Turnvater1 | 09.01.2014 17:55 | Win7 PC Systhem extrem langsam - möglicherweise Trojaner Hallo! Ich bruache Eure Hilfe!
Mein Rechner (Acer 4810tz, Win7 home professional,64bit) ist seit etwa zwei Tagen extrem langsam. Scans mit Anitivir und Spybot waren ergebnislos. Ich hab außerdem cccleaner laufen lassen. Gestern hat dan Antivir doch nocht einen vermeintlichen Trojaner gefunden: Code:
In der Datei 'C:\Program Files (x86)\Skype\Phone\Skype.exe'
wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.ZPACK.Gen2' [trojan] gefunden.
Ausgeführte Aktion: Zugriff verweigern Ich hab skype dann deinstaliert. Das hat allerdings nichts geändert.
Inzwischen hab ich der Anleitung des Boards folgend Defogger, FRST und GMER durchlaufen lassen. Defogger war ohne ergebnis.
FRST: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 01
Ran by Jan (administrator) on SUPERMANNII on 09-01-2014 14:55:29
Running from C:\Users\Jan\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Windows\PLFSetI.exe
(Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe
(Safer-Networking Ltd.) D:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Users\Jan\Downloads\gmer_2.1.19163.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-11] (Egis Technology Inc.)
HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-18] (Synaptics Incorporated)
HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [200704 2011-02-17] ()
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2009-10-02] (Acer Incorporated)
HKLM\...\Run: [ODDPwr] - C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe [221728 2009-09-04] (Acer Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-09-24] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [EgisTecLiveUpdate] - C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1094736 2009-11-02] (Dritek System Inc.)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] ()
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-17] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [SpybotSD TeaTimer] - D:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
MountPoints2: E - E:\AutoRun.exe
MountPoints2: {5771f9e0-900e-11e0-9f9b-001e643ba0fc} - F:\AutoRun.exe
MountPoints2: {5771f9e5-900e-11e0-9f9b-001e643ba0fc} - F:\AutoRun.exe
MountPoints2: {74a67757-41fc-11e1-9beb-00262d77db89} - E:\LaunchU3.exe -a
MountPoints2: {d38dc892-ce8a-11e0-be82-001e643ba0fc} - F:\AutoRun.exe
MountPoints2: {d38dc896-ce8a-11e0-be82-001e643ba0fc} - E:\AutoRun.exe
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default
Startup: C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0.7012110116924009.exe.lnk
ShortcutTarget: 0.7012110116924009.exe.lnk -> C:\Users\Jan\AppData\Local\Temp\0.7012110116924009.exe (No File)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4810t&r=273602111606l04f8z1k5t4401b43p
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4810t&r=273602111606l04f8z1k5t4401b43p
SearchScopes: HKLM-x32 - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKCU - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_de___DE419
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_de___DE419
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 208.67.220.220
FireFox:
========
FF ProfilePath: C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default
FF Homepage: hxxp://www.tagesschau.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @t-immersion.com/DFusionHomeWebPlugIn - C:\Program Files (x86)\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll (Total Immersion)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default\Extensions\youtubeunblocker@unblocker.yt
FF Extension: Google Toolbar for Firefox - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: PsicoTSI - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default\Extensions\{7E77F5DF-8022-40e3-9122-F03DEBEFC43B}
FF Extension: Video MPEG4 Wizard Free - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default\Extensions\{6c120548-8b86-4ec0-bd95-8567647f6030}.xpi
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: {dfdf1e4e-01d6-4d39-a50d-fc0e978170f9} - C:\Users\Jan\AppData\Roaming\Mozilla\Firefox\Profiles\627qohnf.default\Extensions\{dfdf1e4e-01d6-4d39-a50d-fc0e978170f9}.xpi
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video
FF HKLM-x32\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa
FF Extension: DivX HiQ - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376 2013-12-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG)
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [786976 2009-10-02] (Acer Incorporated)
R2 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-11] (Egis Technology Inc.)
