|
Plagegeister aller Art und deren Bekämpfung: DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefundenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.11.2014, 22:53 | #16 |
| DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefunden ja das lese ich auch schon die letzten tage... mich beunruhigt nur das wenn es doch so sein sollte, meine papers und concept halt offen gelegen haben... das nich so geil! hier ein die neuen scans FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2014 01 Ran by Administrator (administrator) on WIN7PROF on 23-11-2014 22:45:52 Running from C:\Users\Administrator\Desktop Loaded Profile: Administrator (Available profiles: Administrator) Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Aladdin Knowledge Systems Ltd.) C:\Windows\System32\hasplms.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-22] (AVAST Software) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [413696 2009-05-26] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-333848218-1745761905-3047404079-500\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-333848218-1745761905-3047404079-500\...\MountPoints2: F - F:\bootstrap.exe HKU\S-1-5-21-333848218-1745761905-3047404079-500\...\MountPoints2: {15854dc1-4d69-11e4-920d-78dd08aece2e} - F:\bootstrap.exe HKU\S-1-5-21-333848218-1745761905-3047404079-500\...\MountPoints2: {2657741e-0e55-11e4-b51d-5cff350c09d7} - G:\bootstrap.exe ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-333848218-1745761905-3047404079-500\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKU\S-1-5-21-333848218-1745761905-3047404079-500\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x08DA5C78D909CE01 HKU\S-1-5-21-333848218-1745761905-3047404079-500\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKU\S-1-5-21-333848218-1745761905-3047404079-500: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\searchplugins\google-images.xml FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\searchplugins\qwantcom.xml FF Extension: Disconnect - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\Extensions\2.0@disconnect.me.xpi [2014-10-26] FF Extension: Ghostery - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\Extensions\firefox@ghostery.com.xpi [2014-10-26] FF Extension: Grooveshark Unlocker - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2014-11-19] FF Extension: JSONView - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\Extensions\jsonview@brh.numbera.com.xpi [2014-11-19] FF Extension: Adblock Edge - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2013-07-16] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-22] FF HKU\S-1-5-21-333848218-1745761905-3047404079-500\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\9wn09u8x.default\extensions\cliqz@cliqz.com Chrome: ======= CHR HomePage: Default -> CHR StartupUrls: Default -> "" CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-22] CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-22] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-21] CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-22] CHR Extension: (Google-Suche) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-22] CHR Extension: (Avast Online Security) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-05-22] CHR Extension: (Google Wallet) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-22] CHR Extension: (Google Mail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-22] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-13] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-13] (AVAST Software) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 A2DDA; C:\EEK\BIN\a2ddax64.sys [26176 2014-11-20] (Emsisoft GmbH) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-13] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-13] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-13] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-13] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-22] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-13] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-13] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-13] () R3 atmeltpm; C:\Windows\System32\DRIVERS\atmeltpm64.sys [19456 2011-08-05] (Atmel, Inc.) S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2014-11-20] (Emsisoft GmbH) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-27] (Disc Soft Ltd) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-09-20] (Intel Corporation) R3 LenovoRd; C:\Windows\System32\DRIVERS\LenovoRd.sys [118016 2009-05-11] (Lenovo) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-23 22:45 - 2014-11-23 22:46 - 00013740 _____ () C:\Users\Administrator\Desktop\FRST.txt 2014-11-23 22:45 - 2014-11-23 22:45 - 00000000 ____D () C:\Users\Administrator\Desktop\FRST-OlderVersion 2014-11-22 13:11 - 2014-11-22 13:11 - 00005790 _____ () C:\Users\Administrator\Desktop\detekt.log 2014-11-22 13:09 - 2014-11-22 13:09 - 27395304 _____ () C:\Users\Administrator\Desktop\detekt(1).exe 2014-11-22 12:34 - 2014-11-22 12:34 - 00000000 ____D () C:\Users\Administrator\Desktop\frst scanner 2014-11-21 20:47 - 2014-11-21 20:47 - 00000768 _____ () C:\EamClean.log 2014-11-21 19:56 - 2014-11-22 13:13 - 00001236 _____ () C:\Users\Administrator\Desktop\detekt.rar 2014-11-20 20:20 - 2014-11-23 22:45 - 00000000 ____D () C:\FRST 2014-11-20 20:18 - 2014-11-20 20:19 - 00000000 ____D () C:\Users\Administrator\Desktop\docs 2014-11-20 20:17 - 2014-11-23 22:45 - 02118144 _____ (Farbar) C:\Users\Administrator\Desktop\FRST64.exe 2014-11-20 19:38 - 2014-11-21 20:04 - 00000000 ____D () C:\EEK 2014-11-20 19:38 - 2014-11-20 19:38 - 00000762 _____ () C:\Users\Administrator\Desktop\Start Emsisoft Emergency Kit.lnk 2014-11-20 19:09 - 2014-11-22 13:13 - 00000000 ____D () C:\Users\Administrator\Desktop\anti anti vs bad things 2014-11-20 18:23 - 2014-11-20 18:23 - 00000000 ____D () C:\Users\Administrator\Desktop\scrnshot 2014-11-20 10:55 - 2014-11-20 16:31 - 00271791 _____ () C:\Users\Administrator\Downloads\detekt.log 2014-11-20 10:46 - 2014-11-20 10:47 - 27810288 _____ () C:\Users\Administrator\Downloads\detekt.exe 2014-11-19 19:25 - 2014-11-19 19:25 - 00036872 _____ () C:\Users\Administrator\Downloads\NPPJSONViewer1_21.zip 2014-11-19 17:33 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-11-19 17:33 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll 2014-11-19 17:33 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-11-19 17:33 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll 2014-11-13 12:19 - 2014-11-13 12:19 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-11-13 12:19 - 2014-11-13 12:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-11-13 12:19 - 2014-11-13 12:19 - 00001943 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2014-11-13 12:17 - 2014-11-13 12:17 - 32490888 _____ ( ) C:\Users\Administrator\Downloads\K-Lite_Codec_Pack_1080_Full.exe 2014-11-13 12:16 - 2014-11-13 12:16 - 11752039 _____ ( ) C:\Users\Administrator\Downloads\K-Lite_Codec_Pack_1080_Basic.exe 2014-11-13 12:14 - 2014-11-13 12:14 - 13884752 _____ ( ) C:\Users\Administrator\Downloads\klcp_update_1084_20141031.exe 2014-11-12 10:52 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-11-12 10:52 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-11-12 10:52 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-11-12 10:52 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-11-12 10:52 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-11-12 10:52 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-11-12 10:52 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-11-12 10:52 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-11-12 10:52 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-11-12 10:52 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-11-12 10:52 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-11-12 10:52 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-11-12 10:52 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-11-12 10:52 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-11-12 10:52 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-11-12 10:52 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-11-12 10:52 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-11-12 10:52 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-11-12 10:52 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-11-12 10:52 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-11-12 10:52 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-11-12 10:52 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-11-12 10:52 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-11-12 10:52 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-11-12 10:52 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-11-12 10:52 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-11-12 10:52 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-11-12 10:52 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-11-12 10:52 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-11-12 10:52 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-11-12 10:52 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-11-12 10:52 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-11-12 10:52 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-11-12 10:52 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-11-12 10:52 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-11-12 10:52 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-11-12 10:52 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-11-12 10:52 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-11-12 10:52 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-11-12 10:52 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-11-12 10:52 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-11-12 10:52 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-11-12 10:52 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-11-12 10:52 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-11-12 10:52 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-11-12 10:52 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-11-12 10:52 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-11-12 10:52 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-11-12 10:52 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-11-12 10:52 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-11-12 10:52 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-11-12 10:52 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-11-12 10:52 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-11-12 10:52 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-11-12 10:52 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-11-12 10:52 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-11-12 10:52 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-11-12 10:52 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-11-12 10:52 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-11-12 10:52 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2014-11-12 10:52 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2014-11-12 10:52 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-11-12 10:52 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-11-12 10:52 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-11-12 10:52 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-11-12 10:52 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2014-11-12 10:52 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2014-11-12 10:52 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-11-12 10:52 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-11-12 10:52 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-11-12 10:52 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2014-11-12 10:52 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2014-11-12 10:50 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-11-12 10:50 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-11-12 10:50 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-11-12 10:50 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-11-12 