|
Log-Analyse und Auswertung: Windows Vista Spam-Email Anhang geöffnetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
18.07.2014, 17:51 | #1 |
| Windows Vista Spam-Email Anhang geöffnet Hallo liebes Trojaner-Board-Team, ich habe folgendes Problem: Meine Frau hat leider den Anhang einer Spam Email geöffnet. Nun bin ich mir leider nicht sicher ob dadurch eine Sicherheitslücke entstanden ist und ob der Laptop gefahrlos benutzt werden kann. Die Anleitung in eurem Forum habe ich befolgt und die benötigten Log-Files angehängt. vielen Lieben Dank im Vorraus!!! mfg Benjamin Pohl |
18.07.2014, 18:30 | #2 |
/// the machine /// TB-Ausbilder | Windows Vista Spam-Email Anhang geöffnet Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
18.07.2014, 19:53 | #3 |
| Windows Vista Spam-Email Anhang geöffnet Ach das wusste ich nicht. Sorry!
__________________Also hier der Gmer-Log: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-07-18 18:40:33 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST500LM012_HN-M500MBB rev.2AR10002 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\Lisa\AppData\Local\Temp\pwloakow.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwAddBootEntry [0x929454BA] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwAllocateVirtualMemory [0x92F28C22] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwAssignProcessToJobObject [0x92945ED6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateEvent [0x92950FA8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateEventPair [0x92950FF4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateIoCompletion [0x92951176] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateMutant [0x92950F16] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwCreateSection [0x92F28FA6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateSemaphore [0x92950F5E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateThread [0x9294611C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateTimer [0x92951130] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwDebugActiveProcess [0x9294693E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwDeleteBootEntry [0x92945508] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwFreeVirtualMemory [0x92F28CEA] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwLoadDriver [0x92F273EC] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwModifyBootEntry [0x92945556] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwNotifyChangeKey [0x9294A534] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwNotifyChangeMultipleKeys [0x929473A6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenEvent [0x92950FD2] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenEventPair [0x92951016] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenIoCompletion [0x9295119A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenMutant [0x92950F3C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenSection [0x929510BA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenSemaphore [0x92950F86] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwOpenTimer [0x92951154] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwProtectVirtualMemory [0x92F28E4A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwQueryObject [0x92947272] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwQueueApcThread [0x92946DD4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSetBootEntryOrder [0x929455A4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSetBootOptions [0x929455F2] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSetContextThread [0x929467BE] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSetSystemInformation [0x929451FA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSetSystemPowerState [0x929453AA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwShutdownSystem [0x92945350] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSuspendProcess [0x92946AF8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSuspendThread [0x92946C54] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwSystemDebugControl [0x9294541A] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwTerminateProcess [0x92F28EFE] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwTerminateThread [0x92946636] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwUnloadDriver [0x92F2741C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwVdmControl [0x92945640] SSDT \SystemRoot\System32\Drivers\aswSP.SYS ZwWriteVirtualMemory [0x92F28D96] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS ZwCreateThreadEx [0x929462F4] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!KeSetEvent + 10D 82ABB758 4 Bytes [BA, 54, 94, 92] .text ntkrnlpa.exe!KeSetEvent + 131 82ABB77C 4 Bytes [22, 8C, F2, 92] .text ntkrnlpa.exe!KeSetEvent + 191 82ABB7DC 4 Bytes [D6, 5E, 94, 92] {SALC ; POP ESI; XCHG ESP, EAX; XCHG EDX, EAX} .text ntkrnlpa.exe!KeSetEvent + 1D1 82ABB81C 8 Bytes [A8, 0F, 95, 92, F4, 0F, 95, ...] .text ntkrnlpa.exe!KeSetEvent + 1DD 82ABB828 4 Bytes [76, 11, 95, 92] {JBE 0x13; XCHG EBP, EAX; XCHG EDX, EAX} .text ... .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8F80F340, 0x3442A7, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\PDF Architect\HelperService.exe[200] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\system32\csrss.exe[560] KERNEL32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\system32\wininit.exe[612] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\system32\csrss.exe[624] KERNEL32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\system32\services.exe[656] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text ... .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1760] kernel32.dll!SetUnhandledExceptionFilter 76D9A9BD 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1760] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\system32\Dwm.exe[1788] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\Explorer.EXE[1804] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\ProgramData\WPM\wprotectmanager.exe[1852] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text C:\Windows\System32\spoolsv.exe[1948] kernel32.dll!GetBinaryTypeW + 70 76DC252F 1 Byte [62] .text ... ---- EOF - GMER 2.1 ---- FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01 Ran by Lisa (administrator) on LISALAPTOP on 18-07-2014 16:48:52 Running from C:\Users\Lisa\Downloads Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Cherished Technololgy LIMITED) C:\ProgramData\WPM\wprotectmanager.exe () C:\Program Files\Wireless Console 2\wcourier.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe (pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Dropbox, Inc.) C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [NvSvc] => C:\Windows\system32\nvsvc.dll [86016 2007-05-14] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [8429568 2007-05-14] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] => C:\Windows\system32\NvMcTray.dll [81920 2007-05-14] (NVIDIA Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-03-01] (Synaptics, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4444160 2007-04-25] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1822720 2007-04-13] (Realtek Semiconductor Corp.) HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-01-16] (ASUS) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.) HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [61440 2006-11-02] (ASUSTeK Computer INC.) HKLM\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4297136 2012-10-31] (AVAST Software) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM\...