R2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [158240 2009-09-04] (Acer Incorporated)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2011-09-21] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated)
S2 SBSDWSCService; D:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 connctfy; system32\DRIVERS\connctfy.sys [x]
S3 connctfyMP; system32\DRIVERS\connctfy.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]
U3 pwdcapow; \??\C:\Users\Jan\AppData\Local\Temp\pwdcapow.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-09 14:56 - 2014-01-09 14:56 - 00030422 _____ C:\Users\Jan\Desktop\FRST.txt
2014-01-09 14:55 - 2014-01-09 14:55 - 00021738 _____ C:\Users\Jan\Desktop\Addition.txt
2014-01-09 14:50 - 2014-01-09 14:50 - 00021738 _____ C:\Users\Jan\Downloads\Addition.txt
2014-01-09 14:01 - 2014-01-09 14:55 - 00014220 _____ C:\Users\Jan\Downloads\FRST.txt
2014-01-09 13:54 - 2014-01-09 13:54 - 00377856 _____ C:\Users\Jan\Downloads\gmer_2.1.19163.exe
2014-01-09 13:49 - 2014-01-09 13:49 - 00000000 ____D C:\FRST
2014-01-09 13:48 - 2014-01-09 13:48 - 01931770 _____ (Farbar) C:\Users\Jan\Downloads\FRST64.exe
2014-01-09 13:44 - 2014-01-09 13:45 - 00000468 _____ C:\Users\Jan\Downloads\defogger_disable.log
2014-01-09 13:44 - 2014-01-09 13:44 - 00000000 _____ C:\Users\Jan\defogger_reenable
2014-01-09 13:43 - 2014-01-09 13:43 - 00001142 _____ C:\Users\Jan\Desktop\Continue Zip Extractor Installation.lnk
2014-01-09 13:42 - 2014-01-09 13:43 - 00050477 _____ C:\Users\Jan\Downloads\Defogger.exe
2014-01-09 13:39 - 2014-01-09 13:40 - 00672936 _____ ( ) C:\Users\Jan\Downloads\ZipExtractorSetup.exe
2014-01-08 20:56 - 2014-01-09 00:41 - 00000112 _____ C:\Windows\setupact.log
2014-01-08 20:56 - 2014-01-08 20:56 - 00000374 _____ C:\Windows\PFRO.log
2014-01-08 20:56 - 2014-01-08 20:56 - 00000000 _____ C:\Windows\setuperr.log
2014-01-08 20:52 - 2014-01-08 20:52 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-08 20:52 - 2014-01-08 20:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-08 20:52 - 2014-01-08 20:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-08 20:52 - 2014-01-08 20:52 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-01-08 20:52 - 2014-01-08 20:52 - 00000000 ____D C:\ProgramData\Oracle
2014-01-08 20:52 - 2014-01-08 20:52 - 00000000 ____D C:\Program Files\Java
2014-01-08 20:37 - 2011-05-19 20:28 - 09083904 _____ C:\Users\Jan\Documents\C & C 2011-05-21.ppt
2014-01-08 19:58 - 2014-01-08 19:58 - 00000000 ____D C:\Windows\pss
2014-01-08 19:54 - 2014-01-08 19:56 - 00009608 _____ C:\Users\Jan\Documents\cc_20140108_195447.reg
2014-01-08 19:51 - 2014-01-08 19:51 - 04645232 _____ (Piriform Ltd) C:\Users\Jan\Downloads\ccsetup409.exe
2014-01-08 19:51 - 2014-01-08 19:51 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-08 19:42 - 2014-01-08 19:42 - 00915368 _____ (Oracle Corporation) C:\Users\Jan\Downloads\jxpiinstall(1).exe
2014-01-08 15:43 - 2014-01-08 15:43 - 00080218 _____ C:\Users\Jan\Documents\cc_20140108_154327.reg
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-12 20:05 - 2013-12-12 20:14 - 00000000 ____D C:\Windows\rescache
2013-12-12 03:10 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 03:10 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 03:10 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 03:10 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 03:06 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 03:06 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 03:06 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:06 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 03:06 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 03:06 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:06 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 03:06 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 03:06 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 03:06 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 03:06 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 03:06 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 03:06 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:06 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 03:06 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 03:06 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 03:06 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 03:06 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 03:06 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 03:06 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 