|
Plagegeister aller Art und deren Bekämpfung: Svhost.exe /Backdoor.Agent + PUP.BitCoinMinerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.09.2014, 09:48 | #31 |
| Svhost.exe /Backdoor.Agent + PUP.BitCoinMinerFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-09-2014 Ran by Shu (administrator) on SHU-PC on 25-09-2014 10:47:13 Running from C:\Users\Shu\Downloads Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe () C:\Windows\System32\PnkBstrA.exe (AMD) C:\Windows\System32\atieclxx.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Akamai Technologies, Inc.) C:\Users\Shu\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) C:\Users\Shu\AppData\Local\Akamai\netsession_win.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-06] (AVAST Software) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-07-09] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-2066591825-490448642-3097545973-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Shu\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.) Startup: C:\Users\Shu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Shu\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEF34FECC14C1CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices) BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: EpTec -> {D4F5F5EC-499D-48F5-AFD1-B25723A6E43E} -> C:\Users\Shu\AppData\Roaming\WinRAR\eptec.dll (Space International, Inc.) Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Handler: cup - {A0BE0236-AB5A-45DC-A304-2269CE96708E} - No File Handler: dup - {A0BE0236-AB5A-45DC-A304-2269CE96708E} - No File Handler-x32: cup - {A0BE0236-AB5A-45DC-A304-2269CE96708E} - No File Handler-x32: dup - {A0BE0236-AB5A-45DC-A304-2269CE96708E} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Shu\AppData\Roaming\Mozilla\Firefox\Profiles\vz98gkax.default FF SelectedSearchEngine: WEB.DE Suche FF Homepage: https://www.google.de/ FF NetworkProxy: "autoconfig_url", "file:///C:\\Users\\Shu\\AppData\\Local\\Temp\\proxtube.pac" FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll () FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB) FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.) FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll No File FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB) FF Plugin-x32: @ngm.nexoneu.com/NxGame -> C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon) FF Plugin-x32: @ogplanet.com/npOGPPlugin -> C:\Windows\system32\npOGPPlugin.dll No File FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Shu\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: German Dictionary - C:\Users\Shu\AppData\Roaming\Mozilla\Firefox\Profiles\vz98gkax.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2014-06-08] FF Extension: Разпознаване на устройство Logitech - C:\Users\Shu\AppData\Roaming\Mozilla\Firefox\Profiles\vz98gkax.default\Extensions\DeviceDetection@logitech.com [2013-10-04] FF Extension: Classic Theme Restorer - C:\Users\Shu\AppData\Roaming\Mozilla\Firefox\Profiles\vz98gkax.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-05-03] FF Extension: MEGA - C:\Users\Shu\AppData\Roaming\Mozilla\Firefox\Profiles\vz98gkax.default\Extensions\firefox@mega.co.nz.xpi [2014-01-09] FF Extension: Adblock Plus - C:\Users\Shu\AppData\Roaming\Mozilla\Firefox\Profiles\vz98gkax.