Plagegeister aller Art und deren Bekämpfung: Trojaner 'TR/Crypt.XPACK.Gen'

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
| ![]() Trojaner 'TR/Crypt.XPACK.Gen' Liebe Trojaner Bord Community, ich habe mir ein gebrauchtes Netbook gekauft, um am Wochenende rausfahren zu können. Dieses war zurückgesetzt worden. Es hat ein Windows Starter Programm. Allerdings habe ich keine CD davon. Es ist schon drauf. Als Schreibprogramm habe ich ich mir open office runtergeladen. Firefox für das Internet und als Virenschutz gestern AVIRA. Jetzt habe ich gerade folgende Meldung bekommen: Der Zugriff auf die Datei 'C:\Users\Petra\...\Firefox_37.0.1_einrichten.exe' mit dem Virus oder dem unerwünschten Programm 'TR/Crypt.XPACK.Gen' wurde blockiert. Ausserdem steht unten die Meldung, dass mein Firefox zu langsam arbeitet. Was kann, soll ich jetzt machen. Ich habe noch keine Erfahrung, weil ich das noch nie gemacht habe. Bisher befinden sich kaum Daten von mir auf dem PC. Ich habe lediglich fünf ODT Dateien, in die ich was reingeschrieben habe und die ich gerne behalten möchte. Ich traue mich aber nicht, sie auf einen Stick zu ziehen, weil ich fürchte, dann den Virus mitzunehmen. Wäre es eine Lösung, die Dateien mir selbst per Mail zuzusenden? Oder sende ich dann den Virus auch mit. Muss ich überhaupt die Dateien runterziehen, bevor ich angeleitet, durch Sie, den Virus entferne? Neben dem Netbook habe ich noch mein Notebook zur Verfügung. Zum Glück habe ich die beiden noch nie miteinander verbunden. Beim Notebook hängt sich neuerdings Firefox immer auf, wenn ich eine Seite anklicke. Vielleicht ist das auch ein Virus, aber dass sollte man lieber extra behandeln. Da sind auch viele Daten drauf an denen ich hänge. Ich danke Ihnen schon mal im Voraus Parim |
Trojaner 'TR/Crypt.XPACK.Gen'

hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
| ![]() Trojaner 'TR/Crypt.XPACK.Gen' Hallo schrauber,
__________________ersteinmal vielen Dank für die schnelle Antwort. Ich hoffe es klappt jetzt mit meiner Antwort. Ich habe den Scan laufen lassen und die Dateien liegen auf dem Desktop. Muss ich sie erst öffnen um sie zu senden, oder kann ich sie einfach so reinkopieren? Sorry schrauber, ich habe erst jetzt den Button für die direkte Antwort entdeckt. Bin heute das erste Mal hier unterwegs. Irgendwie aufgeregt und mit Freude was zu lernen. Vorher hatte ich den Antworten Button unter deiner Mail benutzt. Nun weiß ich gar nicht, ob das angekommen ist. Hatte die Scan-Ergebnis-Datein noch nicht mitgesandt, weil ich nicht weiß, ob ich sie vorher öffnen muss oder sie einfach so, mit pacet und copy hier reinkopieren kann. Hallo schrauber, bervor ich gleich ins Bette gehe, kopiere ich mal die Ergebnisse des Scan. FRST Editor: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-05-2015 01 Ran by Petra (administrator) on PETRA-PC on 22-05-2015 18:44:28 Running from C:\Users\Petra\Desktop Loaded Profiles: Petra (Available Profiles: Petra) Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe () C:\Windows\System32\AsusService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (ASUSTek Computer Inc.) C:\Program Files\Asus\Eee Docking\Eee Docking.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotKeyMon.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotkeyService.exe (ASUSTeK Computer Inc.) C:\Program Files\Asus\SHE\SuperHybridEngine.exe (ASUS) C:\Program Files\Asus\CapsHook\CapsHook.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Boingo Wireless, Inc.) C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.OE.Systray.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [EeeSplendidAgent] => C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101288 2010-12-07] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1248176 2010-12-07] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [412600 2010-11-15] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2011-03-11] (AsusTek Computer Inc.) HKLM-x32\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS) HKLM-x32\...\Run: [Eee Docking] => C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [414384 2011-01-07] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files\ASUS\ASUS WebStorage\\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [141848 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [173592 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [150552 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9177632 2010-04-27] (Realtek Semiconductor) HKLM-x32\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [548744 2010-06-10] (ELAN Microelectronic Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] => C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2015-05-14] () HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2011-04-02] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.OE.Systray.exe [128760 2015-05-07] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [728312 2015-04-16] (Avira Operations GmbH & Co. KG) HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\...\RunOnce: [RunCanonMsetUp] => C:\Program Files\Canon\IJ_MSetup4\MCDCHK2.EXE Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2011-04-02] ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files\Asus\AsusVibe\AsusVibeLauncher.exe () ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {CC5FC992-B0AA-47CD-9DC2-83445083CBB8} => C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll [2010-09-02] () ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {618A47A2-528B-4D9A-AFC8-97D3233511E2} => C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll [2010-09-02] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://eeepc.asus.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP07&src=IE-SearchBox SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP07&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1209219964-1995288155-3218319295-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP07&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-1209219964-1995288155-3218319295-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP07&src=IE-SearchBox BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\3ysgaq2s.default FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Extension: Avira Browser Safety - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\3ysgaq2s.default\Extensions\abs@avira.com [2015-05-21] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [827640 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1185584 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AsusService; C:\windows\system32\AsusService.exe [224680 2010-12-07] () R2 Avira.OE.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [206584 2015-05-07] (Avira Operations GmbH & Co. KG) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] () R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] () R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [107400 2015-04-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2015-04-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\windows\System32\DRIVERS\avnetflt.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG) R3 ETD; C:\windows\System32\DRIVERS\ETD.sys [102912 2010-07-21] (ELAN Microelectronic Corp.) R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2015-04-16] (Avira GmbH) S3 btwaudio; system32\drivers\btwaudio.sys [X] S3 btwavdt; \SystemRoot\system32\drivers\btwavdt.sys [X] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X] S3 btwrchid; \SystemRoot\system32\drivers\btwrchid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-22 18:44 - 2015-05-22 18:46 - 00010846 _____ () C:\Users\Petra\Desktop\FRST.txt 2015-05-22 18:43 - 2015-05-22 18:44 - 00000000 ____D () C:\FRST 2015-05-22 18:40 - 2015-05-22 18:40 - 01147392 _____ (Farbar) C:\Users\Petra\Desktop\FRST.exe 2015-05-22 18:36 - 2015-05-22 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP7200 series 2015-05-22 18:35 - 2015-05-22 18:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2015-05-22 18:35 - 2015-05-22 18:35 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool 2015-05-22 18:31 - 2015-05-22 18:31 - 00000000 ___HD () C:\windows\system32\CanonIJ Uninstaller Information 2015-05-22 18:31 - 2015-05-22 18:31 - 00000000 ___HD () C:\ProgramData\CanonBJ 2015-05-22 18:30 - 2012-04-16 05:00 - 00314880 _____ (CANON INC.) C:\windows\system32\CNMLMBA.DLL 2015-05-22 18:29 - 2015-05-22 18:29 - 00000000 ___HD () C:\Program Files\CanonBJ 2015-05-22 18:29 - 2015-05-22 18:29 - 00000000 ____D () C:\windows\system32\STRING 2015-05-22 18:29 - 2012-03-28 17:00 - 00366592 _____ (CANON INC.) C:\windows\system32\CNMNPPM.DLL 2015-05-22 18:29 - 2012-03-28 17:00 - 00035840 _____ (CANON INC.) C:\windows\system32\CNMNPUI.DLL 2015-05-22 18:28 - 2015-05-22 18:36 - 00000000 ____D () C:\Program Files\Canon 2015-05-22 18:26 - 2015-05-22 18:27 - 31423648 _____ () C:\Users\Petra\Downloads\mast-win-ip7200-1_0-mcd.exe 2015-05-21 22:53 - 2011-02-12 07:35 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\FXSCOVER.exe 2015-05-21 22:49 - 2015-04-20 04:55 - 01081344 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2015-05-21 22:49 - 2015-04-20 04:55 - 00811520 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll 2015-05-21 22:49 - 2015-04-20 04:03 - 02382336 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2015-05-21 22:49 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2015-05-21 22:47 - 2015-04-13 05:19 - 00259072 _____ (Microsoft Corporation) C:\windows\system32\services.exe 2015-05-21 22:45 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2015-05-21 22:42 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll 2015-05-21 22:39 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll 2015-05-21 22:35 - 2013-02-27 07:05 - 00101720 _____ (Microsoft Corporation) C:\windows\system32\consent.exe 2015-05-21 22:35 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2015-05-21 22:35 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll 2015-05-21 22:35 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2015-05-21 22:35 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll 2015-05-21 00:46 - 2015-05-21 00:46 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Avira 2015-05-21 00:40 - 2015-04-16 15:23 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00107400 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys 2015-05-21 00:34 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll 2015-05-21 00:34 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll 2015-05-21 00:34 