|
Plagegeister aller Art und deren Bekämpfung: cdn.cloudwm-Seite kann nicht geladen werden!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.07.2014, 10:55 | #16 |
/// the machine /// TB-Ausbilder | cdn.cloudwm-Seite kann nicht geladen werden!ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2014, 21:08 | #17 |
| cdn.cloudwm-Seite kann nicht geladen werden! Hier die Eset Log-Datei
__________________Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=aee02c90160f894291255196e1940d30 # engine=19295 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-07-22 07:52:11 # local_time=2014-07-22 09:52:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Norton 360' # compatibility_mode=3598 16777213 100 100 100717 156721227 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 6043608 33337063 0 0 # scanned=509895 # found=23 # cleaned=0 # scan_time=14771 sh=972DB9071C719922142BE77CF935C208B66F8DE2 ft=1 fh=c50a95d882970223 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\CHRIST~1\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=8872824DA370A893AF27EDA5914C81B016FDE10D ft=1 fh=7df6b6eaf73c436e vn="Variante von Win64/Toolbar.MyWebSearch.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\4jauxstb64.dll.vir" sh=2DB76E64C44398F284BB9607477FFAB286C822A5 ft=1 fh=a15fd42821542f57 vn="Variante von Win32/Toolbar.MyWebSearch.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbarsvc.exe.vir" sh=242016E4DB00A6326CB726E517BD8C44C0D9AF4F ft=1 fh=5585cde8f9518639 vn="Variante von Win32/Toolbar.MyWebSearch.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbrmon.exe.vir" sh=BD3BA77A76482B8432E852B6C12718DFD8A805E8 ft=1 fh=d0f2a63db6645c6c vn="Variante von Win64/Toolbar.MyWebSearch.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbrmon64.exe.vir" sh=E22F1101BCDB847DDA207076C20847EE7BA14783 ft=1 fh=6dacd07894aac7d3 vn="Variante von Win64/Toolbar.MyWebSearch.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\4jbrstub64.dll.vir" sh=BFF74D4CF269E36527CE43A484298A7797D85DDB ft=1 fh=e0568f6273d6b1f6 vn="Variante von Win64/Toolbar.MyWebSearch.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\4jdlghk64.dll.vir" sh=F76EBFB49A14135188A858A9A19ADE33D841FAD9 ft=1 fh=fd6523e46258979f vn="Variante von Win64/Toolbar.MyWebSearch.A evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\AppIntegrator64.exe.vir" sh=385877E899E02E0F9C551D5B3293270C5FEB9D6B ft=1 fh=fc49323ed3498cd9 vn="Variante von Win64/Toolbar.MyWebSearch.A evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\AppIntegratorStub64.dll.vir" sh=E9C0F7642BFDCA4F304679F44A2351765D25D7E3 ft=1 fh=df272951a00ae964 vn="Variante von Win64/Toolbar.MyWebSearch.A evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\ASSISTMONITOR64.DLL.vir" sh=C0F1C1AD7E3E71F00D10961BF88368998314C8B5 ft=1 fh=1104306037fac477 vn="Variante von Win32/Toolbar.MyWebSearch.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\CrExtP4j.exe.vir" sh=2C88C56E84FB90C27DA50DF87011A98C77362B19 ft=1 fh=054dd36e0a8ce909 vn="Variante von Win64/Toolbar.MyWebSearch.A evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\Hpg64.dll.vir" sh=AC297627AB9AB7AD194EC4E3CDE50D2A42F9A4FA ft=1 fh=609aefa527ec4346 vn="Win32/Toolbar.MyWebSearch.AF evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\RadioRage_4j\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE.vir" sh=98B3D6C0D2C39F3E856774B9BB6E4A1727896B10 ft=1 fh=9891fd21f13679d3 vn="Win32/Hoax.Delf.AE Anwendung" ac=I fn="D:\Daten\Sonstiges\Ärgern\Opened.exe" sh=8D9AB0A9F23A73A2C8DB4F236268F988E557BA50 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.FlyStudio evtl. unerwünschte Anwendung" ac=I fn="E:\Downloads\Programme\Betriebssysteme\Activator\Windows 7\SLIC Dump ToolKit v.2.3.rar" sh=CC42E8EF64107B7131FFCF6F7DF220D9C7A40DD5 ft=0 fh=0000000000000000 vn="Win32/Qhost Trojaner" ac=I fn="E:\Downloads\Programme\Install\Nero 12.5 Platinum HD.rar" sh=0F3C4A44BC42A18308962F73AB92FE6EE9D3018D ft=0 fh=0000000000000000 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="E:\Downloads\Programme\Tools\DAEMON Tools Ultra.rar" sh=C8B6C19B9BB40EFC3662CE6C11632008DFB09361 ft=0 fh=0000000000000000 vn="Variante von MSIL/Spy.Agent.KW Trojaner" ac=I fn="E:\Downloads\Programme\Tools\DDL-Files Fixer.rar" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAD Trojaner" ac=I fn="E:\Downloads\Spiele\Action\Assasins Creed III\Assasins Creed III.iso" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="E:\Downloads\Spiele\Action\Tom Clancy's Splinter Cell Conviction\Tom Clancy's