10:50 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-11-12 10:50 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-11-12 10:50 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-11-12 10:50 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-11-12 10:50 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-11-12 10:50 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-11-12 10:50 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-11-12 10:50 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-11-12 10:50 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-11-12 10:50 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2014-11-12 10:50 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-11-12 10:50 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-11-12 10:50 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-11-12 10:50 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-11-12 10:50 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-11-12 10:50 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2014-11-12 10:50 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-11-12 10:50 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-11-12 10:50 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-11-12 10:50 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-11-12 10:50 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-11-12 10:50 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-11-12 10:50 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-11-12 10:50 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL 2014-11-12 10:50 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL 2014-11-11 16:47 - 2014-11-11 16:47 - 00021610 _____ () C:\Users\Administrator\Downloads\Kooperationsvertrag_mapexpert_ver 1(1).odt 2014-11-07 11:22 - 2014-11-12 09:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-24 13:59 - 2014-10-24 13:59 - 00021610 _____ () C:\Users\Administrator\Downloads\Kooperationsvertrag_mapexpert_ver 1.odt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-11-23 22:18 - 2014-05-22 12:21 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-11-23 22:16 - 2014-05-22 12:21 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-11-23 22:13 - 2014-04-12 10:32 - 02043269 _____ () C:\Windows\WindowsUpdate.log 2014-11-23 22:12 - 2014-08-12 18:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-11-22 13:17 - 2010-11-21 07:50 - 00699440 _____ () C:\Windows\system32\perfh007.dat 2014-11-22 13:17 - 2010-11-21 07:50 - 00149548 _____ () C:\Windows\system32\perfc007.dat 2014-11-22 13:17 - 2009-07-14 06:13 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-11-22 12:17 - 2014-05-22 12:21 - 00002194 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-11-22 12:13 - 2009-07-14 05:45 - 00038800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-11-22 12:13 - 2009-07-14 05:45 - 00038800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-11-22 12:06 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-11-22 12:05 - 2014-05-10 12:26 - 00030979 _____ () C:\Windows\setupact.log 2014-11-22 11:38 - 2014-05-22 12:21 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-11-21 19:21 - 2014-05-28 17:25 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-11-21 19:15 - 2014-05-28 17:18 - 00000000 ____D () C:\ProgramData\Adobe 2014-11-21 19:14 - 2014-05-28 17:26 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-11-20 20:32 - 2014-06-03 07:37 - 00000000 ____D () C:\Users\Administrator\Desktop\entertain me 2014-11-20 20:19 - 2014-06-03 07:36 - 00000000 ____D () C:\Users\Administrator\Desktop\work 2014-11-20 10:37 - 2014-05-22 12:22 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-11-17 16:04 - 2014-07-28 14:30 - 00000000 ____D () C:\Users\Administrator\Documents\meshmixer 2014-11-13 16:11 - 2014-05-22 12:21 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-11-13 16:11 - 2014-05-22 12:21 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-11-13 12:20 - 2014-05-23 11:58 - 00011046 _____ () C:\Windows\PFRO.log 2014-11-13 12:19 - 2014-05-22 12:21 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-11-13 12:19 - 2014-05-22 12:21 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-11-13 12:19 - 2014-05-22 12:21 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-11-13 12:19 - 2014-05-22 12:21 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-11-13 12:19 - 2014-05-22 12:21 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-11-13 12:19 - 2014-05-22 12:21 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-11-13 12:19 - 2014-05-22 12:21 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-11-13 12:17 - 2014-08-07 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack 2014-11-13 12:17 - 2014-08-07 22:59 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack 2014-11-13 12:11 - 2014-08-12 18:46 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-11-13 12:11 - 2014-06-25 18:07 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Adobe 2014-11-13 12:11 - 2014-05-22 13:24 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-11-13 12:11 - 2014-05-22 13:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-11-13 11:13 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-11-13 10:37 - 2014-04-17 11:58 - 04908464 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-11-13 10:35 - 2013-02-11 16:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-11-13 10:34 - 2014-05-23 11:58 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-11-13 10:19 - 2013-07-16 18:08 - 00000000 ____D () C:\Windows\system32\MRT 2014-11-13 10:16 - 2013-02-08 17:16 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-11-12 00:38 - 2014-05-23 12:05 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Skype 2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-10-24 18:58 - 2014-10-17 19:00 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\.purple Some content of TEMP: ==================== C:\Users\Administrator\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpb7cvpb.dll C:\Users\Administrator\AppData\Local\Temp\SkypeSetup.exe C:\Users\Administrator\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-11-15 08:17 ==================== End Of Log ============================ --- --- --- und die addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-11-2014 01 Ran by Administrator at 2014-11-23 22:46:46 Running from C:\Users\Administrator\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 123D Design R1.5 (HKLM\...\123D Design) (Version: 1.5.23 - Autodesk, Inc.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.223 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software) Blender (HKLM\...\Blender) (Version: 2.71 - Blender Foundation) CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP) Conexant 20585 SmartAudio HD (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.95.49.53 - Conexant) CPUID HWMonitor 1.23 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Cura 14.07 (HKLM-x32\...\Cura_14.07) (Version: - ) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Dropbox (HKU\S-1-5-21-333848218-1745761905-3047404079-500\...\Dropbox) (Version: 2.8.4 - Dropbox, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 18.7 - Intel) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2993 - Intel Corporation) K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - ) Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.05 - ) Meshmixer (HKLM\...\Meshmixer_x64) (Version: - ) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 33.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 de)) (Version: 33.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Paint.NET v3.5.10 (HKLM\...\{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}) (Version: 3.60.0 - dotPDN LLC) PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.214.2 - Tracker Software Products Ltd) Pidgin (HKLM-x32\...\Pidgin) (Version: 2.10.9 - ) pidgin-otr 4.0.0-1 (HKLM-x32\...\pidgin-otr) (Version: 4.0.0-1 - Cypherpunks CA) QuickTime (HKLM-x32\...\{C78EAC6F-7A73-452E-8134-DBB2165C5A68}) (Version: 7.62.14.0 - Apple Inc.) Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.32494 - TeamViewer) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - ) UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.) Vectorworks 2010 Hilfe (HKLM-x32\...\eu.computerworks.vectorworks.2010.help.deu.C597E665C9D833B0F52B09434821DFAEF4904789.1) (Version: 1.0 - UNKNOWN) Vectorworks 2010 Hilfe (x32 Version: 1.0 - UNKNOWN) Hidden Vectorworks Pro 2010 SP2 R1 (HKLM-x32\...\Vectorworks Pro 2010 SP2 R1) (Version: - ) VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN) Windows Driver Package - Arduino LLC (www.arduino.cc) Arduino USB Driver (01/04/2013 1.0.0.0) (HKLM\...\1E3EA5624DD04BEFECF3FFF6D3A21CCE9CD70A91) (Version: 01/04/2013 1.0.0.0 - Arduino LLC (www.arduino.cc)) WinRAR (HKLM-x32\...\WinRAR archiver) (Version: - ) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\ooofilt_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\propertyhdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files (x86)\OpenOffice 4\program\shlxthdl\shlxthdl_x64.dll (Apache Software Foundation) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> C:\Program Files\Blender Foundation\Blender\BlendThumb64.dll () CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-333848218-1745761905-3047404079-500_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Administrator\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-05-28 17:14 - 00002150 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 3dns.adobe.com 127.0.0.1 3dns.adobe.de 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-1.adobe.de 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-2.adobe.de 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-3.adobe.de 127.0.0.1 3dns-4.adobe.com 127.0.0.1 3dns-4.adobe.de 127.0.0.1 activate.adobe.com 127.0.0.1 activate.adobe.de 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 activate.wip3.adobe.de 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sea.adobe.de 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 activate-sjc0.adobe.de 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns.adobe.de 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-1.adobe.de 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-2.adobe.de 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-3.adobe.de 127.0.0.1 adobe-dns-4.adobe.com 127.0.0.1 adobe-dns-4.adobe.de 127.0.0.1 adobe-dns-5.adobe.com There are 14 more lines. ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {00ACB2FD-3E6D-485C-AB5D-1DE4078350C2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-13] (Adobe Systems Incorporated) Task: {19167FD5-208E-4462-BCC0-A8DB9A74A06D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd) Task: {38CEC05D-E0BD-42A8-AC54-7FD5F9C012B8} - System32\Tasks\{1906F479-C795-49C8-B073-301A860A5A70} => Firefox.exe hxxp://ui.skype.com/ui/0/6.21.0.104/de/abandoninstall?page=tsProgressBar Task: {48E6FB1A-66AA-42B1-885C-878F8BB627A9} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] () Task: {6D68A109-49F2-4223-82CC-FF5C3CABD65C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-22] (Google Inc.) Task: {99ABD3A4-2F51-488B-A4F5-4BD41E036CF0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-13] (AVAST Software) Task: {9E802FE3-3D7F-4CBE-B5A7-F61064C9617A} - System32\Tasks\AdobeAAMUpdater-1.0-Win7Prof-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {CD4630B8-A219-4EF7-9A1E-509314BD5BFB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-22] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-05-22 13:27 - 2006-12-11 01:14 - 00043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll 2014-05-10 12:33 - 2013-02-19 10:43 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2014-11-21 23:33 - 2014-11-21 23:33 - 02903040 _____ () C:\Program Files\AVAST Software\Avast\defs\14112101\algo.dll 2014-11-23 22:12 - 2014-11-23 22:12 - 02903552 _____ () C:\Program Files\AVAST Software\Avast\defs\14112301\algo.dll 2014-11-13 12:19 - 2014-11-13 12:19 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-333848218-1745761905-3047404079-500 - Administrator - Enabled) => C:\Users\Administrator Gast (S-1-5-21-333848218-1745761905-3047404079-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-333848218-1745761905-3047404079-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/22/2014 05:38:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 33.1.0.5423, Zeitstempel: 0x545c0a59 Name des fehlerhaften Moduls: mozalloc.dll, Version: 33.1.0.5423, Zeitstempel: 0x545be5ee Ausnahmecode: 0x80000003 Fehleroffset: 0x00001425 ID des fehlerhaften Prozesses: 0x13dc Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (11/22/2014 05:38:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 33.1.0.5423, Zeitstempel: 0x545c0a37 Name des fehlerhaften Moduls: mozalloc.dll, Version: 33.1.0.5423, Zeitstempel: 0x545be5ee Ausnahmecode: 0x80000003 Fehleroffset: 0x00001425 ID des fehlerhaften Prozesses: 0xb30 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Error: (11/22/2014 00:25:52 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (11/22/2014 00:25:23 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (11/22/2014 00:07:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/22/2014 11:37:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2014 09:13:28 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (11/21/2014 08:49:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2014 07:55:25 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (11/21/2014 07:53:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (11/21/2014 07:24:05 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Backup Service Home-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (11/14/2014 11:04:39 AM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "T410-THINK", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{BFE5B42C-A327-4577-84EE-760920E9A1E9}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/13/2014 10:47:42 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (11/13/2014 10:47:41 PM) (Source: Disk) (EventID: 11) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden. Error: (11/13/2014 00:33:22 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 13.11.2014 um 12:30:49 unerwartet heruntergefahren. Error: (11/06/2014 07:39:54 PM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "T410-THINK", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{BFE5B42C-A327-4577-84EE-760920E9A1E9}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/05/2014 01:19:07 PM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "USER-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{BFE5B42C-A327-4577-84EE-760920E9A1E9}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/03/2014 05:34:05 PM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "MARKUS-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{BFE5B42C-A327-4577-84EE-760920E9A1E9}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/03/2014 11:09:59 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 03.11.2014 um 11:06:50 unerwartet heruntergefahren. Error: (10/27/2014 01:11:13 PM) (Source: bowser) (EventID: 8003) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "USER-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{BFE5B42C-A327-4577-84EE-760920E9A1E9}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Microsoft Office Sessions: ========================= Error: (11/22/2014 05:38:17 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe33.1.0.5423545c0a59mozalloc.dll33.1.0.5423545be5ee800000030000142513dc01d0066d213d6a5cC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllf58569b4-7265-11e4-b54a-78dd08aece2e Error: (11/22/2014 05:38:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: firefox.exe33.1.0.5423545c0a37mozalloc.dll33.1.0.5423545be5ee8000000300001425b3001d0064dbc0f187eC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dllf2c16773-7265-11e4-b54a-78dd08aece2e Error: (11/22/2014 00:25:52 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Users\ADMINI~1\AppData\Local\Temp\_MEI26842\detekt.exe.manifest Error: (11/22/2014 00:25:23 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Users\ADMINI~1\AppData\Local\Temp\_MEI31522\detekt.exe.manifest Error: (11/22/2014 00:07:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/22/2014 11:37:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2014 09:13:28 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Users\ADMINI~1\AppData\Local\Temp\_MEI33362\detekt.exe.manifest Error: (11/21/2014 08:49:36 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2014 07:55:25 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Users\ADMINI~1\AppData\Local\Temp\_MEI24122\detekt.exe.manifest Error: (11/21/2014 07:53:40 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 CodeIntegrity Errors: =================================== Date: 2014-11-23 22:22:41.036 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:37:37.786 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:35:42.474 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:34:41.714 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:33:57.563 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:32:57.378 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:31:48.456 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:21:09.597 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-23 12:19:54.498 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-11-22 18:55:25.426 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\CX64CQ17.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz Percentage of memory in use: 19% Total physical RAM: 3891.67 MB Available physical RAM: 3149.76 MB Total Pagefile: 7781.52 MB Available Pagefile: 6691.89 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (Win7Professionalx64) (Fixed) (Total:298.09 GB) (Free:230.37 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: C93A3282) Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
24.11.2014, 09:33 | #17 |
/// TB-Ausbilder /// Anleitungs-Guru | DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefunden Das Tool ist momentan "unbrauchbar". Nicht umsonst wird ein Update nach dem anderen rausgebracht.
__________________Mach mal einen ESET-Scan zu Deiner Beruhigung: Schritt 1 ESET Online Scanner
__________________ |
24.11.2014, 11:46 | #18 |
| DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefundenscan is in arbeit... |
24.11.2014, 15:46 | #19 |
| DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefunden so fertig... ich habe noch meine alte win vista platte rangehängt da ich ab und an auch auf diese zugreifen muss... ich war erstaunt was da alles drin rum wuselt!ernsthaft! da war früher ein gdata(2012) prog darauf.... aber meine aktuelle platte win 7 scheint wohl unbefleckt zu sein.. oder? |
24.11.2014, 18:00 | #20 |
/// TB-Ausbilder /// Anleitungs-Guru | DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefunden Poste bitte das ESET Log wie beschrieben und nicht als Anhang.
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
24.11.2014, 18:58 | #21 |
| DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefundenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=0e37ca25dae654458d83487dfd707911 # engine=21236 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-11-24 01:40:57 # local_time=2014-11-24 02:40:57 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 71 94 182131 16078799 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 168466307 0 0 # scanned=300227 # found=47 # cleaned=0 # scan_time=8198 sh=3B29C36CCB0FD00A0812896E61D3AE6CE18E5EEE ft=1 fh=5ce1e22016c2ce7d vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6WTW9HC\spstub[1].exe" sh=972DB9071C719922142BE77CF935C208B66F8DE2 ft=1 fh=c50a95d882970223 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Administrator\AppData\Local\Temp\OCS\ocs_v71b.exe" sh=FEFC5123167E6C7D72E2113A7EDE6B5A01891BC3 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Backup\C\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kthc1d8v.default\prefs_24_02_2014_11_23_54.js" sh=9B01F0D111E86972DACC553B969006A45DCEC0F2 ft=1 fh=a0aefda3f3809e2e vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\Main\bin\CltMngSvc.exe.vir" sh=2DE0850CBDDAC6F960C68212CB58F0A34C3071E8 ft=1 fh=c8c3c71b037f132f vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\Main\bin\SPTool.dll.vir" sh=6509FB8A8AC07A7058E9126547B1C61E81E55B71 ft=1 fh=0d2073e1124a6c6b vn="Win32/Conduit.SearchProtect.Q evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\Main\bin\uninstall.exe.vir" sh=745E6C58EAB2327C31E5B123072A12B5F9F6BC9A ft=1 fh=198a6bb102f3bd19 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\SearchProtect\bin\cltmng.exe.vir" sh=30201356783F0508217BD58285E0CCE97FE74BC0 ft=1 fh=90fcc86cd35724aa vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\SearchProtect\bin\SPTool64.exe.vir" sh=4AE330A04D39407CAD3AD0A1DE5D948BC3A72741 ft=1 fh=123813dabc383735 vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\SearchProtect\bin\SPVC32.dll.vir" sh=DFD223F65E3ED21E69C4B1A4C1030840AA4E1B43 ft=1 fh=5bc9522f3fe0ccca vn="Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\SearchProtect\bin\SPVC32Loader.dll.vir" sh=F91E89BA77788D3532D35A1A482C831A0C8E19FA ft=1 fh=bdeda04c5c6db519 vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\SearchProtect\bin\SPVC64.dll.vir" sh=E49093A515D0EC3A0E4C689EF920E741CB9E17DC ft=1 fh=c8de0c5af4839296 vn="Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\SearchProtect\bin\SPVC64Loader.dll.vir" sh=787B2690A5FA365A9DA9188342D8A8EC5C4ED585 ft=1 fh=75aec034a38f1116 vn="Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\Searchprotect\UI\bin\cltmngui.exe.vir" sh=A613667E35EDB22BEF81391A363FF22D0CA6AC52 ft=1 fh=c71c00111059e6aa vn="Variante von Win32/Adware.Toolbar.Shopper.AD Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\ShopperReports3\bin\3.0.517.0\CntntCntr.dll.vir" sh=79675DC5217F4D44C4A5769D169BC88BB9F74557 ft=0 fh=0000000000000000 vn="Win32/Adware.Toolbar.Shopper.AD Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\chrome\firefoxtoolbar.jar.vir" sh=56EA1F0BBEA2B9489F9F7EE0CE4D9578888DAF6C ft=1 fh=c71c0011b39bc89d vn="Variante von Win32/Adware.Toolbar.Shopper.AD Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\components\BRNstFF.dll.vir" sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="H:\AdwCleaner\Quarantine\C\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kthc1d8v.default\user.js.vir" sh=3F20DC68A6AAC23C4702D16C8A5388DCFE591AEA ft=1 fh=e5e2264a283a7f45 vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\IGSViewer\MyBabylonTB.exe" sh=5AB7DF196501605084A1675D11FB1958737F825C ft=1 fh=4b56ef77f39f4b77 vn="Variante von MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="H:\Program Files\MSR\backup\System Update kb70007\Installer.dll" sh=26545AE9CE673A5A328808BEE1A060F65BC741B9 ft=1 fh=66036335b3a0f36d vn="Variante von MSIL/Adware.Proxomoto.E Anwendung" ac=I fn="H:\Program Files\MSR\backup\System Update kb70007\InstallerLibrary.dll" sh=7FCB7AA30A9D70C36C1B04D2784587EC02F5593A ft=1 fh=fdfab6fc5fe2b71f vn="Variante von MSIL/Adware.Proxomoto.G Anwendung" ac=I fn="H:\Program Files\MSR\backup\System Update kb70007\WindowsUpdater.exe" sh=4E475FD620FBCCBB37453AF2BD0427BDA73109FF ft=1 fh=70875884387ffbdb vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\DpInterface32.dll" sh=524ED1264811258D64BA2BE8B48005C6D1935713 ft=1 fh=19b60c262a337e59 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\DpInterface64.dll" sh=72971E4B87542575A876B36FB87879B416F4EC88 ft=1 fh=eb8c71c588367618 vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\DpInterfacef32.dll" sh=01C9B3D0E073B824021B29F1FD957A8643DF6931 ft=1 fh=9d9cb38b273b86fe vn="Variante von Win32/ELEX.AR evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\RSHP.exe" sh=F34BB16FA7EEF85B106A7C3A3FDEEE95ECF18001 ft=1 fh=7bd5299d4d87abc5 vn="Win32/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\SearchProtect32.dll" sh=FB15CD6ADCD9BDFBF68D5DF5EAEA02BF329F8D4F ft=1 fh=dfa2b1c2f56e7303 vn="Win64/Thinknice.A evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\SearchProtect64.dll" sh=B733C40B96BCA6CC139230D0F7C4E51CEC12CF35 ft=1 fh=08ea3c71e6c55c1b vn="Win32/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\SpAPPSv32.dll" sh=D6F9F256C03B81C01D6CFF28D2D966F59F786AC3 ft=1 fh=3a3e287aa52ff7e5 vn="Variante von Win64/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\SpAPPSv64.dll" sh=EC7EC5D60C5A578BC9953115D368BECD05BA14B2 ft=1 fh=ecbff00cc7dcc0fd vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="H:\Program Files\SupTab\SupTab.dll" sh=95D8C7F2851240F836D46EBD0DCB0BBAE3C9C3C8 ft=1 fh=c39b2415a29978f2 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="H:\ProgramData\IePluginService\PluginService.exe" sh=0B0A6BAA57B7F36549C7C7407E765A6A4889B7B4 ft=0 fh=0000000000000000 vn="Java/TrojanDownloader.Agent.NCJ Trojaner" ac=I fn="H:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\784b3597-3615991b" sh=757BDC60DB7F2DADEA0F1DD39FCB96341CAA7FB5 ft=1 fh=37dacb647a5f563b vn="Variante von Win32/Injector.JZY Trojaner" ac=I fn="H:\Users\User\AppData\Roaming\1098.exe" sh=757BDC60DB7F2DADEA0F1DD39FCB96341CAA7FB5 ft=1 fh=37dacb647a5f563b vn="Variante von Win32/Injector.JZY Trojaner" ac=I fn="H:\Users\User\AppData\Roaming\1098_aldibytill7_aorr2Ab5tD.exe" sh=1203A7EDE44DA5ADD6B090FE208EF06609E5CC6E ft=1 fh=d149241470372d40 vn="Win32/Delf.ODB Trojaner" ac=I fn="H:\Users\User\AppData\Roaming\winvideogt_x32.exe" sh=81447912A34F2B17146525275592838967D4FFF7 ft=1 fh=e9acee4b46b6c119 vn="Variante von Win32/RiskWare.Astori.A Anwendung" ac=I fn="H:\Users\User\AppData\Roaming\InetStat\inetstat.exe" sh=B89CB86566345777AE8C0B7EBEC20093ABA9345B ft=0 fh=0000000000000000 vn="Win32/Reveton.J Trojaner" ac=I fn="H:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk" sh=DB181B6F57352AD0F1C8B08CC6D0DFB404872455 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="H:\Users\User\AppData\Roaming\MyPhoneExplorer\LENOVO Lenovo A760 [860227025457415]\Cache\external\Lenovo_A760_Google_ROM_140106.zip" sh=EC7EC5D60C5A578BC9953115D368BECD05BA14B2 ft=1 fh=ecbff00cc7dcc0fd vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="H:\Users\User\AppData\Roaming\SupTab\SupTab.dll" sh=DB181B6F57352AD0F1C8B08CC6D0DFB404872455 ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="H:\Users\User\Desktop\lenovo a 769 rom\Lenovo_A760_Google_ROM_140106.zip" sh=DEAC30B91F2430AA6B94E98BAD180C45295AA08C ft=1 fh=f64f4ef25ee17a60 vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="H:\Users\User\Desktop\work\wbform\IGSviewerSetup.exe" sh=A981E3D6F03D3BD57D1472F33A4093A01533F8A8 ft=1 fh=7aaf7b3d0491af48 vn="Variante von MSIL/AdvancedSystemProtector.F evtl. unerwünschte Anwendung" ac=I fn="H:\Users\User\Downloads\wzmp_8.exe" sh=EAE2784C9115FE9CFA44A116B74E72C1BCCFA7F6 ft=1 fh=2e79e77116fe19c4 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="H:\Users\User\Downloads\durchschauen\MyPhoneExplorer_1.8.5.exe" sh=5AB7DF196501605084A1675D11FB1958737F825C ft=1 fh=4b56ef77f39f4b77 vn="Variante von MSIL/Adware.Proxomoto.A Anwendung" ac=I fn="H:\Windows\Microsoft\System Update kb70007\Installer.dll" sh=26545AE9CE673A5A328808BEE1A060F65BC741B9 ft=1 fh=66036335b3a0f36d vn="Variante von MSIL/Adware.Proxomoto.E Anwendung" ac=I fn="H:\Windows\Microsoft\System Update kb70007\InstallerLibrary.dll" sh=7FCB7AA30A9D70C36C1B04D2784587EC02F5593A ft=1 fh=fdfab6fc5fe2b71f vn="Variante von MSIL/Adware.Proxomoto.G Anwendung" ac=I fn="H:\Windows\Microsoft\System Update kb70007\WindowsUpdater.exe" sh=BDF1075E6C90522C4EBF80AE1CE14AC4FA27B48C ft=0 fh=0000000000000000 vn="Variante von Win32/Adware.OneStep.AT Anwendung" ac=I fn="H:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZA7OW7VE\upgrade[1].cab" |
24.11.2014, 22:21 | #22 | |
/// TB-Ausbilder /// Anleitungs-Guru | DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefundenZitat:
Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Code:
ATTFilter H:\Users\User\AppData\Roaming\1098.exe H:\Users\User\AppData\Roaming\1098_aldibytill7_aorr2Ab5tD.exe H:\Users\User\AppData\Roaming\winvideogt_x32.exe
__________________ Gruß deeprybka Lob, Kritik, Wünsche? Spende fürs trojaner-board? _______________________________________________ „Neminem laede, immo omnes, quantum potes, iuva.“ Arthur Schopenhauer |
Themen zu DETEKT scan hat blackshades rat , xtreme rat, darkcomet rat auf win7 gefunden |
blackshades rat, conduit.search, conduit.search entfernen, darkcomet, darkcomet rat, detekt, fehlercode 0x80000003, fehlercode windows, java/trojandownloader.agent.ncj, msil/advancedsystemprotector.f, msil/adware.proxomoto.a, msil/adware.proxomoto.e, msil/adware.proxomoto.g, win32/adware.onestep.at, win32/adware.toolbar.shopper.ad, win32/downware.l, win32/elex.ar, win32/elex.av, win32/injector.jzy, win32/thinknice.a, win32/thinknice.b, win32/thinknice.c, win32/toolbar.babylon, win64/thinknice.a, win64/thinknice.c, xtreme rat |