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-04] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-10-04] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-06] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-09] (Advanced Micro Devices, Inc.) [File not signed] S2 AODService; C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [137584 2014-01-08] () S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2014-08-12] (Perfect World Entertainment Inc) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-06] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-08] () [File not signed] S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-08-09] (BitRaider, LLC) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5128944 2013-11-19] (INCA Internet Co., Ltd.) [File not signed] R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-08-04] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-13] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 1394hub; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices) R2 AODDriver4.3.0; C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [59624 2014-01-08] (Advanced Micro Devices) S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-06] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-06] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-06] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-06] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-06] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-06] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-06] () R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-13] (Disc Soft Ltd) S3 gouranga; C:\Windows\System32\DRIVERS\gouranga.sys [16384 2014-08-04] (GSPOON CO., LTD.) R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv.sys [42016 2013-11-27] (Visicom Media Inc.) S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [35232 2013-12-06] (Visicom Media Inc.) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0081.sys [28768 2014-01-23] (SoftEther VPN Project at University of Tsukuba, Japan.) S3 SEE; C:\Windows\System32\drivers\see.sys [38240 2014-06-03] (SoftEther VPN Project at University of Tsukuba, Japan.) S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed] S3 Synth3dVsc; No ImagePath R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) S3 tsusbhub; No ImagePath S3 VGPU; No ImagePath S3 VIAHdAudAddService; No ImagePath S3 X6va015; No ImagePath S3 X6va016; No ImagePath S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 hxsyol; \??\C:\AeriaGames\AuraKingdom\avital\hxsy64.sys [X] S3 X6va021; \??\C:\Windows\SysWOW64\Drivers\X6va021 [X] S3 xhunter1; \??\C:\Windows\xhunter1.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-25 10:47 - 2014-09-25 10:47 - 00000000 ____D () C:\Users\Shu\Downloads\FRST-OlderVersion 2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Shu\AppData\Local\Adobe 2014-09-20 21:29 - 2014-09-20 21:29 - 00000242 _____ () C:\Users\Shu\Downloads\Search.txt 2014-09-20 20:30 - 2014-09-20 20:30 - 19829279 _____ () C:\Users\Shu\Downloads\Flareon_A4.rar 2014-09-19 16:52 - 2014-09-19 16:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-18 08:33 - 2014-09-18 08:33 - 00854417 _____ () C:\Users\Shu\Desktop\SecurityCheck.exe 2014-09-18 08:33 - 2014-09-18 08:33 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-18 08:32 - 2014-09-18 08:32 - 02347384 _____ (ESET) C:\Users\Shu\Desktop\esetsmartinstaller_deu.exe 2014-09-17 11:44 - 2014-09-25 10:47 - 00016366 _____ () C:\Users\Shu\Downloads\FRST.txt 2014-09-17 11:43 - 2014-09-17 11:43 - 00001460 _____ () C:\Users\Shu\Desktop\JRT.txt 2014-09-17 11:38 - 2014-09-17 11:38 - 00000000 ____D () C:\Windows\ERUNT 