04 03:10 - 00000000 ___RD () C:\Users\Haribo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-15 09:57 - 2014-05-07 02:56 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 09:57 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\PolicyDefinitions 2014-05-15 01:35 - 2013-09-07 00:04 - 00000000 ___HD () C:\Windows\system32\MRT 2014-05-15 01:34 - 2013-09-07 00:04 - 93223848 ____H (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-13 16:13 - 2014-03-28 09:38 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\Security System 2 2014-05-13 16:13 - 2014-03-28 09:38 - 00000000 ____D () C:\Users\Haribo\AppData\Roaming\BupSystem 2014-05-13 00:10 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\NDF Some content of TEMP: ==================== C:\Users\Haribo\AppData\Local\Temp\AcDeltree.exe C:\Users\Haribo\AppData\Local\Temp\avgnt.exe C:\Users\Haribo\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Haribo\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Haribo\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Haribo\AppData\Local\Temp\MouseKeyboardCenterx64_1031.exe C:\Users\Haribo\AppData\Local\Temp\nsbD38C.exe C:\Users\Haribo\AppData\Local\Temp\nsbF820.exe C:\Users\Haribo\AppData\Local\Temp\nslCB41.exe C:\Users\Haribo\AppData\Local\Temp\nso76AC.exe C:\Users\Haribo\AppData\Local\Temp\nswF542.exe C:\Users\Haribo\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Haribo\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\Haribo\AppData\Local\Temp\vlc-2.1.4-win64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-07 19:11 ==================== End Of Log ============================ |
10.06.2014, 11:29 | #6 |
/// the machine /// TB-Ausbilder | Probleme wegen Spammail?! Nö das is ein kleiner Fehler in dem Programm, kannste ignorieren. Alles sauber
__________________ --> Probleme wegen Spammail?! |
Themen zu Probleme wegen Spammail?! |
beste, besten, email, fake, frage, heute, leutz, malware, nichts, probleme, rechnung, spammail, telekom, troja, trojaner, trojanern, voll, weiterhelfen |