Splinter Cell Conviction.iso" sh=A58A00A0CA69481ED240E975557351DCB8DC4708 ft=0 fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAH Trojaner" ac=I fn="E:\Downloads\Spiele\Rennspiele\SBK Generations\SBK Generations.iso" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="E:\Downloads\Spiele\Rollenspiele\Fabel III\Fabel III.iso" sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="Variante von Win32/Packed.VMProtect.AAA Trojaner" ac=I fn="E:\Downloads\Spiele\Strategie\Die Siedler 7 - Wege zu einem Koenigreich\Die Siedler 7 - Wege zu einem Koenigreich.iso" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Windows Defender Norton 360 Online WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2014 TuneUp Utilities 2014 (de-DE) TuneUp Utilities 2014 Java 7 Update 60 Adobe Flash Player 14.0.0.145 Mozilla Firefox 23.0 Firefox out of Date! ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-07-2014 Ran by Christoph (administrator) on PC-CHRISTOPH on 22-07-2014 22:07:47 Running from C:\Users\Christoph\Desktop Platform: Windows 8 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Stardock Software, Inc) C:\Tools\Stardock\Decor8\Decor8Srv.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe (Stardock Software, Inc) C:\Program Files (x86)\Stardock\Start8\Start8_64.exe (Stardock Software, Inc) C:\Tools\Stardock\Decor8\Decor8_64.exe (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (TuneUp Software) C:\Tools\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe (Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (TuneUp Software) C:\Tools\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Apple Inc.) C:\Tools\Common Files\Apple\Internet Services\iCloudServices.exe (Microsoft Corporation) C:\Install\Microsoft Office\Office15\ONENOTEM.EXE (Dropbox, Inc.) C:\Users\Christoph\AppData\Roaming\Dropbox\bin\Dropbox.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Adobe Systems Inc.) C:\Install\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Qualcomm Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (Mozilla Corporation) C:\Tools\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtPreLoad.exe [64640 2012-12-28] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1212560 2012-06-13] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [516928 2013-02-15] (Acronis) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-04-30] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation) HKLM-x32\...\Run: [Shwicon9106] => C:\Program Files (x86)\Multimedia Card Reader(9106)\Shwicon9106.exe [262144 2012-06-28] () HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1105848 2013-01-10] (Acronis) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Install\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Install\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-08-21] (DivX, LLC) HKLM-x32\...\Run: [WsmUpdater] => C:\Program Files (x86)\Web Solution Mart\Windows 8 Codecs Pack\Updater.exe [292208 2012-05-18] (Web Solution Mart) HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [480648 2014-04-01] (Autodesk Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Tools\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.) HKU\.DEFAULT\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.) HKU\S-1-5-21-3507760142-4053387310-2989893969-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1081224 2013-02-05] (Autodesk, Inc.) HKU\S-1-5-21-3507760142-4053387310-2989893969-1001\...\Run: [iCloudServices] => C:\Tools\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.) HKU\S-1-5-21-3507760142-4053387310-2989893969-1001\...\Policies\Explorer: [] HKU\S-1-5-21-3507760142-4053387310-2989893969-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 Startup: C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk ShortcutTarget: An OneNote senden.lnk -> C:\Install\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Christoph\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Install\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Install\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Install\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: AcronisSyncError -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Install\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncInProgress -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Install\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AcronisSyncOk -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Install\Acronis\TrueImageHome\tishell64.dll (Acronis) ShellIconOverlayIdentifiers: AutoCAD Digital Signatures Icon Overlay Handler -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: OverlayExcluded -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayPending -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayProtected -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Install\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Install\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Install\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Christoph\AppData\Roaming\Mozilla\Firefox\Profiles\57pjfzjr.default FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\Install\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Tools\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM - C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @ptc.com/ProductViewLite - C:\Program Files (x86)\Common Files\PTC\np6_pvapplite9.dll (PTC) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Tools\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Tools\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Acrobat - C:\Install\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation) FF Extension: Fast Dial - C:\Users\Christoph\AppData\Roaming\Mozilla\Firefox\Profiles\57pjfzjr.default\Extensions\fastdial@telega.phpnet.us [2013-09-16] FF Extension: Hola Better Internet - C:\Users\Christoph\AppData\Roaming\Mozilla\Firefox\Profiles\57pjfzjr.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack [2014-07-20] FF Extension: OpenDownload² - C:\Users\Christoph\AppData\Roaming\Mozilla\Firefox\Profiles\57pjfzjr.default\Extensions\{210249CE-F888-11DD-B868-4CB456D89593} [2014-01-05] FF Extension: Adblock Plus - C:\Users\Christoph\AppData\Roaming\Mozilla\Firefox\Profiles\57pjfzjr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-16] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Install\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Install\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-08-16] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn [2014-07-22] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF [2014-04-06] FF StartMenuInternet: FIREFOX.EXE - C:\Tools\Mozilla Firefox\firefox.exe ==================== Services (Whitelisted) ================= R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [581000 2014-04-01] (Autodesk Inc.) R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [226944 2012-12-28] (Qualcomm Atheros Commnucations) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.) S2 AxAutoMntSrv; C:\Tools\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team) R2 Decor8; C:\Tools\Stardock\Decor8\Decor8Srv.exe [74416 2012-11-27] (Stardock Software, Inc) S2 DellDigitalDelivery; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [173056 2012-06-19] (Dell Products, LP.) [File not signed] R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2010-01-11] (Stardock Corporation) [File not signed] R2 IAStorDataMgrSvc; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [7168 2012-07-09] (Intel Corporation) [File not signed] R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe [265040 2014-06-27] (Symantec Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1618888 2014-04-30] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21009352 2014-04-30] (NVIDIA Corporation) R2 Start8; C:\Program Files (x86)\Stardock\Start8\Start8Srv.exe [143288 2014-04-04] (Stardock Software, Inc) S3 StarWindServiceAE; C:\Tools\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed] S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] S4 TeamViewer8; C:\Tools\TeamViewer\Version8\TeamViewer_Service.exe [5087584 2013-10-01] (TeamViewer GmbH) R2 TuneUp.UtilitiesSvc; C:\Tools\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2099512 2013-10-12] (TuneUp Software) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [81536 2012-12-26] (Atheros) ==================== Drivers (Whitelisted) ==================== S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc) S0 asahci64; C:\Windows\System32\drivers\asahci64.sys [49560 2012-09-17] (Asmedia Technology) [File not signed] R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\BASHDefs\20140703.