03:06 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 03:06 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 03:06 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 03:06 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 03:06 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 03:06 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 03:06 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 03:06 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 03:06 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 03:06 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 03:06 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-11 12:43 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-11 12:43 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-11 12:43 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-11 12:43 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-11 12:43 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 12:43 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 12:43 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-11 12:43 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 12:42 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 12:42 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-11 12:42 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 12:42 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-11 12:42 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-11 12:42 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 12:42 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 12:42 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-11 12:42 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-11 12:42 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 12:42 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
==================== One Month Modified Files and Folders =======
2014-01-09 14:56 - 2014-01-09 14:56 - 00030422 _____ C:\Users\Jan\Desktop\FRST.txt
2014-01-09 14:55 - 2014-01-09 14:55 - 00021738 _____ C:\Users\Jan\Desktop\Addition.txt
2014-01-09 14:55 - 2014-01-09 14:01 - 00014220 _____ C:\Users\Jan\Downloads\FRST.txt
2014-01-09 14:50 - 2014-01-09 14:50 - 00021738 _____ C:\Users\Jan\Downloads\Addition.txt
2014-01-09 14:32 - 2013-02-19 12:02 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-09 13:54 - 2014-01-09 13:54 - 00377856 _____ C:\Users\Jan\Downloads\gmer_2.1.19163.exe
2014-01-09 13:49 - 2014-01-09 13:49 - 00000000 ____D C:\FRST
2014-01-09 13:48 - 2014-01-09 13:48 - 01931770 _____ (Farbar) C:\Users\Jan\Downloads\FRST64.exe
2014-01-09 13:45 - 2014-01-09 13:44 - 00000468 _____ C:\Users\Jan\Downloads\defogger_disable.log
2014-01-09 13:44 - 2014-01-09 13:44 - 00000000 _____ C:\Users\Jan\defogger_reenable
2014-01-09 13:44 - 2011-02-17 15:09 - 00000000 ____D C:\Users\Jan
2014-01-09 13:43 - 2014-01-09 13:43 - 00001142 _____ C:\Users\Jan\Desktop\Continue Zip Extractor Installation.lnk
2014-01-09 13:43 - 2014-01-09 13:42 - 00050477 _____ C:\Users\Jan\Downloads\Defogger.exe
2014-01-09 13:40 - 2014-01-09 13:39 - 00672936 _____ ( ) C:\Users\Jan\Downloads\ZipExtractorSetup.exe
2014-01-09 12:07 - 2011-02-17 15:02 - 01386477 _____ C:\Windows\WindowsUpdate.log
2014-01-09 12:06 - 2012-10-01 18:11 - 00000433 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2014-01-09 01:29 - 2012-01-18 19:09 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Skype
2014-01-09 01:29 - 2012-01-18 19:08 - 00000000 ____D C:\ProgramData\Skype
2014-01-09 01:07 - 2011-02-17 23:49 - 01437788 _____ C:\Windows\system32\perfh007.dat
2014-01-09 01:07 - 2011-02-17 23:49 - 00385096 _____ C:\Windows\system32\perfc007.dat
2014-01-09 01:07 - 2009-07-14 06:13 - 00006194 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-09 00:52 - 2009-07-14 05:45 - 00017376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-09 00:52 - 2009-07-14 05:45 - 00017376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-09 00:41 - 2014-01-08 20:56 - 00000112 _____ C:\Windows\setupact.log
2014-01-09 00:41 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-09 00:21 - 2012-06-25 23:10 - 00007605 _____ C:\Users\Jan\AppData\Local\Resmon.ResmonCfg
2014-01-08 20:56 - 2014-01-08 20:56 - 00000374 _____ C:\Windows\PFRO.log
2014-01-08 20:56 - 2014-01-08 20:56 - 00000000 _____ C:\Windows\setuperr.log
2014-01-08 20:52 - 2014-01-08 20:52 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-08 20:52 - 2014-01-08 20:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-08 20:52 - 2014-01-08 20:52 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-08 20:52 - 2014-01-08 20:52 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-01-08 20:52 - 2014-01-08 20:52 - 00000000 ____D C:\ProgramData\Oracle