\Run: [] => [X] HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\MountPoints2: {04b379af-9c6a-11e3-bc07-001d6009185e} - F:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\MountPoints2: {a7b98961-97af-11e3-8b4e-001d6009185e} - F:\HTC_Sync_Manager_PC.exe Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700&type=default&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700&type=default&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1382370558&from=cor&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700&type=default&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700&type=default&q={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=ds&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700&type=default&q={searchTerms} BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR) DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab Hosts: Hosts file not detected in the default directory Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\gdlpm4ty.default-1393772530668 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\delta-homes.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-02-09] FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-02-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-10] FF HKLM\...\Firefox\Extensions: [quick_start@gmail.com] - C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\hxx9xz4g.default\extensions\quick_start@gmail.com FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-05-26] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ========================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-10-31] (AVAST Software) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 Wpm; C:\ProgramData\WPM\wprotectmanager.exe [501904 2014-02-26] (Cherished Technololgy LIMITED) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [21256 2012-10-31] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-10-31] (AVAST Software) R1 AswRdr; C:\Windows\system32\Drivers\AswRdr.sys [35928 2012-10-31] (AVAST Software) R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [738504 2012-10-31] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [361032 2012-10-31] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [54232 2012-10-31] (AVAST Software) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-04-02] (DT Soft Ltd) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 SiBulk; C:\Windows\System32\drivers\SiBulk.sys [16768 2008-02-08] () [File not signed] S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-18 16:48 - 2014-07-18 16:49 - 00016206 _____ () C:\Users\Lisa\Downloads\FRST.txt 2014-07-18 16:48 - 2014-07-18 16:49 - 00000000 ____D () C:\FRST 2014-07-18 16:47 - 2014-07-18 16:47 - 00000540 _____ () C:\Users\Lisa\Downloads\defogger_disable.log 2014-07-18 16:47 - 2014-07-18 16:47 - 00000156 _____ () C:\Users\Lisa\defogger_reenable 2014-07-18 16:45 - 2014-07-18 16:45 - 00380416 _____ () C:\Users\Lisa\Downloads\Gmer-19357.exe 2014-07-18 16:44 - 2014-07-18 16:44 - 01077248 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe 2014-07-18 16:43 - 2014-07-18 16:43 - 00050477 _____ () C:\Users\Lisa\Downloads\Defogger.exe 2014-07-15 15:40 - 2014-07-15 15:40 - 00131546 _____ () C:\Users\Lisa\Documents\Lisa Pohl Forderung stornierten Zahlung Ihrer Bestellung Ebay vom 15.07.2014.zip 2014-07-10 12:40 - 2014-06-07 02:19 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-10 12:40 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-10 12:40 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-10 12:40 - 2014-05-30 08:53 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-10 12:39 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-10 12:39 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-10 12:39 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-10 12:39 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-10 12:39 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-10 12:39 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-10 12:39 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-10 12:39 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-10 12:39 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-10 12:39 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-10 12:39 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-10 12:39 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-10 12:39 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-21 20:06 - 2014-06-21 20:06 - 00143552 _____ () C:\Windows\Minidump\Mini062114-01.dmp 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Local\cache 2014-06-21 13:07 - 2014-06-21 13:07 - 08790287 _____ (MusicBrainz) C:\Users\Lisa\Downloads\picard-setup-1.2.exe 2014-06-21 13:07 - 2014-06-21 13:07 - 00000000 ____D () C:\Program Files\MusicBrainz Picard ==================== One Month Modified Files and Folders ======= 2014-07-18 16:49 - 2014-07-18 16:48 - 00016206 _____ () C:\Users\Lisa\Downloads\FRST.txt 2014-07-18 16:49 - 2014-07-18 16:48 - 00000000 ____D () C:\FRST 2014-07-18 16:47 - 2014-07-18 16:47 - 00000540 _____ () C:\Users\Lisa\Downloads\defogger_disable.log 2014-07-18 16:47 - 2014-07-18 16:47 - 00000156 _____ () C:\Users\Lisa\defogger_reenable 2014-07-18 16:47 - 2013-02-09 15:25 - 00000000 ____D () C:\Users\Lisa 2014-07-18 16:45 - 2014-07-18 16:45 - 00380416 _____ () C:\Users\Lisa\Downloads\Gmer-19357.exe 2014-07-18 16:44 - 2014-07-18 16:44 - 01077248 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe 2014-07-18 16:44 - 2006-11-02 14:47 - 00004880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-18 16:44 - 2006-11-02 14:47 - 00004880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-18 16:43 - 2014-07-18 16:43 - 00050477 _____ () C:\Users\Lisa\Downloads\Defogger.exe 2014-07-18 16:42 - 2014-01-04 18:34 - 00000000 ___RD () C:\Users\Lisa\Dropbox 2014-07-18 16:42 - 2014-01-04 18:29 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Dropbox 2014-07-18 16:22 - 2014-02-23 18:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-18 14:46 - 2008-01-21 03:35 - 01981646 _____ () C:\Windows\WindowsUpdate.log 2014-07-18 02:00 - 2013-02-10 12:27 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Adobe 2014-07-17 16:13 - 2014-05-03 11:03 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\DropboxMaster 2014-07-17 16:12 - 2013-02-09 16:05 - 00027240 _____ () C:\Users\Lisa\AppData\Roaming\nvModes.001 2014-07-17 16:11 - 2013-02-10 13:53 - 00000000 ____D () C:\Windows\Minidump 2014-07-17 16:11 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-17 16:10 - 2013-02-10 13:52 - 299064631 _____ () C:\Windows\MEMORY.DMP 2014-07-15 15:40 - 2014-07-15 15:40 - 00131546 _____ () C:\Users\Lisa\Documents\Lisa XXXX Forderung stornierten Zahlung Ihrer Bestellung Ebay vom 15.07.2014.zip 2014-07-14 21:39 - 2006-11-02 15:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-12 21:13 - 2014-01-29 16:27 - 00000000 ____D () C:\Users\Lisa\Desktop\baby 2014-07-12 03:19 - 2006-11-02 14:47 - 03699568 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-12 03:15 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 20:22 - 2013-04-02 18:00 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-09 20:22 - 2013-04-02 18:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 16:41 - 2008-01-21 09:16 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-06 16:40 - 2006-11-02 14:52 - 00105490 _____ () C:\Windows\setupact.log 2014-07-05 06:08 - 2013-02-09 15:25 - 00000680 _____ () C:\Users\Lisa\AppData\Local\d3d9caps.dat 2014-06-25 14:47 - 2013-02-09 15:51 - 00027240 _____ () C:\Users\Lisa\AppData\Roaming\nvModes.dat 2014-06-21 20:06 - 2014-06-21 20:06 - 00143552 _____ () C:\Windows\Minidump\Mini062114-01.dmp 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Local\cache 2014-06-21 13:07 - 2014-06-21 13:07 - 08790287 _____ (MusicBrainz) C:\Users\Lisa\Downloads\picard-setup-1.2.exe 2014-06-21 13:07 - 2014-06-21 13:07 - 00000000 ____D () C:\Program Files\MusicBrainz Picard Some content of TEMP: ==================== C:\Users\Lisa\AppData\Local\Temp\AdobeApplicationManager.exe C:\Users\Lisa\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzqv5p8.dll C:\Users\Lisa\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe C:\Users\Lisa\AppData\Local\Temp\ICReinstall_UltimateCodec.exe C:\Users\Lisa\AppData\Local\Temp\InstallAX.exe C:\Users\Lisa\AppData\Local\Temp\InstallPlugin.exe C:\Users\Lisa\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-18 16:21 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- Der Addition-Log: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:15-07-2014 01 Ran by Lisa at 2014-07-18 16:49:48 Running from C:\Users\Lisa\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 2007 Microsoft Office Suite Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) 2007 Microsoft Office Suite Service Pack 3 (SP3) (Version: - Microsoft) Hidden 32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe AIR (Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Professional CS6 (HKLM\...\{BD5669B5-49FF-4490-B956-E9D7CB9B0ADC}) (Version: 12.0 - Adobe Systems Incorporated) Adobe Help Manager (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated) Adobe Help Manager (Version: 4.0.244 - Adobe Systems Incorporated) Hidden Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated) Adobe Media Player (Version: 1.8 - Adobe Systems Incorporated) Hidden Adobe Photoshop CS6 (HKLM\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) ASUS Touch Pad Extra (HKLM\...\{DB891739-2EB3-45A8-9CBD-941C255CECD4}) (Version: - ) Atheros Driver Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros) ATK Hotkey (HKLM\...\{3912D529-02BC-4CA8-B5ED-0D0C20EB6003}) (Version: 1.00.0014 - ATK) ATK Hotkey (HKLM\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0056 - ASUS) ATK Media (HKLM\...\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}) (Version: - ) ATKOSD2 (HKLM\...\{5C1DB4ED-E9B4-402D-BB14-D75D97D6C1A6}) (Version: 6.64.1.4 - ATK) avast! Free Antivirus (HKLM\...\avast) (Version: 7.0.1474.0 - AVAST Software) BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden C4700 (Version: 130.0.373.000 - Hewlett-Packard) Hidden CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd) Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC) Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) Free YouTube to MP3 Converter version 3.12.35.514 (HKLM\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.35.514 - DVDVideoSoft Ltd.) GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Photosmart C4700 All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{2012D762-5DCA-455A-B5FE-EDF79BC93E18}) (Version: 13.0 - HP) HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP) HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.001 - Hewlett-Packard) HPPhotoGadget (Version: 130.0.282.000 - Hewlett-Packard) Hidden hpPrintProjects (Version: 130.0.303.000 - Hewlett-Packard) Hidden HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden hpWLPGInstaller (Version: 130.0.303.000 - Hewlett-Packard) Hidden Inkscape 0.48 (HKLM\...\Inkscape) (Version: 0.48 - Partha Bagchi) Java 7 Update 55 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden LinuxLive USB Creator (HKLM\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere) MarketResearch (Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (Version: 1.00.0000 - Adobe) Hidden Motorola SM56 Speakerphone Modem (HKLM\...\SMSERIAL) (Version: 6.12.25.06 - Motorola Inc) Mozilla Firefox 30.0 (x86 de) (HKLM\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MusicBrainz Picard (HKLM\...\MusicBrainz Picard) (Version: 1.2 - MusicBrainz) Network (Version: 130.0.572.000 - Hewlett-Packard) Hidden NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) PDF Architect (HKLM\...\{80A07844-CA64-4DE4-AB61-D37DDBE8074F}) (Version: 1.0.52.8917 - pdfforge) PDF Settings CS6 (Version: 11.0 - Adobe Systems Incorporated) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.6.2 - pdfforge) PS_AIO_06_C4700_SW_Min (Version: 130.0.373.000 - Hewlett-Packard) Hidden Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5406 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM\...\{DC24971E-1946-445D-8A82-CE685433FA7D}) (Version: - Realtek) rebox.NET 1.9.5.0 (HKLM\...\rebox.NET 1.9.5.0) (Version: 1.9.5.0 - clone.AD) Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 9.1.19.0 - Synaptics) Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.0.5 (HKLM\...\VLC media player) (Version: 2.0.5 - VideoLAN) WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden Windows 7 USB/DVD Download Tool (HKLM\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) WinFlash (HKLM\...\{DE10AB76-4756-4913-BE25-55D1C1051F9A}) (Version: - ) Wireless Console 2 (HKLM\...\{83F73CB1-7705-49D1-9852-84D839CA2A45}) (Version: 2.0.8 - ATK) ==================== Restore Points ========================= 12-06-2014 09:47:45 Geplanter Prüfpunkt 15-06-2014 10:07:42 Windows Update 16-06-2014 10:45:04 Geplanter Prüfpunkt 17-06-2014 10:36:29 Geplanter Prüfpunkt 18-06-2014 13:07:57 Geplanter Prüfpunkt 19-06-2014 16:21:12 Geplanter Prüfpunkt 20-06-2014 09:33:10 Windows Update 21-06-2014 12:03:48 Geplanter Prüfpunkt 23-06-2014 18:31:01 Geplanter Prüfpunkt 24-06-2014 13:40:12 Windows Update 25-06-2014 11:17:07 Geplanter Prüfpunkt 27-06-2014 13:37:47 Geplanter Prüfpunkt 28-06-2014 15:51:39 Geplanter Prüfpunkt 30-06-2014 08:45:54 Geplanter Prüfpunkt 01-07-2014 15:58:24 Windows Update 02-07-2014 13:14:23 Geplanter Prüfpunkt 04-07-2014 11:44:51 Geplanter Prüfpunkt 08-07-2014 16:13:11 Windows Update 10-07-2014 12:20:24 Geplanter Prüfpunkt 11-07-2014 10:24:03 Windows Update 12-07-2014 01:59:32 Geplanter Prüfpunkt 13-07-2014 17:34:16 Geplanter Prüfpunkt 15-07-2014 09:25:09 Windows Update 17-07-2014 19:43:04 Geplanter Prüfpunkt 18-07-2014 11:46:35 Windows Update ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {1E5472BB-D34E-405B-8C30-553D8FFE065E} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {50961489-E600-4CCE-B5D1-9077B61FE4FC} - System32\Tasks\DigitalSite => C:\Users\Lisa\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {D603A389-11B6-4523-8536-FA3581E64592} - System32\Tasks\AdobeAAMUpdater-1.0-LisaPC-Lisa => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-12-10] (Adobe Systems Incorporated) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {F19D5DF4-ADB0-4882-B0F1-4145F723A175} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2012-10-31] (AVAST Software) Task: {F8C2B04B-663C-43DA-BB7D-E02F306108E2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\Lisa\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-07-18 12:18 - 2014-07-18 08:52 - 02820096 _____ () C:\Program Files\AVAST Software\Avast\defs\14071800\algo.dll 2013-02-09 15:50 - 2006-12-21 00:03 - 01036288 _____ () C:\Program Files\Wireless Console 2\wcourier.exe 2013-02-09 16:04 - 2007-01-17 20:26 - 07708672 _____ () C:\Program Files\ATKOSD2\ATKOSD2.exe 2014-01-19 13:09 - 2004-05-27 19:13 - 00057344 _____ () C:\Program Files\ATK Hotkey\CMSSC.dll 2014-01-19 13:09 - 2006-12-18 18:26 - 02420736 _____ () C:\Program Files\ATK Hotkey\ATKOSD.exe 2013-02-09 16:03 - 2006-10-25 16:37 - 00045056 _____ () C:\Program Files\ASUS\ATK Media\GERSTRING.dll 2014-07-17 16:12 - 2014-07-17 16:12 - 00043008 _____ () c:\users\lisa\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzqv5p8.