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-28] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1504000.00D\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-06-11] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-06-11] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\IPSDefs\20140721.001\IDSvia64.sys [525016 2014-04-04] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140722.002\ENG64.SYS [126040 2014-04-06] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140722.002\EX64.SYS [2099288 2014-04-06] (Symantec Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19744 2014-04-30] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-16] (Duplex Secure Ltd.) R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1504000.00D\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1504000.00D\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation) S3 STHFK; C:\Windows\System32\Drivers\sthfk64.sys [46632 2012-02-03] (CSR plc.) R0 SymDS; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\N360x64\1504000.00D\SymELAM.sys [23568 2013-08-01] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-06] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1504000.00D\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1504000.00D\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2013-08-16] (Acronis International GmbH) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [183224 2013-08-16] (Acronis) R3 TuneUpUtilitiesDrv; C:\Tools\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software) R3 xusb22; C:\Windows\System32\drivers\xusb22.sys [89088 2012-07-26] (Microsoft Corporation) U3 atwag4wd; C:\Windows\System32\Drivers\atwag4wd.sys [0 ] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-22 22:07 - 2014-07-22 22:07 - 02090496 _____ (Farbar) C:\Users\Christoph\Desktop\FRST64.exe 2014-07-22 22:07 - 2014-07-22 22:07 - 00027382 _____ () C:\Users\Christoph\Desktop\FRST.txt 2014-07-22 19:23 - 2014-07-22 20:06 - 3538040236 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e08.avi 2014-07-22 19:23 - 2014-07-22 20:06 - 3522442212 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e07.avi 2014-07-22 19:23 - 2014-07-22 20:06 - 3420949972 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e09.avi 2014-07-22 19:23 - 2014-07-22 20:04 - 3192830142 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e10.avi 2014-07-22 17:37 - 2014-07-22 17:37 - 00000000 ___RD () C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-07-21 18:30 - 2014-07-21 18:30 - 00001862 _____ () C:\Users\Public\Desktop\Xilisoft Video Converter Ultimate.lnk 2014-07-21 18:05 - 2014-07-21 18:05 - 00000000 ____D () C:\Windows\ERUNT 2014-07-20 22:31 - 2014-07-20 22:31 - 00000000 ____D () C:\Users\Christoph\Documents\Freemake 2014-07-20 09:50 - 2014-07-20 09:50 - 00261710 _____ () C:\Windows\msxml4-KB2758694-enu.LOG 2014-07-19 12:22 - 2014-07-19 12:22 - 00040211 _____ () C:\ComboFix.txt 2014-07-19 12:20 - 2014-07-19 12:20 - 995721956 _____ () C:\Windows\MEMORY.DMP 2014-07-19 12:08 - 2014-07-19 12:08 - 00001285 _____ () C:\CF-Submit.htm 2014-07-19 12:07 - 2014-07-19 12:23 - 00000000 ____D () C:\ComboFix 2014-07-17 20:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-17 20:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-17 20:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-17 20:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-17 20:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-17 20:27 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-07-17 20:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-17 20:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-17 20:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-17 20:25 - 2014-07-19 12:23 - 00000000 ____D () C:\Qoobox 2014-07-17 20:25 - 2014-07-19 12:11 - 00000000 ____D () C:\Windows\erdnt 2014-07-16 17:47 - 2014-07-16 17:47 - 00000744 _____ () C:\Users\Christoph\Desktop\JDownloaderExp - Verknüpfung.lnk 2014-07-15 19:26 - 2014-07-15 19:26 - 00000000 ____D () C:\zoek_backup 2014-07-15 19:25 - 2014-07-22 22:07 - 00000000 ____D () C:\FRST 2014-07-14 21:32 - 2014-07-21 22:04 - 00874368 _____ () C:\Windows\PFRO.log 2014-07-14 21:16 - 2014-07-22 17:54 - 00690250 _____ () C:\Windows\WindowsUpdate.log 2014-07-14 20:51 - 2014-07-20 09:39 - 05117056 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-14 20:45 - 2014-07-16 11:39 - 00045248 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys 2014-07-14 20:45 - 2014-07-14 20:45 - 00000000 ____D () C:\Windows\system32\log 2014-07-14 20:45 - 2014-07-14 20:45 - 00000000 ____D () C:\Windows\SMinidump 2014-07-14 20:39 - 2014-07-14 20:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-14 20:35 - 2014-06-19 04:12 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-14 20:35 - 2014-06-19 04:12 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-14 