2014-09-17 11:37 - 2014-09-17 11:37 - 00002349 _____ () C:\Users\Shu\Desktop\AdwCleaner[S3].txt 2014-09-17 11:30 - 2014-09-17 11:30 - 00001491 _____ () C:\Users\Shu\Desktop\mbar.txt 2014-09-17 11:01 - 2014-09-17 11:01 - 01373475 _____ () C:\Users\Shu\Desktop\AdwCleaner_3.310.exe 2014-09-17 11:01 - 2014-09-17 11:01 - 01016035 _____ (Thisisu) C:\Users\Shu\Desktop\JRT.exe 2014-09-16 16:11 - 2014-09-16 16:11 - 00029566 _____ () C:\ComboFix.txt 2014-09-16 15:53 - 2014-09-16 15:53 - 00001130 _____ () C:\Users\Shu\Desktop\ComboFix.exe - Verknüpfung.lnk 2014-09-15 20:14 - 2014-09-15 20:15 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Shu\Downloads\tdsskiller.exe 2014-09-15 19:32 - 2014-09-15 19:32 - 00002165 _____ () C:\Users\Shu\Desktop\Dragon Nest Europe.lnk 2014-09-15 18:23 - 2014-09-15 18:23 - 00262144 ____N () C:\Windows\Minidump\091514-23150-01.dmp 2014-09-15 11:27 - 2014-09-15 11:28 - 00018397 _____ () C:\Windows\DirectX.log 2014-09-15 09:43 - 2014-09-25 10:47 - 00000000 ____D () C:\FRST 2014-09-15 09:43 - 2014-09-15 09:51 - 00038153 _____ () C:\Users\Shu\Desktop\FRST.txt 2014-09-15 09:43 - 2014-09-15 09:44 - 00053678 _____ () C:\Users\Shu\Desktop\Addition.txt 2014-09-15 09:42 - 2014-09-15 09:42 - 01102777 _____ () C:\Users\Shu\Desktop\Scan Results.140915-0942.txt 2014-09-15 09:41 - 2014-09-25 10:47 - 02106880 _____ (Farbar) C:\Users\Shu\Downloads\FRST64.exe 2014-09-15 09:29 - 2014-09-15 09:30 - 00000000 ____D () C:\Users\Shu\Downloads\SGN SW Torrent 2014-09-15 08:53 - 2014-09-15 08:53 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-09-15 08:53 - 2014-09-15 08:53 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-09-15 08:53 - 2014-09-15 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-09-15 08:53 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2014-09-15 08:52 - 2014-09-15 08:52 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Shu\Downloads\spybot-2.4.exe 2014-09-14 22:25 - 2014-09-14 22:25 - 00000085 _____ () C:\Windows\wininit.ini 2014-09-14 22:25 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-09-14 22:25 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-09-14 22:25 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-09-14 22:25 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-09-14 22:25 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-09-14 22:25 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-09-14 22:25 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-09-14 22:25 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-09-14 22:20 - 2014-09-14 22:20 - 00000000 ____D () C:\Users\Shu\Documents\ProcAlyzer Dumps 2014-09-14 22:12 - 2014-09-16 16:11 - 00000000 ____D () C:\Qoobox 2014-09-14 22:12 - 2014-09-14 22:35 - 00000000 ____D () C:\Windows\erdnt 2014-09-14 22:07 - 2014-09-16 15:54 - 05579386 ____R (Swearware) C:\Users\Shu\Downloads\ComboFix.exe 2014-09-14 22:00 - 2014-09-25 10:40 - 00007976 _____ () C:\Windows\PFRO.log 2014-09-14 21:45 - 2014-09-14 22:56 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-09-14 21:44 - 2014-09-14 21:44 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Shu\Downloads\mbar-1.07.0.1012.exe 2014-09-14 11:39 - 2014-09-15 18:21 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDGi Europe 2014-09-14 10:40 - 2014-09-14 10:40 - 00692832 _____ ( ) C:\Users\Shu\Downloads\DNDownloader96.exe 2014-09-14 09:04 - 2014-09-25 10:40 - 00002455 _____ () C:\Windows\setupact.log 2014-09-14 09:04 - 2014-09-14 09:04 - 00000000 _____ () C:\Windows\setuperr.log 2014-09-13 12:13 - 2014-09-13 12:13 - 01942203 _____ () C:\Users\Shu\Desktop\vitctorian houses.zip 2014-09-13 10:53 - 2014-09-13 10:53 - 06057862 _____ (Tim Kosse) C:\Users\Shu\Downloads\FileZilla_3.9.0.5_win32-setup.exe 2014-09-12 14:52 - 2014-09-12 14:56 - 00000000 ____D () C:\Users\Shu\Desktop\world 2014-09-10 10:00 - 2014-09-10 13:33 - 00000000 ____D () C:\Users\Shu\Desktop\Minecraft 2014-09-09 12:47 - 2014-09-22 14:45 - 00000000 ____D () C:\Users\Shu\Powersaves3DS 2014-09-09 12:47 - 2014-09-09 12:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Action Replay PowerSaves 3DS 2014-09-09 12:47 - 2014-09-09 12:47 - 00000000 ____D () C:\Program Files (x86)\Action Replay PowerSaves 3DS 2014-09-07 23:19 - 2014-09-07 23:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dawn of War II - Destroyer 40k 2014-09-05 21:02 - 2014-09-05 21:02 - 01402920 _____ () C:\Users\Shu\Downloads\battlelog-web-plugins_2.5.1_149.exe 2014-09-02 10:00 - 2014-09-02 10:06 - 00000000 ____D () C:\Users\Shu\AppData\Local\lab_1_54 2014-09-01 21:30 - 2014-09-01 21:30 - 00003088 _____ () C:\Windows\System32\Tasks\{CA426A73-A1F4-4917-967B-CDAE3FBA6F61} 2014-09-01 11:32 - 2014-09-01 11:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WorldPainter 2014-09-01 11:32 - 2014-09-01 11:33 - 00000000 ____D () C:\Program Files\WorldPainter 2014-08-31 17:06 - 2014-08-31 17:06 - 01397992 _____ () C:\Users\Shu\Downloads\battlelog-web-plugins_2.5.0_148.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-25 10:47 - 2014-09-25 10:47 - 00000000 ____D () C:\Users\Shu\Downloads\FRST-OlderVersion 2014-09-25 10:47 - 2014-09-17 11:44 - 00016366 _____ () C:\Users\Shu\Downloads\FRST.txt 2014-09-25 10:47 - 2014-09-15 09:43 - 00000000 ____D () C:\FRST 2014-09-25 10:47 - 2014-09-15 09:41 - 02106880 _____ (Farbar) C:\Users\Shu\Downloads\FRST64.exe 2014-09-25 10:46 - 2009-07-14 06:45 - 00020672 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-25 10:46 - 2009-07-14 06:45 - 00020672 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-25 10:40 - 2014-09-14 22:00 - 00007976 _____ () C:\Windows\PFRO.log 2014-09-25 10:40 - 2014-09-14 09:04 - 00002455 _____ () C:\Windows\setupact.log 2014-09-25 10:40 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-25 00:02 - 2014-07-04 20:28 - 00000000 ____D () C:\Users\Shu\AppData\Local\Warframe 2014-09-25 00:02 - 2013-10-04 17:53 - 00000000 ____D () C:\ProgramData\Origin 2014-09-25 00:02 - 2013-10-04 17:02 - 01600960 _____ () C:\Windows\WindowsUpdate.log 2014-09-25 00:00 - 2013-10-04 20:47 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-09-24 23:50 - 2013-10-04 18:48 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2014-09-24 23:38 - 2013-10-04 18:48 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0 2014-09-24 23:36 - 2014-06-15 17:46 - 00000000 ____D () C:\Users\Shu\Documents\ArcheAge 2014-09-24 23:28 - 2013-10-04 18:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-09-24 21:05 - 2013-10-04 18:09 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\TS3Client 2014-09-24 19:48 - 2013-10-04 21:28 - 00000000 ____D () C:\Users\Shu\Documents\DragonNest 2014-09-24 17:19 - 2013-10-04 17:53 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-09-24 16:40 - 2014-07-23 18:04 - 00000000 ____D () C:\Users\Shu\AppData\Local\ftblauncher 2014-09-24 16:40 - 2014-02-28 21:04 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\FTB 2014-09-24 15:24 - 2014-03-22 21:48 - 00000000 ____D () C:\Users\Shu\Desktop\Bewerbungskram 2014-09-24 12:28 - 2013-10-04 18:14 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-09-24 12:28 - 2013-10-04 18:14 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-09-24 12:28 - 2013-10-04 18:14 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-09-24 12:25 - 2013-10-04 20:52 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\Skype 2014-09-24 12:08 - 2013-10-04 17:21 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-09-23 11:18 - 2013-11-01 00:27 - 00000000 ____D () C:\Users\Shu\Desktop\PS CS6 Portable By KaelAlexander 2014-09-22 19:36 - 2014-05-04 09:12 - 00000000 ____D () C:\Users\Shu\AppData\Local\Battle.net 2014-09-22 19:35 - 2014-05-04 09:12 - 00000000 ____D () C:\Program Files (x86)\Diablo III 2014-09-22 19:34 - 2014-05-04 09:12 - 00000000 ____D () C:\Program Files (x86)\Battle.net 2014-09-22 14:45 - 2014-09-09 12:47 - 00000000 ____D () C:\Users\Shu\Powersaves3DS 2014-09-21 10:11 - 2014-09-21 10:11 - 00000000 ____D () C:\Users\Shu\AppData\Local\Adobe 2014-09-20 21:29 - 2014-09-20 21:29 - 00000242 _____ () C:\Users\Shu\Downloads\Search.txt 2014-09-20 20:30 - 2014-09-20 20:30 - 19829279 _____ () C:\Users\Shu\Downloads\Flareon_A4.rar 2014-09-20 10:02 - 2009-07-14 19:58 - 01324398 _____ () C:\Windows\system32\perfh007.dat 2014-09-20 10:02 - 2009-07-14 19:58 - 00343506 _____ () C:\Windows\system32\perfc007.dat 2014-09-20 10:02 - 2009-07-14 07:13 - 00006224 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-20 09:24 - 2013-10-04 17:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-09-19 16:52 - 2014-09-19 16:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-09-18 08:33 - 2014-09-18 08:33 - 00854417 _____ () C:\Users\Shu\Desktop\SecurityCheck.exe 2014-09-18 08:33 - 2014-09-18 08:33 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-09-18 08:32 - 2014-09-18 08:32 - 02347384 _____ (ESET) C:\Users\Shu\Desktop\esetsmartinstaller_deu.exe 2014-09-17 11:43 - 2014-09-17 11:43 - 00001460 _____ () C:\Users\Shu\Desktop\JRT.txt 2014-09-17 11:38 - 2014-09-17 11:38 - 00000000 ____D () C:\Windows\ERUNT 2014-09-17 11:37 - 2014-09-17 11:37 - 00002349 _____ () C:\Users\Shu\Desktop\AdwCleaner[S3].txt 2014-09-17 11:33 - 2013-10-26 10:34 - 00000000 ____D () C:\AdwCleaner 2014-09-17 11:30 - 2014-09-17 11:30 - 00001491 _____ () C:\Users\Shu\Desktop\mbar.txt 2014-09-17 11:29 - 2014-07-10 13:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-17 11:24 - 2013-10-04 17:55 - 00000000 ____D () C:\Windows\Panther 2014-09-17 11:01 - 2014-09-17 11:01 - 01373475 _____ () C:\Users\Shu\Desktop\AdwCleaner_3.310.exe 2014-09-17 11:01 - 2014-09-17 11:01 - 01016035 _____ (Thisisu) C:\Users\Shu\Desktop\JRT.exe 2014-09-17 11:00 - 2014-02-19 03:00 - 00000000 ____D () C:\Users\Shu\AppData\Local\Apps\2.0 2014-09-17 10:58 - 2014-02-25 00:41 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-09-16 16:11 - 2014-09-16 16:11 - 00029566 _____ () C:\ComboFix.txt 2014-09-16 16:11 - 2014-09-14 22:12 - 00000000 ____D () C:\Qoobox 2014-09-16 16:09 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-09-16 15:58 - 2013-10-28 10:13 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-09-16 15:54 - 2014-09-14 22:07 - 05579386 ____R (Swearware) C:\Users\Shu\Downloads\ComboFix.exe 2014-09-16 15:53 - 2014-09-16 15:53 - 00001130 _____ () C:\Users\Shu\Desktop\ComboFix.exe - Verknüpfung.lnk 2014-09-15 20:15 - 2014-09-15 20:14 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Shu\Downloads\tdsskiller.exe 2014-09-15 19:32 - 2014-09-15 19:32 - 00002165 _____ () C:\Users\Shu\Desktop\Dragon Nest Europe.lnk 2014-09-15 18:24 - 2013-11-18 13:06 - 00000000 ____D () C:\Windows\Minidump 2014-09-15 18:23 - 2014-09-15 18:23 - 00262144 ____N () C:\Windows\Minidump\091514-23150-01.dmp 2014-09-15 18:21 - 2014-09-14 11:39 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SDGi Europe 2014-09-15 18:21 - 2014-06-14 13:20 - 00000000 ____D () C:\Program Files (x86)\SDGi Europe 2014-09-15 11:28 - 2014-09-15 11:27 - 00018397 _____ () C:\Windows\DirectX.log 2014-09-15 09:51 - 2014-09-15 09:43 - 00038153 _____ () C:\Users\Shu\Desktop\FRST.txt 2014-09-15 09:44 - 2014-09-15 09:43 - 00053678 _____ () C:\Users\Shu\Desktop\Addition.txt 2014-09-15 09:42 - 2014-09-15 09:42 - 01102777 _____ () C:\Users\Shu\Desktop\Scan Results.140915-0942.txt 2014-09-15 09:41 - 2014-01-14 00:52 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\uTorrent 2014-09-15 09:30 - 2014-09-15 09:29 - 00000000 ____D () C:\Users\Shu\Downloads\SGN SW Torrent 2014-09-15 09:24 - 2014-06-27 22:11 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\NexonLauncher 2014-09-15 09:24 - 2014-06-27 22:10 - 00000000 ____D () C:\Program Files (x86)\Nexon 2014-09-15 08:58 - 2013-10-28 10:13 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-09-15 08:53 - 2014-09-15 08:53 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk 2014-09-15 08:53 - 2014-09-15 08:53 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2014-09-15 08:53 - 2014-09-15 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2 2014-09-15 08:52 - 2014-09-15 08:52 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Shu\Downloads\spybot-2.4.exe 2014-09-15 08:29 - 2014-02-19 03:00 - 00000000 ____D () C:\Users\Shu\AppData\Local\Deployment 2014-09-14 22:56 - 2014-09-14 21:45 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-09-14 22:36 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-09-14 22:35 - 2014-09-14 22:12 - 00000000 ____D () C:\Windows\erdnt 2014-09-14 22:34 - 2013-10-04 17:04 - 00000000 ____D () C:\Users\Shu 2014-09-14 22:25 - 2014-09-14 22:25 - 00000085 _____ () C:\Windows\wininit.ini 2014-09-14 22:20 - 2014-09-14 22:20 - 00000000 ____D () C:\Users\Shu\Documents\ProcAlyzer Dumps 2014-09-14 22:03 - 2014-05-23 08:35 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-14 22:00 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME 2014-09-14 21:44 - 2014-09-14 21:44 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Shu\Downloads\mbar-1.07.0.1012.exe 2014-09-14 10:40 - 2014-09-14 10:40 - 00692832 _____ ( ) C:\Users\Shu\Downloads\DNDownloader96.exe 2014-09-14 09:12 - 2013-11-06 22:37 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\FileZilla 2014-09-14 09:04 - 2014-09-14 09:04 - 00000000 _____ () C:\Windows\setuperr.log 2014-09-13 17:46 - 2013-11-05 00:02 - 00000132 _____ () C:\Users\Shu\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2014-09-13 12:13 - 2014-09-13 12:13 - 01942203 _____ () C:\Users\Shu\Desktop\vitctorian houses.zip 2014-09-13 10:53 - 2014-09-13 10:53 - 06057862 _____ (Tim Kosse) C:\Users\Shu\Downloads\FileZilla_3.9.0.5_win32-setup.exe 2014-09-12 15:19 - 2014-02-18 18:05 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\.minecraft 2014-09-12 14:56 - 2014-09-12 14:52 - 00000000 ____D () C:\Users\Shu\Desktop\world 2014-09-10 13:33 - 2014-09-10 10:00 - 00000000 ____D () C:\Users\Shu\Desktop\Minecraft 2014-09-09 12:47 - 2014-09-09 12:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Action Replay PowerSaves 3DS 2014-09-09 12:47 - 2014-09-09 12:47 - 00000000 ____D () C:\Program Files (x86)\Action Replay PowerSaves 3DS 2014-09-07 23:19 - 2014-09-07 23:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dawn of War II - Destroyer 40k 2014-09-07 15:07 - 2013-10-09 15:33 - 00000000 ____D () C:\Users\Shu\Documents\My Games 2014-09-07 09:14 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-09-06 08:47 - 2013-10-04 18:49 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins 2014-09-05 21:02 - 2014-09-05 21:02 - 01402920 _____ () C:\Users\Shu\Downloads\battlelog-web-plugins_2.5.1_149.exe 2014-09-03 08:13 - 2013-10-10 23:58 - 00000000 ____D () C:\Users\Shu\AppData\Local\PMB Files 2014-09-02 23:38 - 2013-10-10 23:58 - 00000000 ____D () C:\ProgramData\PMB Files 2014-09-02 20:55 - 2014-07-09 14:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph 2014-09-02 19:33 - 2014-07-11 20:50 - 00000000 ____D () C:\Users\Shu\Documents\survarium 2014-09-02 19:32 - 2014-04-10 12:15 - 00000000 ____D () C:\Program Files (x86)\GameforgeLive 2014-09-02 10:06 - 2014-09-02 10:00 - 00000000 ____D () C:\Users\Shu\AppData\Local\lab_1_54 2014-09-01 23:37 - 2014-04-10 12:15 - 00000000 ____D () C:\Users\Shu\Downloads\Gameforge Live 2014-09-01 21:30 - 2014-09-01 21:30 - 00003088 _____ () C:\Windows\System32\Tasks\{CA426A73-A1F4-4917-967B-CDAE3FBA6F61} 2014-09-01 21:29 - 2013-10-04 20:52 - 00000000 ____D () C:\ProgramData\Skype 2014-09-01 11:57 - 2014-01-22 12:40 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\WorldPainter 2014-09-01 11:33 - 2014-09-01 11:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WorldPainter 2014-09-01 11:33 - 2014-09-01 11:32 - 00000000 ____D () C:\Program Files\WorldPainter 2014-08-31 17:06 - 2014-08-31 17:06 - 01397992 _____ () C:\Users\Shu\Downloads\battlelog-web-plugins_2.5.0_148.exe 2014-08-31 08:06 - 2013-10-24 18:52 - 00000000 ____D () C:\Users\Shu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GamersFirst 2014-08-29 11:38 - 2014-07-09 14:42 - 00000000 ____D () C:\Program Files (x86)\Glyph Files to move or delete: ==================== C:\Users\Shu\worldpainter_64_1.8.1.exe Some content of TEMP: ==================== C:\Users\Shu\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-09-17 12:17 ==================== End Of Log ============================ Probleme bestehen zurzeit keine, Rec.Log kommt später |
25.09.2014, 13:13 | #32 |
/// the machine /// TB-Ausbilder | Svhost.exe /Backdoor.Agent + PUP.BitCoinMiner ok
__________________
__________________ |
27.09.2014, 22:27 | #33 |
| Svhost.exe /Backdoor.Agent + PUP.BitCoinMiner Kann sich etwas hinaus ziehen, wenig zeit / viel Stress
__________________Bitte um Geduld, dankö Code:
ATTFilter Farbar Recovery Scan Tool (x64) Version: 12-09-2014 Ran by SYSTEM at 2014-09-27 23:32:56 Running from f:\ Boot Mode: Recovery ================== Search Files: "svhost.exe" ============= ====== End Of Search ====== Geändert von NyanShu (27.09.2014 um 22:42 Uhr) |
28.09.2014, 13:42 | #34 |
/// the machine /// TB-Ausbilder | Svhost.exe /Backdoor.Agent + PUP.BitCoinMiner Sieht gut aus. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.09.2014, 16:29 | #35 |
| Svhost.exe /Backdoor.Agent + PUP.BitCoinMiner Läuft bis jetzt fehlerfrei Denke ist vorerst gelöst, falls nochmal was kommen sollte die Tage, melde ich mich. Danke schon mal für die Hilfe |
29.09.2014, 10:53 | #36 |
/// the machine /// TB-Ausbilder | Svhost.exe /Backdoor.Agent + PUP.BitCoinMiner Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Svhost.exe /Backdoor.Agent + PUP.BitCoinMiner |