2014-01-08 20:52 - 2014-01-08 20:52 - 00000000 ____D C:\Program Files\Java
2014-01-08 19:58 - 2014-01-08 19:58 - 00000000 ____D C:\Windows\pss
2014-01-08 19:56 - 2014-01-08 19:54 - 00009608 _____ C:\Users\Jan\Documents\cc_20140108_195447.reg
2014-01-08 19:52 - 2011-03-03 00:44 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-08 19:51 - 2014-01-08 19:51 - 04645232 _____ (Piriform Ltd) C:\Users\Jan\Downloads\ccsetup409.exe
2014-01-08 19:51 - 2014-01-08 19:51 - 00002768 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-01-08 19:51 - 2012-03-11 17:29 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2014-01-08 19:51 - 2012-03-11 17:29 - 00000000 ____D C:\Program Files\CCleaner
2014-01-08 19:42 - 2014-01-08 19:42 - 00915368 _____ (Oracle Corporation) C:\Users\Jan\Downloads\jxpiinstall(1).exe
2014-01-08 15:51 - 2013-10-11 15:25 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Dropbox
2014-01-08 15:43 - 2014-01-08 15:43 - 00080218 _____ C:\Users\Jan\Documents\cc_20140108_154327.reg
2014-01-08 15:42 - 2011-10-13 14:48 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Winamp
2014-01-08 15:42 - 2009-07-27 21:41 - 00000000 ____D C:\Windows\Panther
2014-01-08 15:41 - 2011-06-06 07:35 - 00000000 ____D C:\Windows\Minidump
2014-01-08 15:36 - 2013-10-11 15:30 - 00000000 ___RD C:\Users\Jan\Dropbox
2014-01-08 15:36 - 2011-02-17 15:10 - 00000000 ___RD C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-08 15:29 - 2013-10-16 19:31 - 00000000 ____D C:\Users\Jan\AppData\Local\FluxSoftware
2014-01-08 15:29 - 2013-10-11 15:27 - 00000891 _____ C:\Windows\wininit.ini
2014-01-08 14:43 - 2013-10-11 15:30 - 00001018 _____ C:\Users\Jan\Desktop\Dropbox.lnk
2014-01-08 14:43 - 2013-10-11 15:28 - 00000000 ____D C:\Users\Jan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-08 00:24 - 2012-09-25 22:46 - 00000000 ____D C:\Users\Jan\Desktop\Drei Fragezeichen
2014-01-06 19:25 - 2012-05-08 14:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-22 17:33 - 2013-12-22 17:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-17 14:56 - 2013-05-02 10:26 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-12-17 14:56 - 2013-03-27 23:46 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-12-17 14:56 - 2013-03-27 23:46 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-12-15 03:05 - 2013-07-19 13:41 - 00000000 ____D C:\Windows\system32\MRT
2013-12-15 03:01 - 2011-03-24 01:05 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-12 20:14 - 2013-12-12 20:05 - 00000000 ____D C:\Windows\rescache
2013-12-12 03:32 - 2009-07-14 05:45 - 00424216 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-12 03:09 - 2009-10-29 04:27 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-10 21:33 - 2013-02-19 12:02 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 21:32 - 2013-01-06 19:18 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 21:32 - 2013-01-06 19:18 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Users\Jan\AppData\Local\Temp\avgnt.exe
C:\Users\Jan\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe
C:\Users\Jan\AppData\Local\Temp\setup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-09 03:31
==================== End Of Log ============================ Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-01-2014 01
Ran by Jan at 2014-01-09 14:56:16
Running from C:\Users\Jan\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Update for Microsoft Office 2007 (KB2508958) (x32 Version: - Microsoft)
64 Bit HP CIO Components Installer (Version: 6.2.2 - Hewlett-Packard) Hidden
Acer Backup Manager (x32 Version: 2.0.0.29 - NewTech Infosystems)
Acer Crystal Eye webcam Ver:1.1.124.1120 (x32 Version: 1.1.124.1120 - Chicony Electronics Co.,Ltd.)
Acer eRecovery Management (x32 Version: 4.05.3005 - Acer Incorporated)
Acer GridVista (x32 Version: 3.01.0730 - Acer Inc.)
Acer PowerSmart Manager (x32 Version: 4.07.3008 - Acer Incorporated)
Acer Registration (x32 Version: 1.02.3006 - Acer Incorporated)
Acer Updater (x32 Version: 1.01.3017 - Acer Incorporated)
Acer VCM (x32 Version: 4.05.3000 - Acer Incorporated)
Acrobat.com (x32 Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (x32 Version: 9.5.5 - Adobe Systems Incorporated)
ATI AVIVO64 Codecs (Version: 10.9.0.40908 - ATI Technologies Inc.) Hidden
ATI Catalyst Install Manager (Version: 3.0.741.0 - ATI Technologies, Inc.)