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll 2015-05-21 00:34 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll 2015-05-21 00:34 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll 2015-05-21 00:33 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll 2015-05-21 00:33 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2015-05-21 00:33 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe 2015-05-21 00:33 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe 2015-05-21 00:33 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll 2015-05-21 00:33 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll 2015-05-21 00:33 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys 2015-05-21 00:33 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys 2015-05-21 00:33 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2015-05-21 00:33 - 2012-04-26 06:45 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\rdpwsx.dll 2015-05-21 00:33 - 2012-04-26 06:41 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\rdrmemptylst.exe 2015-05-21 00:32 - 2012-11-23 04:48 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe 2015-05-21 00:32 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll 2015-05-21 00:32 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll 2015-05-21 00:27 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\windows\system32\mfc42u.dll 2015-05-21 00:27 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\windows\system32\mfc42.dll 2015-05-21 00:23 - 2015-05-21 00:23 - 00001169 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-05-21 00:23 - 2011-02-23 06:47 - 00223232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys 2015-05-21 00:23 - 2011-02-23 06:47 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2015-05-21 00:23 - 2011-02-23 06:47 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2015-05-21 00:23 - 2011-02-23 06:47 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bowser.sys 2015-05-21 00:22 - 2015-05-21 00:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-05-21 00:22 - 2015-05-21 00:39 - 00000000 ____D () C:\ProgramData\Avira 2015-05-21 00:22 - 2015-05-21 00:39 - 00000000 ____D () C:\Program Files\Avira 2015-05-21 00:21 - 2015-05-21 00:21 - 00000000 ____D () C:\ProgramData\Package Cache 2015-05-21 00:21 - 2013-11-27 03:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2015-05-21 00:20 - 2015-05-21 00:20 - 04737144 _____ (Avira Operations GmbH & Co. KG) C:\Users\Petra\Downloads\avira_de_av_555d0838735c5__ws.exe 2015-05-21 00:20 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe 2015-05-21 00:20 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2015-05-21 00:20 - 2015-02-03 05:16 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2015-05-21 00:20 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys 2015-05-21 00:20 - 2015-02-03 05:16 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2015-05-21 00:20 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 02135040 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\evr.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe 2015-05-21 00:20 - 2015-02-03 05:12 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx 2015-05-21 00:20 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll 2015-05-21 00:20 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2015-05-21 00:20 - 2015-02-03 05:11 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe 2015-05-21 00:20 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll 2015-05-21 00:20 - 2015-02-03 05:09 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll 2015-05-21 00:20 - 2015-02-03 05:09 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll 2015-05-21 00:20 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll 2015-05-21 00:20 - 2015-02-03 05:08 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2015-05-21 00:20 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll 2015-05-21 00:20 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys 2015-05-21 00:20 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys 2015-05-21 00:20 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2015-05-21 00:20 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\windows\system32\winload.exe 2015-05-21 00:20 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe 2015-05-21 00:20 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\windows\system32\ci.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll 2015-05-21 00:19 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll 2015-05-21 00:19 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe 2015-05-21 00:19 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe 2015-05-21 00:19 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe 2015-05-21 00:19 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe 2015-05-21 00:18 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2015-05-21 00:18 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll 2015-05-21 00:18 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll 2015-05-21 00:18 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll 2015-05-20 23:56 - 2015-05-21 00:00 - 00004856 _____ () C:\windows\system32\TmInstall.log 2015-05-20 23:50 - 2015-05-21 00:09 - 00000000 ____D () C:\Users\Petra\AppData\Local\AviraResume 2015-05-20 23:17 - 2015-05-20 23:59 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-05-20 22:50 - 2015-05-20 22:50 - 00000000 ____D () C:\Users\Petra\Documents\Fax 2015-05-20 22:49 - 2015-05-20 22:49 - 00001200 _____ () C:\Users\Petra\Desktop\iP7200 series _3B8506000000 - Verknüpfung.lnk 2015-05-20 22:39 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll 2015-05-20 22:39 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll 2015-05-20 22:39 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll 2015-05-20 22:39 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll 2015-05-20 22:39 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe 2015-05-16 19:24 - 2015-05-22 18:43 - 00000000 ____D () C:\Users\Petra\Documents\HA ASA 4-13 2015-05-14 04:55 - 2015-05-14 04:55 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\OpenOffice 2015-05-14 04:52 - 2015-05-14 04:52 - 00001074 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk 2015-05-14 04:52 - 2015-05-14 04:52 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 2015-05-14 04:51 - 2015-05-14 04:51 - 00000000 ____D () C:\Program Files\OpenOffice 4 2015-05-14 04:45 - 2015-05-14 04:46 - 00000000 ____D () C:\Users\Petra\Desktop\OpenOffice 4.1.1 (de) Installation Files 2015-05-14 04:33 - 2015-05-14 04:39 - 164858324 _____ () C:\Users\Petra\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe 2015-05-14 04:24 - 2015-05-20 23:59 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-05-14 04:24 - 2015-05-14 04:24 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-05-14 04:24 - 2015-05-14 04:24 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-05-14 04:24 - 2015-05-14 04:24 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Mozilla 2015-05-14 04:24 - 2015-05-14 04:24 - 00000000 ____D () C:\Users\Petra\AppData\Local\Mozilla 2015-05-14 04:24 - 2015-05-14 04:24 - 00000000 ____D () C:\ProgramData\Mozilla 2015-05-14 04:21 - 2015-05-14 04:21 - 00243664 _____ () C:\Users\Petra\Downloads\Firefox Setup Stub 38.0.exe 2015-05-14 03:18 - 2015-05-14 03:18 - 00982696 _____ () C:\Users\Petra\Downloads\Firefox_37.0.1_einrichten.exe 2015-05-14 03:15 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2015-05-14 03:15 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2015-05-14 03:15 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2015-05-14 03:15 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2015-05-14 03:14 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2015-05-14 03:14 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2015-05-14 03:14 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2015-05-14 03:14 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2015-05-14 03:14 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2015-05-14 03:04 - 2015-05-14 03:04 - 00000059 _____ () C:\windows\system32\ȼ 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\windows\ConfigSetRoot 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boingo 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\ProgramData\GoBoingo 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\Program Files\Boingo 2015-05-14 03:03 - 2010-05-28 04:27 - 00005576 _____ () C:\windows\Language.ini 2015-05-14 03:01 - 2015-05-14 03:01 - 00001158 _____ () C:\Users\Public\Desktop\eBay.lnk 2015-05-14 03:01 - 2015-05-14 03:01 - 00001108 _____ () C:\Users\Public\Desktop\E-Manual.lnk 2015-05-14 02:59 - 2015-05-14 02:59 - 00000000 ____D () C:\windows\system32\Atheros_L1e 2015-05-14 02:58 - 2015-05-14 02:58 - 00000000 ____D () C:\windows\system32\SRSLabs 2015-05-14 02:58 - 2015-05-14 02:58 - 00000000 ____D () C:\windows\system32\RTCOM 2015-05-14 02:58 - 2015-05-14 02:58 - 00000000 ____D () C:\Program Files\Elantech 2015-05-14 02:57 - 2015-05-14 02:58 - 00002119 _____ () C:\RHDSetup.log 2015-05-14 02:57 - 2015-05-14 02:58 - 00000000 ___HD () C:\Program Files\Temp 2015-05-14 02:57 - 2015-05-14 02:57 - 00000000 ____D () C:\Program Files\Realtek 2015-05-14 02:57 - 2010-04-27 10:57 - 03583008 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkAPO.dll 2015-05-14 02:57 - 2010-04-27 10:57 - 01775136 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkPgExt.dll 2015-05-14 02:57 - 2010-04-27 10:57 - 01083936 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTSndMgr.cpl 2015-05-14 02:57 - 2010-04-27 10:57 - 00367136 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkApoApi.dll 2015-05-14 02:57 - 2010-04-27 10:57 - 00058400 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCoInst.dll 2015-05-14 02:57 - 2010-04-27 10:12 - 03084256 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHDA.sys 2015-05-14 02:57 - 2010-04-27 07:50 - 00299424 _____ (Fortemedia Corporation) C:\windows\system32\FMAPO.dll 2015-05-14 02:57 - 2010-04-06 08:58 - 00000008 _____ () C:\windows\system32\Drivers\rtkhdaud.dat 2015-05-14 02:57 - 2010-03-22 08:22 - 01247776 _____ (Realtek Semiconductor Corp.) C:\windows\RtlExUpd.dll 2015-05-14 02:57 - 2010-01-26 05:38 - 00145760 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTACap.dll 2015-05-14 02:57 - 2009-12-30 11:58 - 00004692 _____ () C:\windows\system32\Drivers\SamSfPa.dat 2015-05-14 02:57 - 2009-12-15 12:26 - 00357576 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEP32A.dll 