20:35 - 2014-06-19 04:12 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-07-14 20:35 - 2014-06-19 04:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-07-14 20:35 - 2014-06-19 04:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-14 20:35 - 2014-06-19 04:11 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-14 20:35 - 2014-06-19 04:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-14 20:35 - 2014-06-19 04:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-14 20:35 - 2014-06-19 04:10 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-14 20:35 - 2014-06-19 04:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-14 20:35 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-14 20:35 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-14 20:35 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-14 20:35 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-14 20:35 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-14 20:35 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-14 20:35 - 2014-06-19 02:53 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-14 20:35 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-14 20:35 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-14 20:35 - 2014-06-19 02:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-14 20:35 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-14 20:35 - 2014-06-19 00:05 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-07-14 20:34 - 2014-07-01 00:42 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-14 20:34 - 2014-07-01 00:42 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-14 20:34 - 2014-07-01 00:42 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-07-14 20:34 - 2014-06-28 05:35 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-14 20:34 - 2014-06-18 01:27 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-14 20:34 - 2014-06-18 01:24 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-14 20:34 - 2014-06-11 06:18 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-14 20:34 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-14 20:34 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-14 20:34 - 2014-06-03 00:33 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2014-07-14 20:34 - 2014-05-30 01:31 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-07-14 20:34 - 2014-05-30 01:03 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-07-14 20:34 - 2014-05-30 01:02 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-14 20:34 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2014-07-14 20:34 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-14 20:34 - 2014-05-29 06:04 - 00094552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2014-07-14 20:34 - 2014-05-08 03:34 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-07-14 19:49 - 2014-07-14 19:49 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360 2014-07-13 20:18 - 2014-07-13 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-08 19:30 - 2014-07-08 19:30 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-07-06 18:24 - 2014-05-03 08:34 - 06974808 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-07-06 18:24 - 2014-05-03 08:33 - 01824808 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-07-06 18:24 - 2014-05-02 00:37 - 01023488 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2014-07-06 18:23 - 2014-05-20 04:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-06 18:23 - 2014-05-20 01:45 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-07-06 18:23 - 2014-05-20 01:45 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-07-06 18:23 - 2014-05-20 01:24 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-06 18:23 - 2014-05-20 01:24 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-07-06 18:23 - 2014-05-20 01:24 - 00773632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-06 18:23 - 2014-05-20 01:24 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2014-07-06 18:23 - 2014-05-20 01:24 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2014-07-06 18:23 - 2014-05-20 01:24 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-06 18:23 - 2014-05-15 00:43 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-07-06 18:23 - 2014-05-15 00:43 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-06 18:23 - 2014-05-15 00:42 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-07-06 18:23 - 2014-05-15 00:42 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-07-06 18:23 - 2014-05-03 