Avira Free Antivirus (x32 Version: 14.0.2.286 - Avira)
Backup Manager Basic (x32 Version: 2.0.0.29 - NewTech Infosystems) Hidden
Canon MP560 series MP Drivers (Version: - )
Canon My Printer (x32 Version: - )
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.0908.2225.38429 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0908.2225.38429 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.0908.2225.38429 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.0908.2225.38429 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0908.2225.38429 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.0908.2225.38429 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.0908.2225.38429 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Danish (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help English (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help French (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help German (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.0908.2224.38429 - ATI) Hidden
ccc-core-static (x32 Version: 2009.0908.2225.38429 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2009.0908.2225.38429 - ATI) Hidden
CCleaner (Version: 4.09 - Piriform)
Celtx (2.9.1) (x32 Version: 2.9.1 (de) - Greyfirst)
DivX-Setup (x32 Version: 2.5.0.8 - DivX, LLC)
DJ_AIO_06_F2400_SW_Min (x32 Version: 140.0.690.000 - Hewlett-Packard) Hidden
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
ElsterFormular (x32 Version: 14.1.11318 - Landesfinanzdirektion Thüringen)
Free Audio CD to MP3 Converter version 1.3.12.908 (x32 Version: - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.11.34.1015 (x32 Version: 3.11.34.1015 - DVDVideoSoft Ltd.)
HP Deskjet F2400 All-in-One Driver 14.0 Rel. 6 (Version: 14.0 - HP)
Identity Card (x32 Version: 1.00.3002 - Acer Incorporated)
Intel® Matrix Storage Manager (Version: - Intel Corporation)
Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle)
Launch Manager (x32 Version: 3.0.03 - Acer Inc.)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (x32 Version: 9.7.0621 - Microsoft Corporation)
Mobile Partner (x32 Version: 11.300.05.03.40 - Huawei Technologies Co.,Ltd)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKCU Version: - )
MyWinLocker (x32 Version: 3.1.76.0 - Egis Technology Inc.)
NTI Backup Now 5 (x32 Version: 5.1.2.627 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.627 - NewTech Infosystems) Hidden
NTI Media Maker 8 (x32 Version: 8.0.12.6623 - NewTech Infosystems)
NTI Media Maker 8 (x32 Version: 8.0.12.6623 - NewTech Infosystems) Hidden
Optical Drive Power Management (x32 Version: 1.01.3002 - Acer Incorporated)
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Realtek High Definition Audio Driver (x32 Version: 6.0.1.5911 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7100.30093 - Realtek Semiconductor Corp.)
Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.24.0 - SAMSUNG Electronics Co., Ltd.)
Scan (x32 Version: 140.0.80.000 - Hewlett-Packard) Hidden
Spybot - Search & Destroy (x32 Version: 1.6.2 - Safer Networking Limited)
Synaptics Pointing Device Driver (Version: 14.0.6.0 - Synaptics Incorporated)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
Total Immersion D'Fusion @Home Web Plug-In (x32 Version: - Total Immersion)
UBitMenuDE (x32 Version: 01.04 - UBit Schweiz AG)
Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32 Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition (x32 Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32 Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft)
VC80CRTRedist - 8.0.50727.4053 (x32 Version: 1.1.0 - DivX, Inc) Hidden
VLC media player 1.1.7 (x32 Version: 1.1.7 - VideoLAN)
WIDCOMM Bluetooth Software (Version: 6.2.1.800 - Broadcom Corporation)
Winamp (x32 Version: 5.621 - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1 - Nullsoft, Inc)
Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407) (Version: 09/11/2009 6.2.0.9407 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {55398C7E-F088-48CA-AD1F-299D1F2B15F0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
Task: {ABC50B1F-FCB2-4FBA-83EE-BFFBC65C3416} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E50CE564-6337-43B5-A9F0-66BD1E27BA97} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-12-17] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2009-07-29 13:10 - 2009-07-29 13:10 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-02-17 15:15 - 2011-02-17 15:15 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2012-10-16 18:33 - 2012-09-19 18:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2009-02-03 01:33 - 2009-02-03 01:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-29 01:55 - 2008-09-29 01:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2011-03-21 19:57 - 2011-03-21 19:57 - 00096112 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2009-02-26 13:46 - 2009-02-26 13:46 - 00064344 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll
2011-06-22 11:46 - 2011-06-22 11:46 - 00434016 _____ () C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
2013-07-10 17:07 - 2013-07-10 17:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/09/2014 04:53:29 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (01/09/2014 04:05:41 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (01/09/2014 01:08:42 AM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003
Error: (01/09/2014 01:06:06 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "MSDTC Bridge 4.0.0.0" (MSDTC Bridge 4.0.0.0). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (01/09/2014 01:06:06 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (01/09/2014 01:06:06 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (01/09/2014 01:06:05 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "MSDTC Bridge 4.0.0.0" (MSDTC Bridge 4.0.0.0). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (01/09/2014 01:06:05 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (01/09/2014 01:06:05 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
Error: (01/09/2014 01:06:04 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "SMSvcHost 4.0.0.0" (SMSvcHost 4.0.0.0). Der Fehlercode ist das erste DWORD im Datenbereich.
System errors:
=============
Error: (01/09/2014 02:03:02 PM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error: (01/09/2014 01:58:49 PM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.
Error: (01/09/2014 01:49:12 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (01/09/2014 01:41:16 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (01/09/2014 00:06:55 PM) (Source: ipnathlp) (User: )
Description: 10.62.51.2192.168.2.0255.255.255.0
Error: (01/09/2014 00:06:54 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (01/09/2014 00:06:54 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (01/09/2014 00:06:54 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (01/09/2014 00:06:48 PM) (Source: ipnathlp) (User: )
Description: 0
Error: (01/09/2014 00:06:45 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst IPBusEnum erreicht.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 39%
Total physical RAM: 3998.79 MB
Available physical RAM: 2417.61 MB
Total Pagefile: 7995.76 MB
Available Pagefile: 6128.51 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:78.12 GB) (Free:23.06 GB) NTFS
Drive d: () (Fixed) (Total:506.23 GB) (Free:446.18 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 596 GB) (Disk ID: 200E200D)
Partition 1: (Not Active) - (Size=12 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=78 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=506 GB) - (Type=07 NTFS)
==================== End Of Log ============================ GMER: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2014-01-09 16:54:29
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD64 rev.01.0 596,17GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Jan\AppData\Local\Temp\pwdcapow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002fef000 45 bytes [01, 00, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002fef02f 16 bytes [00, 01, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[1944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074f41465 2 bytes [F4, 74]
.text C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[1944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074f414bb 2 bytes [F4, 74]
.text ... * 2
.text C:\Windows\SysWOW64\PnkBstrA.exe[2140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000071841a22 2 bytes [84, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000071841ad0 2 bytes [84, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000071841b08 2 bytes [84, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000071841bba 2 bytes [84, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2140] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000071841bda 2 bytes [84, 71]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 000000006efc11a8 2 bytes [FC, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 000000006efc13a8 2 bytes [FC, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 000000006efc1422 2 bytes [FC, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 000000006efc1498 2 bytes [FC, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 195 000000006edb1b41 2 bytes [DB, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 362 000000006edb1be8 2 bytes [DB, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 418 000000006edb1c20 2 bytes [DB, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 596 000000006edb1cd2 2 bytes [DB, 6E]
.text C:\Windows\PLFSetI.exe[2968] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 628 000000006edb1cf2 2 bytes [DB, 6E]
.text D:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe[3036] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074f41465 2 bytes [F4, 74]
.text D:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe[3036] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074f414bb 2 bytes [F4, 74]
.text ... * 2
---- Processes - GMER 2.1 ----
Library Ì÷î*PH (*** suspicious ***) @ C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe [3068] 0000000028000000
Library C:\Windows\ERUNT.exe (*** suspicious ***) @ C:\Windows\ERUNT.exe [4764] 0000000000400000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ????s_???|??????????????????????? ??????????????r???????????????????????????0???? ???????????????????????????????????????????????????? ????????????t????????????????????????????????????????? D??/????????????????\???????????????s?????kerberos?msv1_0?schannel?wdigest?tspkg?pku2u?????????????????????????s?????????/???????????/?/??? ???_???????????i???,?,?,??? ????????????????????????????????,??????????r??? ??????????????????????????????D????????r????"??????k??????n???? ??????????????????????????????D???????r???? D??+??????????r???fvevol?rdyboost??t????N??????S?????eoo??@%SystemRoot%\system32\wiaservc.dll,-9?tem???+?+?+???????????????????????????????????????m????????????????????????s?????credssp.dll?????? ?????????????????????????????????????????????????????t???(??????P???????W????????????????????? ??????????? ???????P???????W???????P???????W???????????????????4???????????????????????????????? ??????????????????????????????????????????????????????????????????4?? ?????????? ????\???????????????????? ??????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000c55fffb1f
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076c777da
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\000c55fffb1f (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076c777da (not active ControlSet)
---- EOF - GMER 2.1 ---- Ich hoffe ich hab das soweit richtig gemacht. Würd mich über jede hilfe freuen! Gruß Jan |