2015-05-14 02:57 - 2009-12-15 12:26 - 00168648 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEED32A.dll 2015-05-14 02:57 - 2009-12-15 12:26 - 00076488 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEL32A.dll 2015-05-14 02:57 - 2009-12-15 12:26 - 00062664 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEG32A.dll 2015-05-14 02:57 - 2009-12-11 03:55 - 00293584 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DHT32.dll 2015-05-14 02:57 - 2009-12-11 03:55 - 00293584 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DAA32.dll 2015-05-14 02:57 - 2009-11-17 12:13 - 00096160 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTARen.dll 2015-05-14 02:56 - 2015-05-21 00:17 - 00063568 _____ () C:\Users\Petra\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-14 02:56 - 2015-05-21 00:11 - 00000000 ____D () C:\Users\Petra\AppData\Local\Windows Live 2015-05-14 02:56 - 2015-05-20 23:52 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium 2015-05-14 02:56 - 2015-05-14 03:04 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Adobe 2015-05-14 02:56 - 2015-05-14 03:04 - 00000000 ____D () C:\Users\Petra\AppData\Local\Adobe 2015-05-14 02:56 - 2015-05-14 03:03 - 00001413 _____ () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-05-14 02:56 - 2015-05-14 03:03 - 00000000 ____D () C:\Users\Petra\AppData\Local\VirtualStore 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Startmenü 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Netzwerkumgebung 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Druckumgebung 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Documents\Eigene Musik 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Documents\Eigene Bilder 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\AppData\Local\Verlauf 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 ____D () C:\Users\Petra 2015-05-14 02:56 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Petra\Documents\Asus WebStorage 2015-05-14 02:56 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\ASUS WebStorage 2015-05-14 02:56 - 2011-04-02 04:52 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Macromedia 2015-05-14 02:56 - 2011-04-02 04:51 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\E-Cam 2015-05-14 02:56 - 2011-04-02 04:49 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Game Park 2015-05-14 02:56 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Petra\Documents\Bluetooth Exchange Folder 2015-05-14 02:56 - 2011-04-02 04:41 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\InstallShield 2015-05-14 02:56 - 2009-07-14 06:53 - 00000020 ___SH () C:\Users\Petra\ntuser.ini 2015-05-14 02:56 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-14 02:56 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-05-14 02:54 - 2015-05-14 02:54 - 00000000 __SHD () C:\Recovery 2015-05-08 06:33 - 2014-06-28 02:21 - 00391640 __RSH () C:\bootmgr 2015-05-08 05:38 - 2011-04-02 05:09 - 00000000 ____D () C:\Users\Default\AppData\Local\Adobe 2015-05-08 05:38 - 2011-04-02 05:09 - 00000000 ____D () C:\Users\Default User\AppData\Local\Adobe 2015-05-08 05:38 - 2011-04-02 05:08 - 00001441 _____ () C:\Users\Default\Desktop\Trend Micro Titanium.lnk 2015-05-08 05:38 - 2011-04-02 05:08 - 00001441 _____ () C:\Users\Default User\Desktop\Trend Micro Titanium.lnk 2015-05-08 05:38 - 2011-04-02 05:08 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium 2015-05-08 05:38 - 2011-04-02 05:08 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default\Documents\Asus WebStorage 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default\AppData\Roaming\ASUS WebStorage 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default User\Documents\Asus WebStorage 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\ASUS WebStorage 2015-05-08 05:38 - 2011-04-02 04:54 - 00057560 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-08 05:38 - 2011-04-02 04:54 - 00057560 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-08 05:38 - 2011-04-02 04:54 - 00000000 ____D () C:\Users\Default\AppData\Local\Windows Live 2015-05-08 05:38 - 2011-04-02 04:54 - 00000000 ____D () C:\Users\Default User\AppData\Local\Windows Live 2015-05-08 05:38 - 2011-04-02 04:52 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe 2015-05-08 05:38 - 2011-04-02 04:52 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe 2015-05-08 05:38 - 2011-04-02 04:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\E-Cam 2015-05-08 05:38 - 2011-04-02 04:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\E-Cam 2015-05-08 05:38 - 2011-04-02 04:49 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Game Park 2015-05-08 05:38 - 2011-04-02 04:49 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Game Park 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default\Documents\Bluetooth Exchange Folder 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default\AppData\Local\Broadcom 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default User\Documents\Bluetooth Exchange Folder 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default User\AppData\Local\Broadcom 2015-05-08 05:38 - 2011-04-02 04:41 - 00000000 ____D () C:\Users\Default\AppData\Roaming\InstallShield 2015-05-08 05:38 - 2011-04-02 04:41 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\InstallShield 2015-05-08 05:37 - 2015-05-22 18:21 - 01320220 _____ () C:\windows\WindowsUpdate.log ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-22 17:18 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET 2015-05-22 17:00 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-22 17:00 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-22 16:44 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-05-22 16:44 - 2009-07-14 06:39 - 00053795 _____ () C:\windows\setupact.log 2015-05-22 16:44 - 2009-07-14 06:33 - 00284480 _____ () C:\windows\system32\FNTCACHE.DAT 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nl-NL 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\it-IT 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fr-FR 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE 2015-05-22 15:12 - 2011-02-16 17:44 - 00692768 _____ () C:\windows\system32\perfh013.dat 2015-05-22 15:12 - 2011-02-16 17:44 - 00133360 _____ () C:\windows\system32\perfc013.dat 2015-05-22 15:12 - 2011-02-16 17:39 - 00691422 _____ () C:\windows\system32\perfh010.dat 2015-05-22 15:12 - 2011-02-16 17:39 - 00127758 _____ () C:\windows\system32\perfc010.dat 2015-05-22 15:12 - 2009-07-27 12:11 - 03971856 _____ () C:\windows\system32\PerfStringBackup.INI 2015-05-22 15:10 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\LogFiles 2015-05-22 13:23 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender 2015-05-21 22:21 - 2011-04-02 04:30 - 00415588 _____ () C:\windows\PFRO.log 2015-05-20 23:52 - 2011-04-02 05:07 - 00000000 ____D () C:\ProgramData\Trend Micro 2015-05-20 23:07 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp 2015-05-17 09:01 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache 2015-05-17 09:00 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\WCN 2015-05-17 09:00 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\Printing_Admin_Scripts 2015-05-17 09:00 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\MUI 2015-05-17 09:00 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\com 2015-05-14 03:03 - 2011-04-02 04:41 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-05-14 03:03 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-14 03:01 - 2011-04-02 04:48 - 00000000 ____D () C:\Program Files\Asus 2015-05-14 02:59 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\restore 2015-05-14 02:58 - 2011-04-02 04:44 - 00014676 _____ () C:\windows\DPINST.LOG 2015-05-14 02:57 - 2011-04-02 04:48 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2015-05-14 02:54 - 2009-07-27 12:56 - 00000000 ____D () C:\windows\panther 2015-05-14 02:54 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\Recovery 2015-05-08 06:33 - 2009-07-14 06:57 - 00029696 ___SH () C:\windows\system32\config\BCD-Template.LOG 2015-05-08 06:33 - 2009-07-14 06:52 - 00032768 _____ () C:\windows\system32\config\BCD-Template 2015-05-08 05:38 - 2009-07-27 11:57 - 00008134 _____ () C:\windows\TSSysprep.log 2015-05-08 05:38 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2015-05-08 05:35 - 2009-07-14 06:34 - 00004822 _____ () C:\windows\DtcInstall.log ==================== Files in the root of some directories ======= 2011-04-02 04:49 - 2010-03-03 00:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Some files in TEMP: ==================== C:\Users\Petra\AppData\Local\Temp\avgnt.exe C:\Users\Petra\AppData\Local\Temp\MSETUP4.EXE ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-17 08:49 Addition Editor: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-05-2015 01 Ran by Petra at 2015-05-22 18:47:23 Running from C:\Users\Petra\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1209219964-1995288155-3218319295-500 - Administrator - Disabled) Gast (S-1-5-21-1209219964-1995288155-3218319295-501 - Limited - Disabled) Petra (S-1-5-21-1209219964-1995288155-3218319295-1000 - Administrator - Enabled) => C:\Users\Petra ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Acrobat.com (HKLM\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM\...\Adobe AIR) (Version: - Adobe Systems Inc.) Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Reader 9.1 MUI (HKLM\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.1.0 - Adobe Systems Incorporated) ASUS WebStorage (HKLM\...\ASUS WebStorage) (Version: - eCareme Technologies, Inc.) ASUSUpdate for Eee PC (HKLM\...\{587178E7-B1DF-494E-9838-FA4DD36E873C}) (Version: 1.06.02 - ASUSTeK Computer Inc.) AsusVibe2.0 (HKLM\...\Asus Vibe2.0) (Version: - ASUSTEK) Atheros Client Installation Program (HKLM\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.0 - Atheros) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: - Atheros Communications Inc.) Avira (HKLM\...\{022ef99f-0db2-4efc-964d-5dd2da3151f6}) (Version: - Avira Operations GmbH & Co. KG) Avira (Version: - Avira Operations GmbH & Co. KG) Hidden Avira Antivirus (HKLM\...\Avira Antivirus) (Version: - Avira Operations GmbH & Co. KG) Boingo Wi-Fi (HKLM\...\{84C2B80B-64A2-4B22-93EC-F30C3D6BF7D8}) (Version: 1.7.0048 - Boingo Wireless, Inc.) Canon IJ Network Tool (HKLM\...\Canon_IJ_Network_UTILITY) (Version: 3.1.0 - Canon Inc.) Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version: - Canon Inc.) CapsHook (HKLM\...