06:51 - 01408976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-07-06 18:23 - 2014-04-30 00:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2014-07-06 18:23 - 2014-04-30 00:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2014-07-06 18:23 - 2014-04-24 01:51 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-07-06 18:23 - 2014-04-24 01:51 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-06 18:23 - 2014-04-24 01:38 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-07-06 18:23 - 2014-04-24 01:38 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-06 18:23 - 2014-02-08 06:34 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2014-07-05 18:55 - 2014-07-06 18:23 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\MAGIX 2014-07-05 18:55 - 2014-07-06 18:23 - 00000000 ____D () C:\ProgramData\MAGIX 2014-07-05 18:55 - 2014-07-05 18:55 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Xara 2014-07-05 18:55 - 2014-07-05 18:55 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-07-05 08:16 - 2014-07-14 17:48 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Adobe 2014-06-23 21:15 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-23 21:15 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-23 21:14 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-06-23 21:14 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-06-23 21:09 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-06-23 21:09 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-06-23 20:32 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys ==================== One Month Modified Files and Folders ======= 2014-07-22 22:07 - 2014-07-22 22:07 - 02090496 _____ (Farbar) C:\Users\Christoph\Desktop\FRST64.exe 2014-07-22 22:07 - 2014-07-22 22:07 - 00027382 _____ () C:\Users\Christoph\Desktop\FRST.txt 2014-07-22 22:07 - 2014-07-15 19:25 - 00000000 ____D () C:\FRST 2014-07-22 21:48 - 2014-02-11 19:28 - 00001142 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-22 21:48 - 2013-08-16 12:29 - 00005140 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for PC-CHRISTOPH-Christoph PC-Christoph 2014-07-22 21:30 - 2013-08-16 13:47 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-22 21:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-07-22 20:19 - 2013-08-16 11:15 - 03669504 ___SH () C:\Users\Christoph\Desktop\Thumbs.db 2014-07-22 20:16 - 2012-07-26 12:27 - 00756568 _____ () C:\Windows\system32\perfh007.dat 2014-07-22 20:16 - 2012-07-26 12:27 - 00157238 _____ () C:\Windows\system32\perfc007.dat 2014-07-22 20:16 - 2012-07-26 09:28 - 01757638 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-22 20:06 - 2014-07-22 19:23 - 3538040236 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e08.avi 2014-07-22 20:06 - 2014-07-22 19:23 - 3522442212 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e07.avi 2014-07-22 20:06 - 2014-07-22 19:23 - 3420949972 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e09.avi 2014-07-22 20:04 - 2014-07-22 19:23 - 3192830142 _____ () C:\Users\Christoph\Desktop\gtvg-got.720p.s01e10.avi 2014-07-22 17:54 - 2014-07-14 21:16 - 00690250 _____ () C:\Windows\WindowsUpdate.log 2014-07-22 17:48 - 2014-02-11 19:28 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-22 17:47 - 2013-08-15 12:56 - 00000000 ____D () C:\Users\Christoph\Documents\Outlook-Dateien 2014-07-22 17:37 - 2014-07-22 17:37 - 00000000 ___RD () C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-07-22 17:35 - 2014-05-15 16:25 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\DropboxMaster 2014-07-22 17:35 - 2013-08-15 17:26 - 00000000 ___RD () C:\Users\Christoph\Dropbox 2014-07-22 17:35 - 2013-08-15 17:25 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\Dropbox 2014-07-22 17:34 - 2013-08-15 09:50 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-22 17:34 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-21 22:04 - 2014-07-14 21:32 - 00874368 _____ () C:\Windows\PFRO.log 2014-07-21 21:09 - 2013-08-15 18:28 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\Skype 2014-07-21 19:02 - 2013-08-15 10:46 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Deployment 2014-07-21 18:30 - 2014-07-21 18:30 - 00001862 _____ () C:\Users\Public\Desktop\Xilisoft Video Converter Ultimate.lnk 2014-07-21 18:30 - 2013-08-16 22:22 - 00000000 ____D () C:\ProgramData\Xilisoft 2014-07-21 18:30 - 2013-08-16 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xilisoft 2014-07-21 18:05 - 2014-07-21 18:05 - 00000000 ____D () C:\Windows\ERUNT 