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Lisa\AppData\Roaming\Dropbox\bin\libcef.dll 2014-01-22 18:53 - 2014-05-26 17:35 - 09496576 _____ () C:\Users\Lisa\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_rdlang32.deu 2014-05-08 13:21 - 2014-05-08 13:21 - 00305520 _____ () C:\Program Files\Adobe\Reader 10.0\Reader\sqlite.dll 2014-01-22 18:53 - 2014-07-12 17:14 - 00014336 _____ () C:\Users\Lisa\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Updater.DEU ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Lisa\Desktop\Email Signatur.jpg:com.dropbox.attributes ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= Name: Photosmart C4700 series Description: Photosmart C4700 series Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Photosmart C4700 series Description: Photosmart C4700 series Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (07/17/2014 04:12:42 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/15/2014 11:21:36 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/13/2014 11:02:41 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/12/2014 03:18:51 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/11/2014 00:21:06 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2014 06:09:39 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/06/2014 04:38:49 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/04/2014 10:27:45 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 02:47:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 05:54:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/17/2014 04:11:14 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 17.07.2014 um 16:09:08 unerwartet heruntergefahren. Error: (06/25/2014 01:16:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: HP Network Devices Support1 Error: (06/25/2014 01:15:30 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/25/2014 01:15:28 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {80EE4901-33A8-11D1-A213-0080C88593A5} Error: (06/24/2014 03:36:20 PM) (Source: disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (06/21/2014 08:06:50 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 21.06.2014 um 20:05:27 unerwartet heruntergefahren. Error: (06/15/2014 00:02:54 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 13.06.2014 um 03:01:27 unerwartet heruntergefahren. Error: (06/09/2014 06:46:28 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 09.06.2014 um 18:45:00 unerwartet heruntergefahren. Error: (06/09/2014 04:16:42 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Windows Search2300001Neustart des Diensts Error: (06/09/2014 04:16:42 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Windows Search2147749155 (0x80040D23) Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-02-10 14:23:50.898 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 14:23:50.586 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 14:23:50.305 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 14:23:50.009 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 14:23:49.744 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 12:55:36.857 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 12:55:36.685 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 12:55:36.514 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-02-10 12:55:36.326 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 49% Total physical RAM: 3198.33 MB Available physical RAM: 1628.98 MB Total Pagefile: 6614.56 MB Available Pagefile: 5358.91 MB Total Virtual: 2047.88 MB Available Virtual: 1898 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.76 GB) (Free:160.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 6116F80A) Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:47 on 18/07/2014 (Lisa) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. HKCU:DAEMON Tools Lite -> Removed Checking for services/drivers... -=E.O.F=- |
19.07.2014, 20:22 | #4 |
/// the machine /// TB-Ausbilder | Windows Vista Spam-Email Anhang geöffnet hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.07.2014, 10:54 | #5 |
| Windows Vista Spam-Email Anhang geöffnet Hallo Schrauber! Combofix lief soweit ohne Probleme oder gemecker durch. Hier das Logfile von Combofix: Code:
ATTFilter ComboFix 14-07-19.01 - Lisa 20.07.2014 11:31:38.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3198.2289 [GMT 2:00] ausgeführt von:: c:\users\Lisa\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\YingInstall c:\windows\system32\YingInstall\409.ini . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-20 bis 2014-07-20 )))))))))))))))))))))))))))))) . . 2014-07-20 09:43 . 2014-07-20 09:44 -------- d-----w- c:\users\Lisa\AppData\Local\temp 2014-07-20 09:43 . 2014-07-20 09:43 -------- d-----w- c:\users\Mcx1\AppData\Local\temp 2014-07-20 09:43 . 2014-07-20 09:43 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-07-18 14:48 . 2014-07-18 14:51 -------- d-----w- C:\FRST 2014-07-18 11:47 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CA494E7B-B7E6-44FF-A2E2-475852CC6A8C}\mpengine.dll 2014-06-21 11:10 . 2014-06-21 11:10 -------- d-----w- c:\users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 11:10 . 2014-06-21 11:10 -------- d-----w- c:\users\Lisa\AppData\Local\cache 2014-06-21 11:07 . 2014-06-21 11:07 -------- d-----w- c:\program files\MusicBrainz Picard . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-09 18:22 . 2013-04-02 16:00 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-07-09 18:22 . 2013-04-02 16:00 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-04-26 16:01 . 2014-06-12 13:06 502784 ----a-w- c:\windows\system32\usp10.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Lisa\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Lisa\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-10 23:54 131248 ----a-w- c:\users\Lisa\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-14 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-14 8429568] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-14 81920] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-25 4444160] "Skytel"="Skytel.exe" [2007-04-13 1822720] "ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2007-01-16 106496] "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2009-10-26 1458176] "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-12-10 472984] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-10-28 49208] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "HControlUser"="c:\program files\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . c:\users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-5-20 33322312] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HPService REG_MULTI_SZ HPSLPSVC . Inhalt des "geplante Tasks" Ordners . 2014-07-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-02 18:22] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700 mStart Page = hxxp://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST500LM012XHN-M500MBB_S2RYJ9BCC03409&ts=1393424700 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\gdlpm4ty.default-1393772530668\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-AdobeBridge - (no file) HKLM-Run-DivXMediaServer - c:\program files\DivX\DivX Media Server\DivXMediaServer.exe SafeBoot-WudfPf SafeBoot-WudfRd . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2014-07-20 11:44 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . Zeit der Fertigstellung: 2014-07-20 11:47:15 ComboFix-quarantined-files.txt 2014-07-20 09:47 . Vor Suchlauf: 7 Verzeichnis(se), 202.634.133.504 Bytes frei Nach Suchlauf: 12 Verzeichnis(se), 204.695.814.144 Bytes frei . - - End Of File - - 3F90E2C22F2EEA7A8035566CB8701843 5C616939100B85E558DA92B899A0FC36 |
20.07.2014, 17:31 | #6 |
/// the machine /// TB-Ausbilder | Windows Vista Spam-Email Anhang geöffnet Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Windows Vista Spam-Email Anhang geöffnet |
20.07.2014, 19:24 | #7 |
| Windows Vista Spam-Email Anhang geöffnet so erledigt mbam-log: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 20.07.2014 Suchlauf-Zeit: 19:26:15 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.20.04 Rootkit Datenbank: v2014.07.17.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x86 Dateisystem: NTFS Benutzer: Lisa Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 297657 Verstrichene Zeit: 11 Min, 13 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.216 - Bericht erstellt am 20/07/2014 um 19:41:49 # Aktualisiert 17/07/2014 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzername : Lisa - LISALAPTOP # Gestartet von : C:\Users\Lisa\Downloads\adwcleaner_3.216.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : Wpm ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\eSafe Ordner Gelöscht : C:\ProgramData\IePluginService Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\Program Files\SupTab Ordner Gelöscht : C:\Program Files\WinZipper Ordner Gelöscht : C:\Users\Lisa\AppData\Roaming\digitalsite Ordner Gelöscht : C:\Users\Lisa\AppData\Roaming\pdfforge Ordner Gelöscht : C:\Users\Lisa\AppData\Roaming\SupTab Datei Gelöscht : C:\Windows\System32\Tasks\DigitalSite ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk ***** [ Registrierungsdatenbank ] ***** [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{50961489-E600-4CCE-B5D1-9077B61FE4FC} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50961489-E600-4CCE-B5D1-9077B61FE4FC} Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}] Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKLM\Software\delta-homesSoftware Schlüssel Gelöscht : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar Schlüssel Gelöscht : HKLM\Software\hdcode Schlüssel Gelöscht : HKLM\Software\SupTab Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\V9 Schlüssel Gelöscht : HKLM\Software\winzipersvc Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wpm Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WsysControl ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16561 -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\gdlpm4ty.default-1393772530668\prefs.js ] ************************* AdwCleaner[R0].txt - [3356 octets] - [20/07/2014 19:40:06] AdwCleaner[S0].txt - [2953 octets] - [20/07/2014 19:41:49] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3013 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows Vista (TM) Home Premium x86 Ran by Lisa on 20.07.2014 at 19:47:22,61 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Lisa\AppData\Roaming\mozilla\firefox\profiles\gdlpm4ty.default-1393772530668\minidumps [13 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.07.2014 at 19:52:54,71 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01 Ran by Lisa (administrator) on LISALAPTOP on 20-07-2014 20:08:47 Running from C:\Users\Lisa\Downloads Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files\Wireless Console 2\wcourier.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe (pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe (pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Dropbox, Inc.) C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [NvSvc] => C:\Windows\system32\nvsvc.dll [86016 2007-05-14] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] => C:\Windows\system32\NvCpl.dll [8429568 2007-05-14] (NVIDIA Corporation) HKLM\...\Run: [NvMediaCenter] => C:\Windows\system32\NvMcTray.dll [81920 2007-05-14] (NVIDIA Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-03-01] (Synaptics, Inc.) HKLM\...\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4444160 2007-04-25] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Windows\Skytel.exe [1822720 2007-04-13] (Realtek Semiconductor Corp.) HKLM\...\Run: [ASUSTPE] => C:\Windows\system32\ASUSTPE.exe [106496 2007-01-16] (ASUS) HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1458176 2009-10-26] (Motorola Inc.) HKLM\...\Run: [ATKMEDIA] => C:\Program Files\ASUS\ATK Media\DMEDIA.EXE [61440 2006-11-02] (ASUSTeK Computer INC.) HKLM\...\Run: [avast] => C:\Program Files\AVAST Software\Avast\avastUI.exe [4297136 2012-10-31] (AVAST Software) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated) HKLM\...\Run: [SwitchBoard] => C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeCS6ServiceManager] => C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [HControlUser] => C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\gdlpm4ty.default-1393772530668 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-02-09] FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-02-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-10] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-05-26] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ========================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-10-31] (AVAST Software) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [21256 2012-10-31] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-10-31] (AVAST Software) R1 AswRdr; C:\Windows\system32\Drivers\AswRdr.sys [35928 2012-10-31] (AVAST Software) R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [738504 2012-10-31] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [361032 2012-10-31] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [54232 2012-10-31] (AVAST Software) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-04-02] (DT Soft Ltd) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-20] (Malwarebytes Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 SiBulk; C:\Windows\System32\drivers\SiBulk.sys [16768 2008-02-08] () [File not signed] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Lisa\AppData\Local\Temp\catchme.sys [X] S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-20 20:08 - 2014-07-20 20:08 - 00012476 _____ () C:\Users\Lisa\Downloads\FRST.txt 2014-07-20 19:52 - 2014-07-20 19:52 - 00000778 _____ () C:\Users\Lisa\Desktop\JRT.txt 2014-07-20 19:47 - 2014-07-20 19:47 - 00000000 ____D () C:\Windows\ERUNT 2014-07-20 19:44 - 2014-07-20 19:44 - 00003093 _____ () C:\Users\Lisa\Desktop\AdwCleaner[S0].txt 2014-07-20 19:39 - 2014-07-20 19:41 - 00000000 ____D () C:\AdwCleaner 2014-07-20 19:38 - 2014-07-20 19:38 - 00001162 _____ () C:\Users\Lisa\Desktop\mbam.txt 2014-07-20 19:25 - 2014-07-20 19:25 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-20 19:25 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-20 19:25 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-20 19:25 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-20 19:23 - 2014-07-20 19:23 - 01354223 _____ () C:\Users\Lisa\Downloads\adwcleaner_3.216.exe 2014-07-20 19:23 - 2014-07-20 19:23 - 01016261 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT.exe 2014-07-20 19:22 - 2014-07-20 19:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 11:47 - 2014-07-20 11:47 - 00009420 _____ () C:\ComboFix.txt 2014-07-20 11:27 - 2014-07-20 11:47 - 00000000 ____D () C:\ComboFix 2014-07-20 11:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-20 11:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-20 11:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-20 11:26 - 2014-07-20 11:47 - 00000000 ____D () C:\Qoobox 2014-07-20 11:14 - 2014-07-20 11:45 - 00000000 ____D () C:\Windows\erdnt 2014-07-18 17:49 - 2014-07-18 17:49 - 00143552 _____ () C:\Windows\Minidump\Mini071814-05.dmp 2014-07-18 17:26 - 2014-07-18 17:27 - 00143552 _____ () C:\Windows\Minidump\Mini071814-04.dmp 2014-07-18 17:17 - 2014-07-18 17:17 - 00139336 _____ () C:\Windows\Minidump\Mini071814-03.dmp 2014-07-18 17:13 - 2014-07-18 17:13 - 00143552 _____ () C:\Windows\Minidump\Mini071814-02.dmp 2014-07-18 17:01 - 2014-07-18 17:01 - 00143552 _____ () C:\Windows\Minidump\Mini071814-01.dmp 2014-07-18 16:48 - 2014-07-20 20:08 - 00000000 ____D () C:\FRST 2014-07-18 16:47 - 2014-07-18 16:47 - 00000156 _____ () C:\Users\Lisa\defogger_reenable 2014-07-18 16:45 - 2014-07-18 16:45 - 00380416 _____ () C:\Users\Lisa\Downloads\Gmer-19357.exe 2014-07-18 16:44 - 2014-07-18 16:44 - 01077248 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe 2014-07-18 16:43 - 2014-07-18 16:43 - 00050477 _____ () C:\Users\Lisa\Downloads\Defogger.exe 2014-07-15 15:40 - 2014-07-15 15:40 - 00131546 _____ () C:\Users\Lisa\Documents\Lisa Pohl Forderung stornierten Zahlung Ihrer Bestellung Ebay vom 15.07.2014.zip 2014-07-10 12:40 - 2014-06-07 02:19 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-10 12:40 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-10 12:40 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-10 12:40 - 2014-05-30 08:53 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-10 12:39 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-10 12:39 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-10 12:39 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-10 12:39 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-10 12:39 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-10 12:39 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-10 12:39 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-10 12:39 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-10 12:39 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-10 12:39 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-10 12:39 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-10 12:39 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-10 12:39 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-21 20:06 - 2014-06-21 20:06 - 00143552 _____ () C:\Windows\Minidump\Mini062114-01.dmp 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Local\cache 2014-06-21 13:07 - 2014-06-21 13:07 - 08790287 _____ (MusicBrainz) C:\Users\Lisa\Downloads\picard-setup-1.2.exe 2014-06-21 13:07 - 2014-06-21 13:07 - 00000000 ____D () C:\Program Files\MusicBrainz Picard ==================== One Month Modified Files and Folders ======= 2014-07-20 20:09 - 2014-07-20 20:08 - 00012476 _____ () C:\Users\Lisa\Downloads\FRST.txt 2014-07-20 20:08 - 2014-07-18 16:48 - 00000000 ____D () C:\FRST 2014-07-20 19:52 - 2014-07-20 19:52 - 00000778 _____ () C:\Users\Lisa\Desktop\JRT.txt 2014-07-20 19:48 - 2008-01-21 03:35 - 02047180 _____ () C:\Windows\WindowsUpdate.log 2014-07-20 19:47 - 2014-07-20 19:47 - 00000000 ____D () C:\Windows\ERUNT 2014-07-20 19:47 - 2014-01-04 18:29 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Dropbox 2014-07-20 19:46 - 2014-05-03 11:03 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\DropboxMaster 2014-07-20 19:46 - 2014-01-04 18:34 - 00000000 ___RD () C:\Users\Lisa\Dropbox 2014-07-20 19:45 - 2013-02-09 16:05 - 00027240 _____ () C:\Users\Lisa\AppData\Roaming\nvModes.001 2014-07-20 19:44 - 2014-07-20 19:44 - 00003093 _____ () C:\Users\Lisa\Desktop\AdwCleaner[S0].txt 2014-07-20 19:43 - 2008-01-21 04:47 - 00066536 _____ () C:\Windows\PFRO.log 2014-07-20 19:43 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-20 19:43 - 2006-11-02 14:47 - 00004880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-20 19:43 - 2006-11-02 14:47 - 00004880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-20 19:42 - 2006-11-02 15:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-20 19:41 - 2014-07-20 19:39 - 00000000 ____D () C:\AdwCleaner 2014-07-20 19:41 - 2013-04-03 16:39 - 00000973 _____ () C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-20 19:38 - 2014-07-20 19:38 - 00001162 _____ () C:\Users\Lisa\Desktop\mbam.txt 2014-07-20 19:25 - 2014-07-20 19:25 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-20 19:23 - 2014-07-20 19:23 - 01354223 _____ () C:\Users\Lisa\Downloads\adwcleaner_3.216.exe 2014-07-20 19:23 - 2014-07-20 19:23 - 01016261 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT.exe 2014-07-20 19:22 - 2014-07-20 19:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 19:22 - 2014-02-23 18:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-20 11:47 - 2014-07-20 11:47 - 00009420 _____ () C:\ComboFix.txt 2014-07-20 11:47 - 2014-07-20 11:27 - 00000000 ____D () C:\ComboFix 2014-07-20 11:47 - 2014-07-20 11:26 - 00000000 ____D () C:\Qoobox 2014-07-20 11:47 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-07-20 11:47 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-07-20 11:45 - 2014-07-20 11:14 - 00000000 ____D () C:\Windows\erdnt 2014-07-20 11:44 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-07-20 11:19 - 2013-02-09 16:55 - 00000000 ____D () C:\ProgramData\HP 2014-07-20 02:01 - 2013-02-10 12:27 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Adobe 2014-07-18 17:49 - 2014-07-18 17:49 - 00143552 _____ () C:\Windows\Minidump\Mini071814-05.dmp 2014-07-18 17:49 - 2013-02-10 13:53 - 00000000 ____D () C:\Windows\Minidump 2014-07-18 17:49 - 2013-02-10 13:52 - 250977591 _____ () C:\Windows\MEMORY.DMP 2014-07-18 17:27 - 2014-07-18 17:26 - 00143552 _____ () C:\Windows\Minidump\Mini071814-04.dmp 2014-07-18 17:27 - 2013-02-09 15:51 - 00027240 _____ () C:\Users\Lisa\AppData\Roaming\nvModes.dat 2014-07-18 17:17 - 2014-07-18 17:17 - 00139336 _____ () C:\Windows\Minidump\Mini071814-03.dmp 2014-07-18 17:13 - 2014-07-18 17:13 - 00143552 _____ () C:\Windows\Minidump\Mini071814-02.dmp 2014-07-18 17:01 - 2014-07-18 17:01 - 00143552 _____ () C:\Windows\Minidump\Mini071814-01.dmp 2014-07-18 16:47 - 2014-07-18 16:47 - 00000156 _____ () C:\Users\Lisa\defogger_reenable 2014-07-18 16:47 - 2013-02-09 15:25 - 00000000 ____D () C:\Users\Lisa 2014-07-18 16:45 - 2014-07-18 16:45 - 00380416 _____ () C:\Users\Lisa\Downloads\Gmer-19357.exe 2014-07-18 16:44 - 2014-07-18 16:44 - 01077248 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe 2014-07-18 16:43 - 2014-07-18 16:43 - 00050477 _____ () C:\Users\Lisa\Downloads\Defogger.exe 2014-07-15 15:40 - 2014-07-15 15:40 - 00131546 _____ () C:\Users\Lisa\Documents\Lisa xxx Forderung stornierten Zahlung Ihrer Bestellung Ebay vom 15.07.2014.zip 2014-07-12 21:13 - 2014-01-29 16:27 - 00000000 ____D () C:\Users\Lisa\Desktop\baby 2014-07-12 03:19 - 2006-11-02 14:47 - 03699568 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-12 03:15 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 20:22 - 2013-04-02 18:00 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-09 20:22 - 2013-04-02 18:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 16:41 - 2008-01-21 09:16 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-06 16:40 - 2006-11-02 14:52 - 00105490 _____ () C:\Windows\setupact.log 2014-07-05 06:08 - 2013-02-09 15:25 - 00000680 _____ () C:\Users\Lisa\AppData\Local\d3d9caps.dat 2014-06-21 20:06 - 2014-06-21 20:06 - 00143552 _____ () C:\Windows\Minidump\Mini062114-01.dmp 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Local\cache 2014-06-21 13:07 - 2014-06-21 13:07 - 08790287 _____ (MusicBrainz) C:\Users\Lisa\Downloads\picard-setup-1.2.exe 2014-06-21 13:07 - 2014-06-21 13:07 - 00000000 ____D () C:\Program Files\MusicBrainz Picard Some content of TEMP: ==================== C:\Users\Lisa\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_naimd.dll C:\Users\Lisa\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-20 19:50 ==================== End Of Log ============================ --- --- --- |
21.07.2014, 10:50 | #8 |
/// the machine /// TB-Ausbilder | Windows Vista Spam-Email Anhang geöffnetESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.07.2014, 21:19 | #9 |
| Windows Vista Spam-Email Anhang geöffnet Alles soweit durchgeführt. Zuerst das ESET-Log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=aadcd33097b2c144aa0016d3d0aa894d # engine=19277 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-07-21 07:38:04 # local_time=2014-07-21 09:38:04 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=774 16777213 100 91 45551933 182681356 0 0 # compatibility_mode_1='' # compatibility_mode=5892 16776574 100 100 123327 243504212 0 0 # scanned=171642 # found=1 # cleaned=0 # scan_time=11360 sh=464FD963183897BB987030A2097E759ED613A79C ft=1 fh=d1e1cc77b7d23939 vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupTab.dll.vir" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 55 Java version out of Date! Adobe Flash Player 14.0.0.145 Adobe Reader 10.1.10 Adobe Reader out of Date! Mozilla Firefox (30.0) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:21-07-2014 Ran by Lisa (administrator) on LISALAPTOP on 21-07-2014 21:43:32 Running from C:\Users\Lisa\Downloads Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe () C:\Program Files\Wireless Console 2\wcourier.exe () C:\Program Files\ATKOSD2\ATKOSD2.exe (pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe (ATK0100) C:\Program Files\ATK Hotkey\HControl.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe () C:\Program Files\ATK Hotkey\ATKOSD.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (ASUS) C:\Windows\System32\ASUSTPE.exe (Motorola Inc.) C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe (ASUSTeK Computer INC.) C:\Program Files\ASUS\ATK Media\DMedia.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (ASUS) C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Dropbox, Inc.) C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKU\S-1-5-21-1115070674-1653824452-2928014628-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Lisa\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com SearchScopes: HKLM - DefaultScope value is missing. BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! WebRep -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Lisa\AppData\Roaming\Mozilla\Firefox\Profiles\gdlpm4ty.default-1393772530668 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! WebRep - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-02-09] FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-02-09] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-10] FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-05-26] FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ========================== Services (Whitelisted) ================= R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808 2012-10-31] (AVAST Software) R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed] R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed] R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed] S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [21256 2012-10-31] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-10-31] (AVAST Software) R1 AswRdr; C:\Windows\system32\Drivers\AswRdr.sys [35928 2012-10-31] (AVAST Software) R1 aswSnx; C:\Windows\system32\Drivers\aswSnx.sys [738504 2012-10-31] (AVAST Software) R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [361032 2012-10-31] (AVAST Software) R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [54232 2012-10-31] (AVAST Software) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-04-02] (DT Soft Ltd) R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100) S3 SiBulk; C:\Windows\System32\drivers\SiBulk.sys [16768 2008-02-08] () [File not signed] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Lisa\AppData\Local\Temp\catchme.sys [X] S3 EverestDriver; \??\C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-21 21:43 - 2014-07-21 21:43 - 00010378 _____ () C:\Users\Lisa\Downloads\FRST.txt 2014-07-21 21:43 - 2014-07-21 21:43 - 00000000 ____D () C:\Users\Lisa\Downloads\FRST-OlderVersion 2014-07-21 21:42 - 2014-07-21 21:42 - 00000124 _____ () C:\Users\Lisa\Desktop\ESET.txt 2014-07-21 18:24 - 2014-07-21 18:24 - 00000000 ____D () C:\Program Files\ESET 2014-07-21 18:23 - 2014-07-21 18:23 - 02347384 _____ (ESET) C:\Users\Lisa\Downloads\esetsmartinstaller_deu.exe 2014-07-20 19:47 - 2014-07-20 19:47 - 00000000 ____D () C:\Windows\ERUNT 2014-07-20 19:39 - 2014-07-20 19:41 - 00000000 ____D () C:\AdwCleaner 2014-07-20 19:25 - 2014-07-20 20:24 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-20 19:25 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-20 19:25 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-20 19:25 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-20 19:23 - 2014-07-20 19:23 - 01354223 _____ () C:\Users\Lisa\Downloads\adwcleaner_3.216.exe 2014-07-20 19:23 - 2014-07-20 19:23 - 01016261 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT.exe 2014-07-20 19:22 - 2014-07-20 19:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 11:47 - 2014-07-20 11:47 - 00009420 _____ () C:\ComboFix.txt 2014-07-20 11:27 - 2014-07-20 11:47 - 00000000 ____D () C:\ComboFix 2014-07-20 11:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-20 11:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-20 11:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-20 11:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-20 11:26 - 2014-07-20 11:47 - 00000000 ____D () C:\Qoobox 2014-07-20 11:14 - 2014-07-20 11:45 - 00000000 ____D () C:\Windows\erdnt 2014-07-18 17:49 - 2014-07-18 17:49 - 00143552 _____ () C:\Windows\Minidump\Mini071814-05.dmp 2014-07-18 17:26 - 2014-07-18 17:27 - 00143552 _____ () C:\Windows\Minidump\Mini071814-04.dmp 2014-07-18 17:17 - 2014-07-18 17:17 - 00139336 _____ () C:\Windows\Minidump\Mini071814-03.dmp 2014-07-18 17:13 - 2014-07-18 17:13 - 00143552 _____ () C:\Windows\Minidump\Mini071814-02.dmp 2014-07-18 17:01 - 2014-07-18 17:01 - 00143552 _____ () C:\Windows\Minidump\Mini071814-01.dmp 2014-07-18 16:48 - 2014-07-21 21:43 - 00000000 ____D () C:\FRST 2014-07-18 16:47 - 2014-07-18 16:47 - 00000156 _____ () C:\Users\Lisa\defogger_reenable 2014-07-18 16:45 - 2014-07-18 16:45 - 00380416 _____ () C:\Users\Lisa\Downloads\Gmer-19357.exe 2014-07-18 16:44 - 2014-07-21 21:43 - 01080320 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe 2014-07-18 16:43 - 2014-07-18 16:43 - 00050477 _____ () C:\Users\Lisa\Downloads\Defogger.exe 2014-07-10 12:40 - 2014-06-07 02:19 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-10 12:40 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-10 12:40 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-10 12:40 - 2014-05-30 08:53 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-10 12:39 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-10 12:39 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-10 12:39 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-10 12:39 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-10 12:39 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-10 12:39 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-10 12:39 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-10 12:39 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-10 12:39 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-10 12:39 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-10 12:39 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-10 12:39 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-10 12:39 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-10 12:39 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-10 12:39 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-21 20:06 - 2014-06-21 20:06 - 00143552 _____ () C:\Windows\Minidump\Mini062114-01.dmp 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Local\cache 2014-06-21 13:07 - 2014-06-21 13:07 - 08790287 _____ (MusicBrainz) C:\Users\Lisa\Downloads\picard-setup-1.2.exe 2014-06-21 13:07 - 2014-06-21 13:07 - 00000000 ____D () C:\Program Files\MusicBrainz Picard ==================== One Month Modified Files and Folders ======= 2014-07-21 21:44 - 2014-07-21 21:43 - 00010378 _____ () C:\Users\Lisa\Downloads\FRST.txt 2014-07-21 21:43 - 2014-07-21 21:43 - 00000000 ____D () C:\Users\Lisa\Downloads\FRST-OlderVersion 2014-07-21 21:43 - 2014-07-18 16:48 - 00000000 ____D () C:\FRST 2014-07-21 21:43 - 2014-07-18 16:44 - 01080320 _____ (Farbar) C:\Users\Lisa\Downloads\FRST.exe 2014-07-21 21:42 - 2014-07-21 21:42 - 00000124 _____ () C:\Users\Lisa\Desktop\ESET.txt 2014-07-21 21:22 - 2014-02-23 18:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-21 19:57 - 2006-11-02 14:47 - 00004880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-21 19:57 - 2006-11-02 14:47 - 00004880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-21 18:24 - 2014-07-21 18:24 - 00000000 ____D () C:\Program Files\ESET 2014-07-21 18:23 - 2014-07-21 18:23 - 02347384 _____ (ESET) C:\Users\Lisa\Downloads\esetsmartinstaller_deu.exe 2014-07-21 18:11 - 2008-01-21 03:35 - 02066606 _____ () C:\Windows\WindowsUpdate.log 2014-07-21 14:54 - 2014-01-04 18:29 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\Dropbox 2014-07-21 12:00 - 2014-05-03 11:03 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\DropboxMaster 2014-07-21 12:00 - 2014-01-04 18:34 - 00000000 ___RD () C:\Users\Lisa\Dropbox 2014-07-21 11:58 - 2013-02-09 16:05 - 00027240 _____ () C:\Users\Lisa\AppData\Roaming\nvModes.001 2014-07-21 11:57 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-20 22:49 - 2006-11-02 15:01 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-20 20:24 - 2014-07-20 19:25 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-20 19:47 - 2014-07-20 19:47 - 00000000 ____D () C:\Windows\ERUNT 2014-07-20 19:43 - 2008-01-21 04:47 - 00066536 _____ () C:\Windows\PFRO.log 2014-07-20 19:41 - 2014-07-20 19:39 - 00000000 ____D () C:\AdwCleaner 2014-07-20 19:41 - 2013-04-03 16:39 - 00000973 _____ () C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-20 19:25 - 2014-07-20 19:25 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-07-20 19:23 - 2014-07-20 19:23 - 01354223 _____ () C:\Users\Lisa\Downloads\adwcleaner_3.216.exe 2014-07-20 19:23 - 2014-07-20 19:23 - 01016261 _____ (Thisisu) C:\Users\Lisa\Downloads\JRT.exe 2014-07-20 19:22 - 2014-07-20 19:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lisa\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-20 11:47 - 2014-07-20 11:47 - 00009420 _____ () C:\ComboFix.txt 2014-07-20 11:47 - 2014-07-20 11:27 - 00000000 ____D () C:\ComboFix 2014-07-20 11:47 - 2014-07-20 11:26 - 00000000 ____D () C:\Qoobox 2014-07-20 11:47 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default 2014-07-20 11:47 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public 2014-07-20 11:45 - 2014-07-20 11:14 - 00000000 ____D () C:\Windows\erdnt 2014-07-20 11:44 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini 2014-07-20 11:19 - 2013-02-09 16:55 - 00000000 ____D () C:\ProgramData\HP 2014-07-20 02:01 - 2013-02-10 12:27 - 00000000 ____D () C:\Users\Lisa\AppData\Local\Adobe 2014-07-18 17:49 - 2014-07-18 17:49 - 00143552 _____ () C:\Windows\Minidump\Mini071814-05.dmp 2014-07-18 17:49 - 2013-02-10 13:53 - 00000000 ____D () C:\Windows\Minidump 2014-07-18 17:49 - 2013-02-10 13:52 - 250977591 _____ () C:\Windows\MEMORY.DMP 2014-07-18 17:27 - 2014-07-18 17:26 - 00143552 _____ () C:\Windows\Minidump\Mini071814-04.dmp 2014-07-18 17:27 - 2013-02-09 15:51 - 00027240 _____ () C:\Users\Lisa\AppData\Roaming\nvModes.dat 2014-07-18 17:17 - 2014-07-18 17:17 - 00139336 _____ () C:\Windows\Minidump\Mini071814-03.dmp 2014-07-18 17:13 - 2014-07-18 17:13 - 00143552 _____ () C:\Windows\Minidump\Mini071814-02.dmp 2014-07-18 17:01 - 2014-07-18 17:01 - 00143552 _____ () C:\Windows\Minidump\Mini071814-01.dmp 2014-07-18 16:47 - 2014-07-18 16:47 - 00000156 _____ () C:\Users\Lisa\defogger_reenable 2014-07-18 16:47 - 2013-02-09 15:25 - 00000000 ____D () C:\Users\Lisa 2014-07-18 16:45 - 2014-07-18 16:45 - 00380416 _____ () C:\Users\Lisa\Downloads\Gmer-19357.exe 2014-07-18 16:43 - 2014-07-18 16:43 - 00050477 _____ () C:\Users\Lisa\Downloads\Defogger.exe 2014-07-12 21:13 - 2014-01-29 16:27 - 00000000 ____D () C:\Users\Lisa\Desktop\baby 2014-07-12 03:19 - 2006-11-02 14:47 - 03699568 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-12 03:15 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 20:22 - 2013-04-02 18:00 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-07-09 20:22 - 2013-04-02 18:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-07-06 16:41 - 2008-01-21 09:16 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-06 16:40 - 2006-11-02 14:52 - 00105490 _____ () C:\Windows\setupact.log 2014-07-05 06:08 - 2013-02-09 15:25 - 00000680 _____ () C:\Users\Lisa\AppData\Local\d3d9caps.dat 2014-06-21 20:06 - 2014-06-21 20:06 - 00143552 _____ () C:\Windows\Minidump\Mini062114-01.dmp 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Roaming\MusicBrainz 2014-06-21 13:10 - 2014-06-21 13:10 - 00000000 ____D () C:\Users\Lisa\AppData\Local\cache 2014-06-21 13:07 - 2014-06-21 13:07 - 08790287 _____ (MusicBrainz) C:\Users\Lisa\Downloads\picard-setup-1.2.exe 2014-06-21 13:07 - 2014-06-21 13:07 - 00000000 ____D () C:\Program Files\MusicBrainz Picard Some content of TEMP: ==================== C:\Users\Lisa\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcmhpjx.dll C:\Users\Lisa\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-21 12:04 ==================== End Of Log ============================ --- --- --- |
22.07.2014, 11:15 | #10 |
/// the machine /// TB-Ausbilder | Windows Vista Spam-Email Anhang geöffnet Java und Adobe udpaten. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2014, 20:29 | #11 |
| Windows Vista Spam-Email Anhang geöffnet Hallo Schrauber! vielen vielen Dank, für die rasche, unkomplizierte und vor allem kompetente Hilfe! von meiner Seite aus sind keine Fragen mehr offen. Werde deine Tipps so weit wie möglich umsetzten und beherzigen! Nochmal vielen Dank! |
23.07.2014, 11:23 | #12 |
/// the machine /// TB-Ausbilder | Windows Vista Spam-Email Anhang geöffnet Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows Vista Spam-Email Anhang geöffnet |
anhang, anhang geöffnet, anleitung, befolgt, benötigte, email, entstanden, eurem, folge, folgendes, forum, gefahrlos, laptop, leitung, lieben, log-files, nicht sicher, problem, sicherheitslücke, spam, spam email, troja, vista, windows, windows vista |