\{4B5092B6-F231-4D18-83BC-2618B729CA45}) (Version: - AsusTek Computer) Chicken Invaders 2 (HKLM\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}) (Version: - Oberon Media) Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden E-Cam (HKLM\...\{185AFA7A-F63E-450B-94AA-011CAC18090E}) (Version: - AzureWave) Eee Docking 3.8.3 (HKLM\...\Eee Docking_is1) (Version: 3.8.3 - ASUSTek Computer Inc.) EeeSplendid (HKLM\...\{6333FC29-BFE5-4024-AC78-958A1A7555D1}) (Version: - ASUS) EeeSplendid (Version: - ASUS) Hidden ETDWare PS/2-x86 (HKLM\...\Elantech) (Version: - ELAN Microelectronics Corp.) FontResizer (HKLM\...\InstallShield_{17780F99-A9DF-450B-81B3-6781B20A17A8}) (Version: 1.01.0011 - ASUSTek) FontResizer (Version: 1.01.0011 - ASUSTek) Hidden Galerie de photos Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM\...\{D44AA979-47C2-4BC0-A860-09A54224EA44}_is1) (Version: - Oberon Media, Inc.) Hotkey Service (HKLM\...\{71C0E38E-09F2-4386-9977-404D4F6640CD}) (Version: 1.37 - AsusTek Computer Inc.) InstantOn (HKLM\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 1.0.2 - ASUS) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: - Intel Corporation) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LiveUpdate (HKLM\...\{38E5A3B1-ADF1-47E0-8024-76310A30EB36}) (Version: 1.28 - AsusTek Computer Inc.) LocaleMe (HKLM\...\{F58C1D44-4AC9-48E8-9049-7A6CDFCB415C}) (Version: 1.3 - ASUS) Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 38.0.1 (x86 de) (HKLM\...\Mozilla Firefox 38.0.1 (x86 de)) (Version: 38.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 38.0 - Mozilla) OpenOffice 4.1.1 (HKLM\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Raccolta foto di Windows Live (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Ralink RT2860 Wireless LAN Card (HKLM\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: - Ralink) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver (HKLM\...\{9D3D8C60-A55F-4fed-B2B9-173F09590E16}) (Version: 1.00.0159 - REALTEK Semiconductor Corp.) Super Hybrid Engine (HKLM\...\{88F08F98-12BC-4613-81A2-8F9B88CFC73E}) (Version: 2.17 - AsusTek Computer) Windows Driver Package - Broadcom Bluetooth (07/17/2009 (HKLM\...\B41C7C96D83162A676DA7365ADEFD6C1AF62A4EE) (Version: 07/17/2009 - Broadcom) Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0) (HKLM\...\B5C82F3814F82FB37F1513B3185399BD88892B08) (Version: 07/29/2009 6.1.7100.0 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 (HKLM\...\BF20603967CFDCB2BBF91950E8A56DFBC5C833FE) (Version: 07/28/2009 - Broadcom) Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Restore Points ========================= 14-05-2015 04:46:27 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 14-05-2015 04:49:33 OpenOffice 4.1.1 wird installiert 17-05-2015 08:56:34 Sprachpaketdeinstallation 21-05-2015 22:28:23 Windows Update 22-05-2015 15:12:32 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (Whitelisted) ============== 2011-04-02 04:53 - 2010-12-07 18:19 - 00224680 _____ () C:\windows\system32\AsusService.exe 2015-05-07 16:37 - 2015-05-07 16:37 - 00245760 _____ () C:\Program Files\Avira\Launcher\System.ComponentModel.Composition.dll 2010-09-02 13:08 - 2010-09-02 13:08 - 00118784 _____ () C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll 2009-03-02 04:08 - 2009-03-02 04:08 - 00003584 _____ () C:\Program Files\ASUS\ASUS WebStorage\\LogicNP.PropSheetExtensionHelper.dll 2011-03-11 03:05 - 2011-03-11 03:05 - 00181664 _____ () C:\Program Files\Asus\LiveUpdate\Parser.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Control Panel\Desktop\\Wallpaper -> %windir%\web\wallpaper\windows\img0.jpg DNS Servers: ==================== MSCONFIG/TASK MANAGER Error getting == (Currently there is no automatic fix for this section.) ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{F1B2F891-6884-44D8-886F-4B0BAC21F0DC}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe FirewallRules: [{A5AC6AF6-5D38-4B99-88B2-7778481F3F22}] => (Allow) LPort=2869 FirewallRules: [{33B61685-5528-4B59-BB27-250624D17D8D}] => (Allow) LPort=1900 FirewallRules: [{6ADDE698-A413-4F88-A103-6CDF853ED581}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{FA4570A9-B65F-4A0D-BCBF-39C158A5C94C}] => (Allow) C:\Program Files\Windows Live\Mesh\MOE.exe FirewallRules: [{B4843F82-6626-495B-8345-8F60E29A66F1}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{9354BC56-8D1B-4114-B4CC-D94DA8C86A92}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/14/2015 03:03:39 AM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail (3420) WindowsMail0: Die Sicherung wurde abgebrochen, weil sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen wurde. Error: (05/14/2015 02:59:09 AM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {fff6282d-29e8-49b1-825c-36115f2a4ee8} System errors: ============= Error: (05/22/2015 06:42:47 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "PETRA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (05/22/2015 06:42:05 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "PETRA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (05/22/2015 06:40:58 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "PETRA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (05/22/2015 06:35:34 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "PETRA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (05/22/2015 04:46:56 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (05/22/2015 04:44:35 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "PETRA-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (05/22/2015 04:44:35 PM) (Source: Server) (EventID: 2505) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{22D51E9B-6C03-4622-813E-07960C180CE7} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (05/22/2015 04:44:29 PM) (Source: NetBT) (EventID: 4321) (User: ) Description: Der Name "PETRA-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (05/22/2015 04:41:58 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Windows Modules Installer konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (05/22/2015 04:39:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0902 fehlgeschlagen: Sicherheitsupdate für Windows 7 (KB3046306) Microsoft Office: ========================= Error: (05/14/2015 03:03:39 AM) (Source: ESENT) (EventID: 215) (User: ) Description: WinMail3420WindowsMail0: Error: (05/14/2015 02:59:09 AM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {fff6282d-29e8-49b1-825c-36115f2a4ee8} ==================== Memory info =========================== Processor: Intel(R) Atom(TM) CPU N455 @ 1.66GHz Percentage of memory in use: 81% Total physical RAM: 1014.18 MB Available physical RAM: 187.1 MB Total Pagefile: 2038.18 MB Available Pagefile: 812.46 MB Total Virtual: 2047.88 MB Available Virtual: 1895.1 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:100 GB) (Free:74.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:117.87 GB) (Free:117.77 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 3DA54736) Partition 1: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=15 GB) - (Type=1B) Partition 3: (Not Active) - (Size=117.9 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=16 MB) - (Type=EF) Liebe Grüße Parim |
Trojaner 'TR/Crypt.XPACK.Gen'

Posten in CODE-Tags

Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| ![]() Trojaner 'TR/Crypt.XPACK.Gen' Hallo Schrauber, ich weiß nicht wie ich das mit der # machen soll. Wenn ich, wie jetzt, im Antwortenmodus bin, sehe ich keine Raute. Wenn ich nicht im Antwortenmodus bin, sehe ich rechts in der Ecke von deiner Antwort eine Raute und daneben eine Zahl. Die Zahl kann ich anklicken, aber die Raute nicht. Habe ich dich falsch verstanden oder mache ich was falsch? LG und Danke, Parim Hallo Schrauber, hier kommen die Antworten der ganzen Scans. Diesmal mit Rauteklick. Ich konnte das Bild gar nicht sehen, wenn ich mit dem kleinen Netbook auf Trojaner-Board gegangen bin. Als ich mit dem Notebook reingegangen bin, habe ich es gesehen. Gruß Parim [CODE] Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 27.05.2015 Suchlauf-Zeit: 20:02:08 Logdatei: mbam.txt Administrator: Ja Version: Malware Datenbank: v2015.05.27.04 Rootkit Datenbank: v2015.05.24.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Petra Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 303544 Verstrichene Zeit: 1 Std, 1 Min, 57 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente gefunden) Module: 0 (Keine schädliche Elemente gefunden) Registrierungsschlüssel: 0 (Keine schädliche Elemente gefunden) Registrierungswerte: 0 (Keine schädliche Elemente gefunden) Registrierungsdaten: 0 (Keine schädliche Elemente gefunden) Ordner: 0 (Keine schädliche Elemente gefunden) Dateien: 1 PUP.Optional.BundleInstaller.A, C:\Users\Petra\Downloads\Firefox_37.0.1_einrichten.exe, In Quarantäne, [4b551880f2985fd74934e36cd032c040], Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end)[/CODE Code:
ATTFilter # AdwCleaner v4.205 - Bericht erstellt 27/05/2015 um 22:11:14 # Aktualisiert 21/05/2015 von Xplode # Datenbank : 2015-05-25.3 [Server] # Betriebssystem : Windows 7 Starter Service Pack 1 (x86) # Benutzername : Petra - PETRA-PC # Gestarted von : C:\Users\Petra\Downloads\AdwCleaner_4.205.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Internetbrowser ] ***** -\\ Internet Explorer v9.0.8112.16421 -\\ Mozilla Firefox v38.0.1 (x86 de) ************************* AdwCleaner[R0].txt - [839 Bytes] - [27/05/2015 22:07:47] AdwCleaner[S0].txt - [760 Bytes] - [27/05/2015 22:11:14] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [818 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.8.1 (05.27.2015:1) OS: Windows 7 Starter x86 Ran by Petra on 27.05.2015 at 22:33:10,53 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.05.2015 at 22:38:09,36 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Ran by Petra (administrator) on PETRA-PC on 27-05-2015 22:41:14 Running from C:\Users\Petra\Desktop Loaded Profiles: Petra (Available Profiles: Petra) Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Windows\System32\hkcmd.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.OE.Systray.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [EeeSplendidAgent] => C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101288 2010-12-07] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1248176 2010-12-07] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [412600 2010-11-15] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2011-03-11] (AsusTek Computer Inc.) HKLM-x32\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS) HKLM-x32\...\Run: [Eee Docking] => C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [414384 2011-01-07] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files\ASUS\ASUS WebStorage\\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [141848 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [173592 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [150552 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9177632 2010-04-27] (Realtek Semiconductor) HKLM-x32\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [548744 2010-06-10] (ELAN Microelectronic Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] => C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2015-05-14] () HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2011-04-02] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.OE.Systray.exe [128760 2015-05-07] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [728312 2015-04-16] (Avira Operations GmbH & Co. KG) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2011-04-02] ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files\Asus\AsusVibe\AsusVibeLauncher.exe () ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {CC5FC992-B0AA-47CD-9DC2-83445083CBB8} => C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll [2010-09-02] () ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {618A47A2-528B-4D9A-AFC8-97D3233511E2} => C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll [2010-09-02] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://eeepc.asus.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\3ysgaq2s.default FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Extension: Avira Browser Safety - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\3ysgaq2s.default\Extensions\abs@avira.com [2015-05-27] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [827640 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1185584 2015-04-16] (Avira Operations GmbH & Co. KG) S2 AsusService; C:\windows\system32\AsusService.exe [224680 2010-12-07] () R2 Avira.OE.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [206584 2015-05-07] (Avira Operations GmbH & Co. KG) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] () R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] () R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [107400 2015-04-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2015-04-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\windows\System32\DRIVERS\avnetflt.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG) R3 ETD; C:\windows\System32\DRIVERS\ETD.sys [102912 2010-07-21] (ELAN Microelectronic Corp.) R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation) R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2015-04-16] (Avira GmbH) S3 btwaudio; system32\drivers\btwaudio.sys [X] S3 btwavdt; \SystemRoot\system32\drivers\btwavdt.sys [X] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X] S3 btwrchid; \SystemRoot\system32\drivers\btwrchid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-27 22:38 - 2015-05-27 22:38 - 00000595 _____ () C:\Users\Petra\Desktop\JRT.txt 2015-05-27 22:33 - 2015-05-27 22:33 - 00000207 _____ () C:\windows\tweaking.com-regbackup-PETRA-PC-Windows-7-Starter-(32-bit).dat 2015-05-27 22:33 - 2015-05-27 22:33 - 00000000 ____D () C:\RegBackup 2015-05-27 22:32 - 2015-05-27 22:32 - 02946603 _____ (Thisisu) C:\Users\Petra\Downloads\JRT.exe 2015-05-27 22:15 - 2015-05-27 22:15 - 00000897 _____ () C:\Users\Petra\Desktop\AdwCleaner[S0].txt 2015-05-27 22:07 - 2015-05-27 22:11 - 00000000 ____D () C:\AdwCleaner 2015-05-27 22:06 - 2015-05-27 22:06 - 02222592 _____ () C:\Users\Petra\Downloads\AdwCleaner_4.205.exe 2015-05-27 21:26 - 2015-05-27 21:26 - 00001320 _____ () C:\Users\Petra\Desktop\mbam.txt 2015-05-27 20:01 - 2015-05-27 21:23 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-27 20:00 - 2015-05-27 20:00 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-05-27 20:00 - 2015-05-27 20:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-05-27 20:00 - 2015-05-27 20:00 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-05-27 20:00 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2015-05-27 20:00 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2015-05-27 20:00 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2015-05-27 19:55 - 2015-05-27 19:57 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Petra\Downloads\mbam-setup- 2015-05-27 19:41 - 2015-05-27 19:41 - 00000000 ____D () C:\Program Files\Microsoft.NET 2015-05-23 00:02 - 2015-05-23 00:07 - 00009451 _____ () C:\windows\IE11_main.log 2015-05-22 18:47 - 2015-05-22 18:49 - 00017270 _____ () C:\Users\Petra\Desktop\Addition.txt 2015-05-22 18:44 - 2015-05-27 22:41 - 00009581 _____ () C:\Users\Petra\Desktop\FRST.txt 2015-05-22 18:43 - 2015-05-27 22:41 - 00000000 ____D () C:\FRST 2015-05-22 18:40 - 2015-05-22 18:40 - 01147392 _____ (Farbar) C:\Users\Petra\Desktop\FRST.exe 2015-05-22 18:36 - 2015-05-22 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP7200 series 2015-05-22 18:35 - 2015-05-22 18:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities 2015-05-22 18:35 - 2015-05-22 18:35 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool 2015-05-22 18:31 - 2015-05-22 18:31 - 00000000 ___HD () C:\windows\system32\CanonIJ Uninstaller Information 2015-05-22 18:31 - 2015-05-22 18:31 - 00000000 ___HD () C:\ProgramData\CanonBJ 2015-05-22 18:30 - 2012-04-16 05:00 - 00314880 _____ (CANON INC.) C:\windows\system32\CNMLMBA.DLL 2015-05-22 18:29 - 2015-05-22 18:29 - 00000000 ___HD () C:\Program Files\CanonBJ 2015-05-22 18:29 - 2015-05-22 18:29 - 00000000 ____D () C:\windows\system32\STRING 2015-05-22 18:29 - 2012-03-28 17:00 - 00366592 _____ (CANON INC.) C:\windows\system32\CNMNPPM.DLL 2015-05-22 18:29 - 2012-03-28 17:00 - 00035840 _____ (CANON INC.) C:\windows\system32\CNMNPUI.DLL 2015-05-22 18:28 - 2015-05-22 18:36 - 00000000 ____D () C:\Program Files\Canon 2015-05-22 18:26 - 2015-05-22 18:27 - 31423648 _____ () C:\Users\Petra\Downloads\mast-win-ip7200-1_0-mcd.exe 2015-05-21 22:53 - 2011-02-12 07:35 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\FXSCOVER.exe 2015-05-21 22:49 - 2015-04-20 04:55 - 01081344 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2015-05-21 22:49 - 2015-04-20 04:55 - 00811520 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll 2015-05-21 22:49 - 2015-04-20 04:03 - 02382336 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2015-05-21 22:49 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2015-05-21 22:47 - 2015-04-13 05:19 - 00259072 _____ (Microsoft Corporation) C:\windows\system32\services.exe 2015-05-21 22:45 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2015-05-21 22:42 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll 2015-05-21 22:39 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll 2015-05-21 22:35 - 2013-02-27 07:05 - 00101720 _____ (Microsoft Corporation) C:\windows\system32\consent.exe 2015-05-21 22:35 - 2013-02-27 06:55 - 12872704 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2015-05-21 22:35 - 2013-02-27 06:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll 2015-05-21 22:35 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2015-05-21 22:35 - 2013-02-27 06:49 - 00047104 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll 2015-05-21 00:46 - 2015-05-21 00:46 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Avira 2015-05-21 00:40 - 2015-04-16 15:23 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00107400 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys 2015-05-21 00:40 - 2015-04-16 15:23 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys 2015-05-21 00:34 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll 2015-05-21 00:34 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll 2015-05-21 00:34 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll 2015-05-21 00:34 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll 2015-05-21 00:34 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll 2015-05-21 00:33 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll 2015-05-21 00:33 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2015-05-21 00:33 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe 2015-05-21 00:33 - 2014-07-17 03:39 - 00304128 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe 2015-05-21 00:33 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\windows\system32\aaclient.dll 2015-05-21 00:33 - 2014-07-17 03:39 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll 2015-05-21 00:33 - 2014-07-17 03:03 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys 2015-05-21 00:33 - 2014-07-17 03:02 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys 2015-05-21 00:33 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2015-05-21 00:33 - 2012-04-26 06:45 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\rdpwsx.dll 2015-05-21 00:33 - 2012-04-26 06:41 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\rdrmemptylst.exe 2015-05-21 00:32 - 2012-11-23 04:48 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\taskhost.exe 2015-05-21 00:32 - 2012-10-09 19:40 - 00193536 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll 2015-05-21 00:32 - 2012-10-09 19:40 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll 2015-05-21 00:27 - 2014-12-06 05:50 - 00242688 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll 2015-05-21 00:27 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2015-05-21 00:27 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll 2015-05-21 00:27 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll 2015-05-21 00:27 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe 2015-05-21 00:27 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-05-21 00:27 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-05-21 00:27 - 2012-10-03 18:42 - 00156672 _____ (Microsoft Corporation) C:\windows\system32\ncsi.dll 2015-05-21 00:27 - 2012-10-03 18:42 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\nlaapi.dll 2015-05-21 00:27 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\windows\system32\mfc42u.dll 2015-05-21 00:27 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\windows\system32\mfc42.dll 2015-05-21 00:23 - 2015-05-21 00:23 - 00001169 _____ () C:\Users\Public\Desktop\Avira.lnk 2015-05-21 00:23 - 2013-06-26 00:56 - 00527064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys 2015-05-21 00:23 - 2012-11-29 00:57 - 00047720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfLdr.sys 2015-05-21 00:23 - 2012-11-29 00:57 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\Wdfres.dll 2015-05-21 00:23 - 2012-11-29 00:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf 2015-05-21 00:23 - 2011-02-23 06:47 - 00223232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys 2015-05-21 00:23 - 2011-02-23 06:47 - 00123904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2015-05-21 00:23 - 2011-02-23 06:47 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2015-05-21 00:23 - 2011-02-23 06:47 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bowser.sys 2015-05-21 00:22 - 2015-05-21 00:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-05-21 00:22 - 2015-05-21 00:39 - 00000000 ____D () C:\ProgramData\Avira 2015-05-21 00:22 - 2015-05-21 00:39 - 00000000 ____D () C:\Program Files\Avira 2015-05-21 00:21 - 2015-05-21 00:21 - 00000000 ____D () C:\ProgramData\Package Cache 2015-05-21 00:21 - 2015-02-04 04:54 - 00318464 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll 2015-05-21 00:21 - 2014-12-19 03:34 - 00116224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys 2015-05-21 00:21 - 2013-11-27 03:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2015-05-21 00:21 - 2013-11-27 03:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2015-05-21 00:20 - 2015-05-21 00:20 - 04737144 _____ (Avira Operations GmbH & Co. KG) C:\Users\Petra\Downloads\avira_de_av_555d0838735c5__ws.exe 2015-05-21 00:20 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe 2015-05-21 00:20 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2015-05-21 00:20 - 2015-02-03 05:16 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2015-05-21 00:20 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys 2015-05-21 00:20 - 2015-02-03 05:16 - 00067512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2015-05-21 00:20 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 02135040 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01061376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00550912 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\evr.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00400896 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00259584 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00100352 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\smss.exe 2015-05-21 00:20 - 2015-02-03 05:12 - 00065536 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\pcadm.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00017408 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\windows\system32\msmmsp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll 2015-05-21 00:20 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx 2015-05-21 00:20 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll 2015-05-21 00:20 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL 2015-05-21 00:20 - 2015-02-03 05:11 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\pcawrk.exe 2015-05-21 00:20 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\windows\system32\pcalua.exe 2015-05-21 00:20 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\windows\system32\pcaevts.dll 2015-05-21 00:20 - 2015-02-03 05:09 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll 2015-05-21 00:20 - 2015-02-03 05:09 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll 2015-05-21 00:20 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll 2015-05-21 00:20 - 2015-02-03 05:08 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2015-05-21 00:20 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll 2015-05-21 00:20 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys 2015-05-21 00:20 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys 2015-05-21 00:20 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2015-05-21 00:20 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\windows\system32\winload.exe 2015-05-21 00:20 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe 2015-05-21 00:20 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\windows\system32\ci.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00428032 _____ (Microsoft Corporation) C:\windows\system32\secproc.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00423936 _____ (Microsoft Corporation) C:\windows\system32\secproc_isv.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp_isv.dll 2015-05-21 00:19 - 2013-12-04 04:03 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\secproc_ssp.dll 2015-05-21 00:19 - 2013-12-04 04:02 - 00390144 _____ (Microsoft Corporation) C:\windows\system32\msdrm.dll 2015-05-21 00:19 - 2013-12-04 03:54 - 00594944 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_isv.exe 2015-05-21 00:19 - 2013-12-04 03:54 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\RMActivate.exe 2015-05-21 00:19 - 2013-12-04 03:54 - 00510976 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp.exe 2015-05-21 00:19 - 2013-12-04 03:54 - 00508928 _____ (Microsoft Corporation) C:\windows\system32\RMActivate_ssp_isv.exe 2015-05-21 00:18 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2015-05-21 00:18 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll 2015-05-21 00:18 - 2014-12-08 04:46 - 00308224 _____ (Microsoft Corporation) C:\windows\system32\scesrv.dll 2015-05-21 00:18 - 2014-10-14 03:50 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll 2015-05-20 23:56 - 2015-05-21 00:00 - 00004856 _____ () C:\windows\system32\TmInstall.log 2015-05-20 23:50 - 2015-05-21 00:09 - 00000000 ____D () C:\Users\Petra\AppData\Local\AviraResume 2015-05-20 23:17 - 2015-05-20 23:59 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-05-20 22:50 - 2015-05-20 22:50 - 00000000 ____D () C:\Users\Petra\Documents\Fax 2015-05-20 22:49 - 2015-05-20 22:49 - 00001200 _____ () C:\Users\Petra\Desktop\iP7200 series _3B8506000000 - Verknüpfung.lnk 2015-05-20 22:39 - 2014-10-03 03:45 - 01177088 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll 2015-05-20 22:39 - 2014-10-03 03:45 - 00248832 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll 2015-05-20 22:39 - 2014-10-03 03:45 - 00214016 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll 2015-05-20 22:39 - 2014-10-03 03:45 - 00145920 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll 2015-05-20 22:39 - 2014-10-03 03:44 - 00198656 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe 2015-05-16 19:24 - 2015-05-22 23:56 - 00000000 ____D () C:\Users\Petra\Documents\HA ASA 4-13 2015-05-14 04:55 - 2015-05-14 04:55 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\OpenOffice 2015-05-14 04:52 - 2015-05-14 04:52 - 00001074 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.1.lnk 2015-05-14 04:52 - 2015-05-14 04:52 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1 2015-05-14 04:51 - 2015-05-14 04:51 - 00000000 ____D () C:\Program Files\OpenOffice 4 2015-05-14 04:45 - 2015-05-14 04:46 - 00000000 ____D () C:\Users\Petra\Desktop\OpenOffice 4.1.1 (de) Installation Files 2015-05-14 04:33 - 2015-05-14 04:39 - 164858324 _____ () C:\Users\Petra\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe 2015-05-14 04:24 - 2015-05-20 23:59 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-05-14 04:24 - 2015-05-14 04:24 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-05-14 04:24 - 2015-05-14 04:24 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-05-14 04:24 - 2015-05-14 04:24 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Mozilla 2015-05-14 04:24 - 2015-05-14 04:24 - 00000000 ____D () C:\Users\Petra\AppData\Local\Mozilla 2015-05-14 04:24 - 2015-05-14 04:24 - 00000000 ____D () C:\ProgramData\Mozilla 2015-05-14 04:21 - 2015-05-14 04:21 - 00243664 _____ () C:\Users\Petra\Downloads\Firefox Setup Stub 38.0.exe 2015-05-14 03:15 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2015-05-14 03:15 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2015-05-14 03:15 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll 2015-05-14 03:15 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll 2015-05-14 03:14 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2015-05-14 03:14 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\windows\system32\wups.dll 2015-05-14 03:14 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2015-05-14 03:14 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll 2015-05-14 03:14 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe 2015-05-14 03:04 - 2015-05-14 03:04 - 00000059 _____ () C:\windows\system32\ȼ 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\windows\ConfigSetRoot 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boingo 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\ProgramData\GoBoingo 2015-05-14 03:03 - 2015-05-14 03:03 - 00000000 ____D () C:\Program Files\Boingo 2015-05-14 03:03 - 2010-05-28 04:27 - 00005576 _____ () C:\windows\Language.ini 2015-05-14 03:01 - 2015-05-14 03:01 - 00001108 _____ () C:\Users\Public\Desktop\E-Manual.lnk 2015-05-14 02:59 - 2015-05-14 02:59 - 00000000 ____D () C:\windows\system32\Atheros_L1e 2015-05-14 02:58 - 2015-05-14 02:58 - 00000000 ____D () C:\windows\system32\SRSLabs 2015-05-14 02:58 - 2015-05-14 02:58 - 00000000 ____D () C:\windows\system32\RTCOM 2015-05-14 02:58 - 2015-05-14 02:58 - 00000000 ____D () C:\Program Files\Elantech 2015-05-14 02:57 - 2015-05-14 02:58 - 00002119 _____ () C:\RHDSetup.log 2015-05-14 02:57 - 2015-05-14 02:58 - 00000000 ___HD () C:\Program Files\Temp 2015-05-14 02:57 - 2015-05-14 02:57 - 00000000 ____D () C:\Program Files\Realtek 2015-05-14 02:57 - 2010-04-27 10:57 - 03583008 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkAPO.dll 2015-05-14 02:57 - 2010-04-27 10:57 - 01775136 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkPgExt.dll 2015-05-14 02:57 - 2010-04-27 10:57 - 01083936 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTSndMgr.cpl 2015-05-14 02:57 - 2010-04-27 10:57 - 00367136 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkApoApi.dll 2015-05-14 02:57 - 2010-04-27 10:57 - 00058400 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCoInst.dll 2015-05-14 02:57 - 2010-04-27 10:12 - 03084256 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHDA.sys 2015-05-14 02:57 - 2010-04-27 07:50 - 00299424 _____ (Fortemedia Corporation) C:\windows\system32\FMAPO.dll 2015-05-14 02:57 - 2010-04-06 08:58 - 00000008 _____ () C:\windows\system32\Drivers\rtkhdaud.dat 2015-05-14 02:57 - 2010-03-22 08:22 - 01247776 _____ (Realtek Semiconductor Corp.) C:\windows\RtlExUpd.dll 2015-05-14 02:57 - 2010-01-26 05:38 - 00145760 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTACap.dll 2015-05-14 02:57 - 2009-12-30 11:58 - 00004692 _____ () C:\windows\system32\Drivers\SamSfPa.dat 2015-05-14 02:57 - 2009-12-15 12:26 - 00357576 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEP32A.dll 2015-05-14 02:57 - 2009-12-15 12:26 - 00168648 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEED32A.dll 2015-05-14 02:57 - 2009-12-15 12:26 - 00076488 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEL32A.dll 2015-05-14 02:57 - 2009-12-15 12:26 - 00062664 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEG32A.dll 2015-05-14 02:57 - 2009-12-11 03:55 - 00293584 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DHT32.dll 2015-05-14 02:57 - 2009-12-11 03:55 - 00293584 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DAA32.dll 2015-05-14 02:57 - 2009-11-17 12:13 - 00096160 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTARen.dll 2015-05-14 02:56 - 2015-05-21 00:17 - 00063568 _____ () C:\Users\Petra\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-14 02:56 - 2015-05-21 00:11 - 00000000 ____D () C:\Users\Petra\AppData\Local\Windows Live 2015-05-14 02:56 - 2015-05-20 23:52 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium 2015-05-14 02:56 - 2015-05-14 03:04 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Adobe 2015-05-14 02:56 - 2015-05-14 03:04 - 00000000 ____D () C:\Users\Petra\AppData\Local\Adobe 2015-05-14 02:56 - 2015-05-14 03:03 - 00001413 _____ () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-05-14 02:56 - 2015-05-14 03:03 - 00000000 ____D () C:\Users\Petra\AppData\Local\VirtualStore 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Startmenü 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Netzwerkumgebung 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Druckumgebung 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Documents\Eigene Musik 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\Documents\Eigene Bilder 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 _SHDL () C:\Users\Petra\AppData\Local\Verlauf 2015-05-14 02:56 - 2015-05-14 02:56 - 00000000 ____D () C:\Users\Petra 2015-05-14 02:56 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Petra\Documents\Asus WebStorage 2015-05-14 02:56 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\ASUS WebStorage 2015-05-14 02:56 - 2011-04-02 04:52 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Macromedia 2015-05-14 02:56 - 2011-04-02 04:51 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\E-Cam 2015-05-14 02:56 - 2011-04-02 04:49 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Game Park 2015-05-14 02:56 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Petra\Documents\Bluetooth Exchange Folder 2015-05-14 02:56 - 2011-04-02 04:41 - 00000000 ____D () C:\Users\Petra\AppData\Roaming\InstallShield 2015-05-14 02:56 - 2009-07-14 06:53 - 00000020 ___SH () C:\Users\Petra\ntuser.ini 2015-05-14 02:56 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-14 02:56 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\Petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-05-14 02:54 - 2015-05-14 02:54 - 00000000 __SHD () C:\Recovery 2015-05-08 06:33 - 2014-06-28 02:21 - 00391640 __RSH () C:\bootmgr 2015-05-08 05:38 - 2011-04-02 05:09 - 00000000 ____D () C:\Users\Default\AppData\Local\Adobe 2015-05-08 05:38 - 2011-04-02 05:09 - 00000000 ____D () C:\Users\Default User\AppData\Local\Adobe 2015-05-08 05:38 - 2011-04-02 05:08 - 00001441 _____ () C:\Users\Default\Desktop\Trend Micro Titanium.lnk 2015-05-08 05:38 - 2011-04-02 05:08 - 00001441 _____ () C:\Users\Default User\Desktop\Trend Micro Titanium.lnk 2015-05-08 05:38 - 2011-04-02 05:08 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium 2015-05-08 05:38 - 2011-04-02 05:08 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default\Documents\Asus WebStorage 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default\AppData\Roaming\ASUS WebStorage 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default User\Documents\Asus WebStorage 2015-05-08 05:38 - 2011-04-02 05:05 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\ASUS WebStorage 2015-05-08 05:38 - 2011-04-02 04:54 - 00057560 _____ () C:\Users\Default\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-08 05:38 - 2011-04-02 04:54 - 00057560 _____ () C:\Users\Default User\AppData\Local\GDIPFONTCACHEV1.DAT 2015-05-08 05:38 - 2011-04-02 04:54 - 00000000 ____D () C:\Users\Default\AppData\Local\Windows Live 2015-05-08 05:38 - 2011-04-02 04:54 - 00000000 ____D () C:\Users\Default User\AppData\Local\Windows Live 2015-05-08 05:38 - 2011-04-02 04:52 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe 2015-05-08 05:38 - 2011-04-02 04:52 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe 2015-05-08 05:38 - 2011-04-02 04:51 - 00000000 ____D () C:\Users\Default\AppData\Roaming\E-Cam 2015-05-08 05:38 - 2011-04-02 04:51 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\E-Cam 2015-05-08 05:38 - 2011-04-02 04:49 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Game Park 2015-05-08 05:38 - 2011-04-02 04:49 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Game Park 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default\Documents\Bluetooth Exchange Folder 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default\AppData\Local\Broadcom 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default User\Documents\Bluetooth Exchange Folder 2015-05-08 05:38 - 2011-04-02 04:45 - 00000000 ____D () C:\Users\Default User\AppData\Local\Broadcom 2015-05-08 05:38 - 2011-04-02 04:41 - 00000000 ____D () C:\Users\Default\AppData\Roaming\InstallShield 2015-05-08 05:38 - 2011-04-02 04:41 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\InstallShield 2015-05-08 05:37 - 2015-05-27 22:34 - 01904613 _____ () C:\windows\WindowsUpdate.log ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-27 22:22 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-05-27 22:22 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-05-27 22:13 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-05-27 22:13 - 2009-07-14 06:39 - 00053963 _____ () C:\windows\setupact.log 2015-05-27 22:12 - 2011-04-02 04:30 - 00416556 _____ () C:\windows\PFRO.log 2015-05-27 21:07 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\Microsoft.NET 2015-05-27 19:53 - 2011-02-16 17:44 - 00702604 _____ () C:\windows\system32\perfh013.dat 2015-05-27 19:53 - 2011-02-16 17:44 - 00136692 _____ () C:\windows\system32\perfc013.dat 2015-05-27 19:53 - 2011-02-16 17:39 - 00700520 _____ () C:\windows\system32\perfh010.dat 2015-05-27 19:53 - 2011-02-16 17:39 - 00130896 _____ () C:\windows\system32\perfc010.dat 2015-05-27 19:53 - 2009-07-27 12:11 - 04060570 _____ () C:\windows\system32\PerfStringBackup.INI 2015-05-27 19:53 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\de-DE 2015-05-22 21:19 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\rescache 2015-05-22 16:44 - 2009-07-14 06:33 - 00284480 _____ () C:\windows\system32\FNTCACHE.DAT 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\nl-NL 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\it-IT 2015-05-22 16:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\fr-FR 2015-05-22 15:10 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\LogFiles 2015-05-22 13:23 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender 2015-05-20 23:52 - 2011-04-02 05:07 - 00000000 ____D () C:\ProgramData\Trend Micro 2015-05-20 23:07 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp 2015-05-17 09:00 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\WCN 2015-05-17 09:00 - 2009-07-14 06:56 - 00000000 ____D () C:\windows\system32\Printing_Admin_Scripts 2015-05-17 09:00 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\MUI 2015-05-17 09:00 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\com 2015-05-14 03:03 - 2011-04-02 04:41 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2015-05-14 03:03 - 2009-07-14 04:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-05-14 03:01 - 2011-04-02 04:48 - 00000000 ____D () C:\Program Files\Asus 2015-05-14 02:59 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\restore 2015-05-14 02:58 - 2011-04-02 04:44 - 00014676 _____ () C:\windows\DPINST.LOG 2015-05-14 02:57 - 2011-04-02 04:48 - 00000000 ____D () C:\Program Files\Common Files\InstallShield 2015-05-14 02:54 - 2009-07-27 12:56 - 00000000 ____D () C:\windows\panther 2015-05-14 02:54 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\Recovery 2015-05-08 06:33 - 2009-07-14 06:57 - 00029696 ___SH () C:\windows\system32\config\BCD-Template.LOG 2015-05-08 06:33 - 2009-07-14 06:52 - 00032768 _____ () C:\windows\system32\config\BCD-Template 2015-05-08 05:38 - 2009-07-27 11:57 - 00008134 _____ () C:\windows\TSSysprep.log 2015-05-08 05:38 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2015-05-08 05:35 - 2009-07-14 06:34 - 00004822 _____ () C:\windows\DtcInstall.log ==================== Files in the root of some directories ======= 2011-04-02 04:49 - 2010-03-03 00:59 - 0131984 _____ () C:\ProgramData\FullRemove.exe Some files in TEMP: ==================== C:\Users\Petra\AppData\Local\Temp\avgnt.exe C:\Users\Petra\AppData\Local\Temp\MSETUP4.EXE C:\Users\Petra\AppData\Local\Temp\Quarantine.exe C:\Users\Petra\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\windows\explorer.exe => File is digitally signed C:\windows\system32\winlogon.exe => File is digitally signed C:\windows\system32\wininit.exe => File is digitally signed C:\windows\system32\svchost.exe => File is digitally signed C:\windows\system32\services.exe => File is digitally signed C:\windows\system32\User32.dll => File is digitally signed C:\windows\system32\userinit.exe => File is digitally signed C:\windows\system32\rpcss.dll => File is digitally signed C:\windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-05-17 08:49 ==================== End of log ============================[CODE] Geändert von Parim (27.05.2015 um 22:31 Uhr) |
Trojaner 'TR/Crypt.XPACK.Gen'

IN dem Screenshot ist doch die Schnell-Antwortenbox unterhalb dieses Themas zu sehen. Dort ist oben bei den ganzen Auswahlelementen eine Raute dabei

ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ --> Trojaner 'TR/Crypt.XPACK.Gen' |
Trojaner 'TR/Crypt.XPACK.Gen'

Hallo Schrauber,

vielen Dank für die Hilfe. Heute versuche ich es mal richtig zu machen, mit der Raute.

LG Parim
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=47a63949400f1a4dad7c70dda77b564c # engine=24089 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-05-29 08:07:07 # local_time=2015-05-29 10:07:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776574 66 85 636203 184561217 0 0 # scanned=4671 # found=0 # cleaned=0 # scan_time=610 ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=47a63949400f1a4dad7c70dda77b564c # engine=24089 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-05-29 08:30:32 # local_time=2015-05-29 10:30:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='' # compatibility_mode=5893 16776574 66 85 637609 184562623 0 0 # scanned=7611 # found=0 # cleaned=0 # scan_time=733 Code:
ATTFilter Results of screen317's Security Check version 1.002 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 10 Flash Player out of Date! Adobe Reader 9 Adobe Reader out of Date! Mozilla Firefox (38.0.1) ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe Avira Antivirus sched.exe Avira Antivirus avshadow.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-05-2015 01 Ran by Petra (administrator) on PETRA-PC on 29-05-2015 22:51:56 Running from C:\Users\Petra\Desktop Loaded Profiles: Petra (Available Profiles: Petra) Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe () C:\Windows\System32\AsusService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (ASUSTek Computer Inc.) C:\Program Files\Asus\Eee Docking\Eee Docking.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotKeyMon.exe (ASUSTeK Computer Inc.) C:\Program Files\Asus\SHE\SuperHybridEngine.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ASUS) C:\Program Files\Asus\CapsHook\CapsHook.exe (ASUSTeK Computer Inc.) C:\Program Files\Asus\HotkeyService\HotkeyService.exe (Boingo Wireless, Inc.) C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.OE.Systray.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [EeeSplendidAgent] => C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-28] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HotkeyMon] => C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe [101288 2010-12-07] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [HotkeyService] => C:\Program Files\ASUS\HotkeyService\HotkeyService.exe [1248176 2010-12-07] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [SuperHybridEngine] => C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [412600 2010-11-15] (ASUSTeK Computer Inc.) HKLM-x32\...\Run: [LiveUpdate] => C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe [1095080 2011-03-11] (AsusTek Computer Inc.) HKLM-x32\...\Run: [CapsHook] => C:\Program Files\ASUS\CapsHook\CapsHook.exe [445344 2010-11-15] (ASUS) HKLM-x32\...\Run: [Eee Docking] => C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [414384 2011-01-07] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files\ASUS\ASUS WebStorage\\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [IgfxTray] => C:\windows\system32\igfxtray.exe [141848 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [HotKeysCmds] => C:\windows\system32\hkcmd.exe [173592 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [Persistence] => C:\windows\system32\igfxpers.exe [150552 2010-05-10] (Intel Corporation) HKLM-x32\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9177632 2010-04-27] (Realtek Semiconductor) HKLM-x32\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [548744 2010-06-10] (ELAN Microelectronic Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] => C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2015-05-14] () HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files\ASUS\APRP\APRP.EXE [2018032 2011-04-02] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files\Avira\Launcher\Avira.OE.Systray.exe [128760 2015-05-07] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [728312 2015-04-16] (Avira Operations GmbH & Co. KG) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk [2011-04-02] ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files\Asus\AsusVibe\AsusVibeLauncher.exe () ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {CC5FC992-B0AA-47CD-9DC2-83445083CBB8} => C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll [2010-09-02] () ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {618A47A2-528B-4D9A-AFC8-97D3233511E2} => C:\Program Files\Asus\ASUS WebStorage\\AsusWSShellExt.dll [2010-09-02] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://eeepc.asus.com HKU\S-1-5-21-1209219964-1995288155-3218319295-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\3ysgaq2s.default FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation) FF Extension: Avira Browser Safety - C:\Users\Petra\AppData\Roaming\Mozilla\Firefox\Profiles\3ysgaq2s.default\Extensions\abs@avira.com [2015-05-29] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [827640 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [434424 2015-04-16] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1185584 2015-04-16] (Avira Operations GmbH & Co. KG) R2 AsusService; C:\windows\system32\AsusService.exe [224680 2010-12-07] () R2 Avira.OE.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [206584 2015-05-07] (Avira Operations GmbH & Co. KG) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\windows\System32\drivers\AsIO.sys [11456 2010-06-28] () R1 AsUpIO; C:\windows\System32\drivers\AsUpIO.sys [11832 2010-08-03] () R2 avgntflt; C:\windows\System32\DRIVERS\avgntflt.sys [107400 2015-04-16] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\windows\System32\DRIVERS\avipbb.sys [136216 2015-04-16] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\windows\System32\DRIVERS\avkmgr.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\windows\System32\DRIVERS\avnetflt.sys [37896 2015-04-16] (Avira Operations GmbH & Co. KG) R3 ETD; C:\windows\System32\DRIVERS\ETD.sys [102912 2010-07-21] (ELAN Microelectronic Corp.) R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation) R1 ssmdrv; C:\windows\System32\DRIVERS\ssmdrv.sys [28520 2015-04-16] (Avira GmbH) S3 btwaudio; system32\drivers\btwaudio.sys [X] S3 btwavdt; \SystemRoot\system32\drivers\btwavdt.sys [X] S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X] S3 btwrchid; \SystemRoot\system32\drivers\btwrchid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-05-29 22:47 - 2015-05-29 22:47 - 00000895 _____ () C:\Users\Petra\Desktop\checkup.txt 2015-05-29 22:34 - 2015-05-29 22:34 - 00852639 _____ () C:\Users\Petra\Downloads\SecurityCheck.exe 2015-05-29 21:32 - 2015-05-29 21:32 - 00000000 ____D () C:\Program Files\ESET 2015-05-29 21:30 - 2015-05-29 21:31 - 02347384 _____ (ESET) C:\Users\Petra\Downloads\esetsmartinstaller_deu.exe 2015-05-29 20:34 - 2015-05-29 20:34 - 00000000 ___SD () C:\windows\system32\CompatTel 2015-05-29 20:34 - 2015-05-29 20:34 - 00000000 ____D () C:\windows\system32\appraiser 2015-05-28 01:28 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2015-05-28 00:56 - 2015-01-09 01:44 - 00419936 _____ () C:\windows\system32\locale.nls 2015-05-28 00:02 - 2012-07-26 05:21 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe 2015-05-28 00:02 - 2012-07-26 05:20 - 00613888 _____ (Microsoft Corporation) C:\windows\system32\WUDFx.dll 2015-05-28 00:02 - 2012-07-26 05:20 - 00172032 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll 2015-05-28 00:02 - 2012-07-26 05:20 - 00073216 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll 2015-05-28 00:02 - 2012-07-26 05:20 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\WUDFCoinstaller.dll 2015-05-28 00:02 - 2012-07-26 04:33 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys 2015-05-28 00:02 - 2012-07-26 04:32 - 00155136 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys 2015-05-28 00:02 - 2012-06-02 16:57 - 00000003 _____ () C:\windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf 2015-05-27 23:59 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\windows\system32\icardres.dll 2015-05-27 23:59 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\windows\system32\TsWpfWrp.exe 2015-05-27 23:59 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\windows\system32\icardagt.exe 2015-05-27 23:59 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\windows\system32\infocardapi.dll 2015-05-27 23:57 - 2012-03-01 07:46 - 00019824 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fs_rec.sys 2015-05-27 23:57 - 2012-03-01 07:29 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\wmi.dll 2015-05-27 22:48 - 2015-05-27 22:48 - 00052030 _____ () C:\Users\Petra\Desktop\FRST II.txt 2015-05-27 22:38 - 2015-05-27 22:38 - 00000595 _____ () C:\Users\Petra\Desktop\JRT.txt 2015-05-27 22:33 - 2015-05-27 22:33 - 00000207 _____ () C:\windows\tweaking.com-regbackup-PETRA-PC-Windows-7-Starter-(32-bit).dat 2015-05-27 22:33 - 2015-05-27 22:33 - 00000000 ____D () C:\RegBackup 2015-05-27 22:32 - 2015-05-27 22:32 - 02946603 _____ (Thisisu) C:\Users\Petra\Downloads\JRT.exe 2015-05-27 22:15 - 2015-05-27 22:15 - 00000897 _____ () C:\Users\Petra\Desktop\AdwCleaner[S0].txt 2015-05-27 22:07 - 2015-05-27 22:11 - 00000000 ____D () C:\AdwCleaner 2015-05-27 22:06 - 2015-05-27 22:06 - 02222592 _____ () C:\Users\Petra\Downloads\AdwCleaner_4.205.exe 2015-05-27 21:26 - 2015-05-27 21:26 - 00001320 _____ () C:\Users\Petra\Desktop\mbam.txt 2015-05-27 20:09 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys 2015-05-27 20:01 - 2015-05-27 21:23 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2015-05-27 20:00 - 2015-05-27 20:00 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-05-27 20:00 - 2015-05-27 20:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-05-27 20:00 - 2015-05-27 20:00 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2015-05-27 20:00 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2015-05-27 20:00 - 