2014-07-21 18:02 - 2013-10-01 21:21 - 00000000 ____D () C:\AdwCleaner 2014-07-21 17:59 - 2013-08-15 12:51 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-07-21 17:53 - 2013-08-15 17:20 - 00000000 ____D () C:\Windows\CUR_DIR 2014-07-20 23:14 - 2014-01-09 17:53 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\vlc 2014-07-20 23:05 - 2013-08-15 12:31 - 00000000 ____D () C:\Tools 2014-07-20 23:02 - 2013-08-15 10:28 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3507760142-4053387310-2989893969-1001 2014-07-20 22:57 - 2013-08-15 09:46 - 00000000 ____D () C:\Users\Christoph\AppData\Local\VirtualStore 2014-07-20 22:55 - 2013-08-16 00:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro 2014-07-20 22:31 - 2014-07-20 22:31 - 00000000 ____D () C:\Users\Christoph\Documents\Freemake 2014-07-20 10:22 - 2013-08-15 17:22 - 00000000 ____D () C:\Users\Public\Documents\Stardock 2014-07-20 10:22 - 2013-08-15 13:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock 2014-07-20 10:22 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-07-20 09:53 - 2013-08-15 12:47 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2014-07-20 09:53 - 2013-08-15 12:43 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-07-20 09:50 - 2014-07-20 09:50 - 00261710 _____ () C:\Windows\msxml4-KB2758694-enu.LOG 2014-07-20 09:39 - 2014-07-14 20:51 - 05117056 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-19 21:09 - 2013-08-15 10:46 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Apps\2.0 2014-07-19 12:36 - 2014-04-01 15:07 - 00000000 ____D () C:\Windows\Minidump 2014-07-19 12:23 - 2014-07-19 12:07 - 00000000 ____D () C:\ComboFix 2014-07-19 12:23 - 2014-07-17 20:25 - 00000000 ____D () C:\Qoobox 2014-07-19 12:22 - 2014-07-19 12:22 - 00040211 _____ () C:\ComboFix.txt 2014-07-19 12:21 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-07-19 12:20 - 2014-07-19 12:20 - 995721956 _____ () C:\Windows\MEMORY.DMP 2014-07-19 12:11 - 2014-07-17 20:25 - 00000000 ____D () C:\Windows\erdnt 2014-07-19 12:08 - 2014-07-19 12:08 - 00001285 _____ () C:\CF-Submit.htm 2014-07-19 12:08 - 2013-08-15 13:02 - 00000000 ____D () C:\Users\Christoph\AppData\Local\CrashDumps 2014-07-19 09:21 - 2012-07-26 07:26 - 15466496 _____ () C:\Windows\system32\config\SYSTEM.bak 2014-07-19 09:21 - 2012-07-26 07:26 - 100433920 _____ () C:\Windows\system32\config\SOFTWARE.bak 2014-07-19 09:21 - 2012-07-26 07:26 - 00376832 _____ () C:\Windows\system32\config\DEFAULT.bak 2014-07-19 09:21 - 2012-07-26 07:26 - 00073728 _____ () C:\Windows\system32\config\SAM.bak 2014-07-19 09:21 - 2012-07-26 07:26 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak 2014-07-17 20:32 - 2012-07-26 10:08 - 05144576 _____ () C:\Windows\system32\config\DRIVERS.bak 2014-07-17 20:30 - 2013-08-16 14:03 - 00000000 ____D () C:\ProgramData\TEMP 2014-07-16 22:48 - 2012-07-26 07:26 - 00524288 ___SH () C:\Windows\system32\config\BBI 2014-07-16 18:18 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\Resources 2014-07-16 17:49 - 2013-08-15 18:33 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\Tunngle 2014-07-16 17:47 - 2014-07-16 17:47 - 00000744 _____ () C:\Users\Christoph\Desktop\JDownloaderExp - Verknüpfung.lnk 2014-07-16 11:39 - 2014-07-14 20:45 - 00045248 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys 2014-07-15 19:26 - 2014-07-15 19:26 - 00000000 ____D () C:\zoek_backup 2014-07-15 19:05 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-14 21:34 - 2014-01-03 19:00 - 00000000 ____D () C:\Users\Christoph\AppData\Local\NPE 2014-07-14 21:31 - 2014-06-15 18:38 - 00000000 ____D () C:\Program Files\KMSpico 2014-07-14 21:05 - 2014-06-15 18:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico 2014-07-14 21:05 - 2014-05-03 12:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoCAD Architecture 2015 - Deutsch (German) 2014-07-14 21:05 - 2013-10-28 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management 2014-07-14 21:05 - 2013-08-25 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk 2014-07-14 21:05 - 2013-08-25 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoCAD 2014 - Deutsch (German) 2014-07-14 21:05 - 2013-08-17 12:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2014-07-14 21:05 - 2013-08-15 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP7200 series 2014-07-14 21:05 - 2013-08-15 09:46 - 00000000 ___RD () C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-07-14 21:05 - 2013-02-16 14:23 - 00000000 ____D () C:\Windows\Panther 2014-07-14 21:05 - 2012-07-26 10:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-07-14 20:45 - 2014-07-14 20:45 - 00000000 ____D () C:\Windows\system32\log 2014-07-14 20:45 - 2014-07-14 20:45 - 00000000 ____D () C:\Windows\SMinidump 2014-07-14 20:39 - 2014-07-14 20:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-14 20:39 - 2013-12-27 15:27 - 00003114 _____ () C:\Windows\System32\Tasks\RDReminder 2014-07-14 20:39 - 2013-08-15 11:44 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-14 20:39 - 2012-07-26 12:29 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-14 20:39 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 20:39 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-14 20:39 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-14 20:38 - 2013-02-16 14:59 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-14 20:30 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\NDF 2014-07-14 20:24 - 2013-08-16 00:24 - 00000879 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-07-14 20:24 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\ELAMBKUP 2014-07-14 19:49 - 2014-07-14 19:49 - 00000000 ____D () C:\Windows\System32\Tasks\Norton 360 2014-07-14 19:49 - 2014-04-06 19:30 - 00003206 _____ () C:\Windows\System32\Tasks\Norton WSC Integration 2014-07-14 19:49 - 2014-04-06 19:29 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 2014-07-14 19:49 - 2014-04-06 19:29 - 00000000 ____D () C:\Windows\system32\Drivers\N360x64 2014-07-14 17:48 - 2014-07-05 08:16 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Adobe 2014-07-13 20:18 - 2014-07-13 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-07-13 20:18 - 2013-11-06 19:44 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-07-13 20:18 - 2013-11-06 19:44 - 00000000 ____D () C:\Program Files\iTunes 2014-07-13 20:18 - 2013-11-06 19:44 - 00000000 ____D () C:\Program Files\iPod 2014-07-08 19:30 - 2014-07-08 19:30 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-07-08 19:30 - 2013-08-16 13:47 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-06 22:56 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-07-06 22:05 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore 2014-07-06 18:26 - 2013-08-15 12:43 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Microsoft Help 2014-07-06 18:23 - 2014-07-05 18:55 - 00000000 ____D () C:\Users\Christoph\AppData\Roaming\MAGIX 2014-07-06 18:23 - 2014-07-05 18:55 - 00000000 ____D () C:\ProgramData\MAGIX 2014-07-05 18:55 - 2014-07-05 18:55 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Xara 2014-07-05 18:55 - 2014-07-05 18:55 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-07-05 18:55 - 2007-04-27 10:43 - 00120200 _____ () C:\Windows\SysWOW64\DLLDEV32i.dll 2014-07-01 00:42 - 2014-07-14 20:34 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-01 00:42 - 2014-07-14 20:34 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-01 00:42 - 2014-07-14 20:34 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-06-28 05:35 - 2014-07-14 20:34 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-26 22:53 - 2012-07-26 10:14 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:53 - 2012-07-26 10:14 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-26 19:57 - 2013-08-18 19:54 - 00000000 ____D () C:\Users\Christoph\AppData\Local\Paint.NET 2014-06-26 17:43 - 2014-02-11 19:28 - 00004114 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-26 17:43 - 2014-02-11 19:28 - 00003878 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-23 21:30 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent Some content of TEMP: ==================== C:\Users\Christoph\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzhgmm8.dll C:\Users\Christoph\AppData\Local\Temp\proxy_vole6777642417427797054.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-10 19:22 ==================== End Of Log ============================ --- --- --- --- --- --- Nein sonst ist alles wieder Super Dankeschön, hier ist mir super geholfen worden !!! |
23.07.2014, 12:08 | #18 |
/// the machine /// TB-Ausbilder | cdn.cloudwm-Seite kann nicht geladen werden! Fertig
__________________Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
24.07.2014, 07:30 | #19 |
| cdn.cloudwm-Seite kann nicht geladen werden! Dankeschön für alles ! Es ist alles erledigt und funktioniert Habe keine Rückfragen mehr... |
24.07.2014, 19:12 | #20 |
/// the machine /// TB-Ausbilder | cdn.cloudwm-Seite kann nicht geladen werden! Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |