![]() |
Suisa Virus blockiert meinen Windows 7 Rechner in jedem Modus meines Laptops Ich war gerade im Internet am surfen als plötzlich mein Bildschirm weiss wurde und eine Info erschien dass ich 75CHF zahlen muss weil ich Illegale Musikdownloads auf dem Rechner habe. Nach recherche in google hies es dass es sich um einen Virus/Trojaner handlet. Ich bekomme diese seite nicht mehr weg auch in abgesicherten Modus nicht. Was soll ich nun tun? |
:hallo: Mein Name ist Marius und ich werde dir bei deinem Problem helfen. Eines vorneweg: Hinweis: Wir können hier nie dafür garantieren, dass wir sämtliche Reste von Schadsoftware gefunden haben. Eine Formatierung ist meist der schnellere und immer der sicherste Weg. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis dir jemand vom Team sagt, dass du clean bist. Eine Bereinigung ist mitunter mit viel Arbeit für dich verbunden.
Vista und Win7 User Alle Tools mit Rechtsklick "als Administrator ausführen" starten. Welche Windowsversion läuft auf dem Rechner? (auch mitteilen, ob 32 oder 64bit!) |
Hallo Marius Vielen Dank schon mal im voraus für deine Bereitshcaft mir zu helfen. Ich habe eine Windows 7 (64Bit) Version. Mit dem 64Bit bin ich mir nicht 100%sicher da mein Laptop von Vista auf Win7 updated wurde und ich dies nicht selber durchgeführt habe. Ich hoffe dass dir diese Angaben erstmals reichen. |
FRST64 Downloade dir bitte Farbar's Recovery Scan Tool x64 und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager
|
Hallo Also ich habe den PC im Reparaturmodus gestartet und das lief auch durch. Ich kann jetzt den PC wider starten. Wenn ich aber versuche den Farbar's Recovery Scan Tool x64 zu starten bekomme ich eine Fehlermeldung: C:\Users\David>f:\frst64.exe Die Version von f:\FRST64.exe ist nicht mit der ausgeführten Windows-Version kom patibel. Öffnen Sie die Systeminformationen des Computers, um zu überprüfen, ob eine x86-(32 Bit)- oder eine x64-(64 Bit)-Version des Programms erforderlich ist , und wenden Sie sich anschließend an den Herausgeber der Software. Hier mal meine system informationen Betriebsystemname Microsoft Windows 7 Professional Version 6.1.7600 Build 7600 Weitere Betriebsystembeschreibung Nicht verfügbar Betriebsystemhersteller Microsoft Corporation Systemname DAVID-PC Systemhersteller Hewlett-Packard Systemmodell HP Pavilion dv6700 Notebook PC Systemtyp X86-basierter PC Prozessor Intel(R) Core(TM)2 Duo CPU T7700 @ 2.40GHz, 2401 MHz, 2 Kern(e), 2 logische(r) Prozessor(en) BIOS-Version/-Datum Hewlett-Packard F.33, 12.11.2007 SMBIOS-Version 2.4 Windows-Verzeichnis C:\Windows Systemverzeichnis C:\Windows\system32 Startgerät \Device\HarddiskVolume1 Gebietsschema Schweiz Hardwareabstraktionsebene Version = "6.1.7600.16385" Benutzername David-PC\David Zeitzone Mitteleuropäische Sommerzeit Installierter physikalischer Speicher (RAM) 4.00 GB Gesamter realer Speicher 3.00 GB Verfügbarer realer Speicher 2.01 GB Gesamter virtueller Speicher 6.00 GB Verfügbarer virtueller Speicher 4.85 GB Größe der Auslagerungsdatei 3.00 GB Auslagerungsdatei C:\pagefile.sys |
OK - dann so: :D FRST (32bit) Downloade dir bitte Farbar's Recovery Scan Tool und speichere diese auf einen USB Stick. Schließe den USB Stick an das infizierte System an Du musst das System nun in die System Reparatur Option booten. Über den Boot Manager
|
Hallo Gibt es auch ne möglichkeit das ganze ohne Windows CD/DVD durchzuführen. Die CD hab ich meiner Freundin ausgeliehen und das geht zwei Wochen bis ich die wider hier hab. |
Ja, über den Boot Manager: Zitat:
|
Hallo, benötigst Du noch weiterhin Hilfe ? Sollte ich innerhalb der nächsten 24 Stunden keine Antwort von dir erhalten, werde ich dein Thema aus meinen Abos nehmen und bekomme dadurch keine Nachricht über neue Antworten. Das Verschwinden der Symptome bedeutet nicht, dass dein System schon sauber ist |
Hallo Ja ich werde jetzt dann gleichd as Log posten war die letzten Tage geschäftlich unterwegs, sorry. Hier das Log: Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 16-04-2012 Ran by David at 22-04-2012 18:47:12 Running from F:\ (X86) OS Language: German Standard Attention: Could not load system hive.FEHLER: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. Attention: The tool is not run from recovery environment and will not function properly. ========================== Registry (Whitelisted) ============= HKLM\...\Winlogon: [Userinit] [x] HKLM\...\Winlogon: [Shell] ================================ Services (Whitelisted) ================== ========================== Drivers (Whitelisted) ============= ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-04-22 18:46 - 2011-08-21 19:31 - 0000000 ____D C:\Users\David\AppData\Local\{0A70500B-8C44-466C-A6E5-29014A6610E3} 2012-04-22 18:46 - 2011-05-29 18:53 - 0000000 ____D C:\Users\David\AppData\Local\{75580811-E74C-4082-B102-98CB6F457A9C} 2012-04-22 18:34 - 2011-10-07 15:26 - 0000000 ____D C:\Users\David\AppData\Local\{8EB94645-DE0E-4463-94F5-443919F18E11} 2012-04-22 18:34 - 2011-09-07 18:37 - 0000000 ____D C:\Users\David\AppData\Local\{356CE8D9-4112-4097-AAF2-765ADDD5EA9B} 2012-04-18 16:45 - 2011-09-11 18:53 - 0031744 ____A C:\Users\David\Desktop\Löschdienst_summary.doc 2012-04-18 15:50 - 2012-04-18 15:36 - 0066048 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Loeschdienst_Druckl_.xls 2012-04-18 15:46 - 2012-04-18 15:36 - 0084480 ____A C:\Users\David\Desktop\TLF_übersicht.ppt 2012-04-18 15:01 - 2011-09-22 19:42 - 0047616 ____A C:\Users\David\Desktop\TLF_Einsatz_summary.doc 2012-04-18 10:53 - 2012-02-09 23:42 - 0060928 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Einsatz_TLF.xls 2012-04-17 14:28 - 2012-02-27 20:30 - 0000000 ____D C:\Users\David\AppData\Local\{AE6F1A14-B387-42A5-9BE2-B363942ADF31} 2012-04-17 14:28 - 2011-09-01 17:50 - 0000000 ____D C:\Users\David\AppData\Local\{5C6E33D0-2969-423C-AE54-8CD930F9D738} 2012-04-17 14:11 - 2012-01-02 21:25 - 0000000 ____D C:\Users\David\AppData\Local\{0B5E58C9-5824-4864-A6B9-53BCE7ED6F7E} 2012-04-17 14:11 - 2011-11-18 00:20 - 0000000 ____D C:\Users\David\AppData\Local\{018C9489-7539-4670-AC85-DF146FFD71DF} 2012-04-17 11:50 - 2012-04-16 06:24 - 0000000 ____D C:\FRST 2012-04-16 03:28 - 2010-11-23 20:06 - 0058782 ____A C:\OTL.Txt 2012-04-16 03:28 - 2010-10-17 21:26 - 0019538 ____A C:\Extras.Txt 2012-04-15 19:22 - 2012-04-15 19:22 - 0065536 __ASH C:\Windows\System32\config\COMPONENTS{88a6a1c9-57bd-11e0-af24-001e3777819a}.TxR.blf 2012-04-09 18:56 - 2011-08-31 15:34 - 0000000 ____D C:\Users\David\AppData\Local\{2334A902-3CBD-4FFB-88A5-1BA3953D4778} 2012-04-09 18:56 - 2011-06-17 22:28 - 0000000 ____D C:\Users\David\AppData\Local\{000D2179-8D69-4DD7-BFB9-973877490E25} 2012-04-09 18:15 - 2012-04-04 22:03 - 0000000 ____D C:\Users\David\AppData\Local\{EDE744F5-A7FF-439D-A315-C8E88E1EDD4F} 2012-04-09 18:15 - 2011-08-16 22:27 - 0000000 ____D C:\Users\David\AppData\Local\{DE16C105-7869-49D1-9242-FE6602AE2914} 2012-04-04 22:02 - 2012-03-01 08:19 - 0000000 ____D C:\Users\David\AppData\Local\{E6C1F8E9-6C64-4F63-9877-BCF8F0F14338} 2012-04-03 18:52 - 2012-01-11 20:45 - 0000000 ____D C:\Users\David\AppData\Local\{F5EE9A91-B0EF-4686-B9F3-47CBEA6D74C7} 2012-04-03 18:52 - 2011-11-20 21:27 - 0000000 ____D C:\Users\David\AppData\Local\{387FD345-4B38-4A24-9A04-054264FFA7F0} 2012-04-02 19:35 - 2012-04-02 19:36 - 0000000 ____D C:\Users\David\AppData\Local\{3E858585-37B1-4A13-B89E-20407A7CB151} 2012-04-02 19:35 - 2011-08-20 09:01 - 0000000 ____D C:\Users\David\AppData\Local\{3E32F5DD-FB69-457E-A624-2F123CB7A8D9} 2012-04-01 18:52 - 2011-10-22 10:30 - 0000000 ____D C:\Users\David\AppData\Local\{901E1C5F-D0DD-4C2B-A668-C00B7C9C67B6} 2012-04-01 18:51 - 2011-10-15 11:33 - 0000000 ____D C:\Users\David\AppData\Local\{5567838F-7506-43E0-B61B-8EDF976DD6F1} 2012-04-01 18:47 - 2012-04-22 18:42 - 0000000 ____D C:\Program Files\iPod 2012-04-01 18:47 - 2012-04-01 18:47 - 0000000 ____D C:\Program Files\iTunes 2012-04-01 18:47 - 2011-11-22 20:19 - 0001753 ____A C:\Users\Public\Desktop\iTunes.lnk ============ 3 Months Modified Files and Folders =============== 2012-04-22 18:47 - 2012-04-22 18:46 - 0000000 ____D C:\Users\David\AppData\Local\{0A70500B-8C44-466C-A6E5-29014A6610E3} 2012-04-22 18:47 - 2012-04-17 11:50 - 0000000 ____D C:\FRST 2012-04-22 18:46 - 2012-04-22 18:46 - 0000000 ____D C:\Users\David\AppData\Local\{75580811-E74C-4082-B102-98CB6F457A9C} 2012-04-22 18:46 - 2009-07-14 06:39 - 0030023 ____A C:\Windows\setupact.log 2012-04-22 18:45 - 2011-01-16 21:31 - 0000000 ____D C:\Users\David\AppData\Roaming\Skype 2012-04-22 18:45 - 2010-11-16 22:58 - 0001092 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-04-22 18:44 - 2010-10-17 21:26 - 0000000 ____D C:\users\David 2012-04-22 18:44 - 2010-10-17 21:18 - 2414682112 __ASH C:\hiberfil.sys 2012-04-22 18:44 - 2009-07-14 06:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT 2012-04-22 18:44 - 2009-07-14 04:37 - 0000000 ____D C:\Windows\System32\wfp 2012-04-22 18:44 - 2009-07-14 04:37 - 0000000 ____D C:\Windows\System32\config\TxR 2012-04-22 18:42 - 2010-10-17 21:45 - 0000000 ____D C:\Windows\System32\Drivers\N360 2012-04-22 18:42 - 2010-10-17 21:39 - 0000000 ____D C:\Users\All Users\Norton 2012-04-22 18:42 - 2010-10-17 21:39 - 0000000 ____D C:\ProgramData\Norton 2012-04-22 18:42 - 2009-07-14 04:37 - 0000000 ____D C:\Windows\System32\DriverStore 2012-04-22 18:41 - 2009-07-14 04:37 - 0000000 ____D C:\Windows\registration 2012-04-22 18:41 - 2009-07-14 04:37 - 0000000 ____D C:\Windows\Microsoft.NET 2012-04-22 18:39 - 2010-11-23 20:04 - 0000000 ____D C:\Users\All Users\MySQL 2012-04-22 18:39 - 2010-11-23 20:04 - 0000000 ____D C:\ProgramData\MySQL 2012-04-22 18:38 - 2009-07-14 06:34 - 0014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-04-22 18:38 - 2009-07-14 06:34 - 0014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-04-22 18:34 - 2012-04-22 18:34 - 0000000 ____D C:\Users\David\AppData\Local\{8EB94645-DE0E-4463-94F5-443919F18E11} 2012-04-22 18:34 - 2012-04-22 18:34 - 0000000 ____D C:\Users\David\AppData\Local\{356CE8D9-4112-4097-AAF2-765ADDD5EA9B} 2012-04-18 17:00 - 2012-04-18 16:45 - 0031744 ____A C:\Users\David\Desktop\Löschdienst_summary.doc 2012-04-18 16:41 - 2012-04-18 15:50 - 0066048 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Loeschdienst_Druckl_.xls 2012-04-18 15:47 - 2012-04-18 15:46 - 0084480 ____A C:\Users\David\Desktop\TLF_übersicht.ppt 2012-04-18 15:36 - 2012-04-18 15:01 - 0047616 ____A C:\Users\David\Desktop\TLF_Einsatz_summary.doc 2012-04-18 15:36 - 2012-04-18 10:53 - 0060928 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Einsatz_TLF.xls 2012-04-17 14:28 - 2012-04-17 14:28 - 0000000 ____D C:\Users\David\AppData\Local\{AE6F1A14-B387-42A5-9BE2-B363942ADF31} 2012-04-17 14:28 - 2012-04-17 14:28 - 0000000 ____D C:\Users\David\AppData\Local\{5C6E33D0-2969-423C-AE54-8CD930F9D738} 2012-04-17 14:11 - 2012-04-17 14:11 - 0000000 ____D C:\Users\David\AppData\Local\{0B5E58C9-5824-4864-A6B9-53BCE7ED6F7E} 2012-04-17 14:11 - 2012-04-17 14:11 - 0000000 ____D C:\Users\David\AppData\Local\{018C9489-7539-4670-AC85-DF146FFD71DF} 2012-04-16 06:24 - 2012-04-16 03:28 - 0058782 ____A C:\OTL.Txt 2012-04-16 06:24 - 2012-04-16 03:28 - 0019538 ____A C:\Extras.Txt 2012-04-15 19:22 - 2012-04-15 19:22 - 0065536 __ASH C:\Windows\System32\config\COMPONENTS{88a6a1c9-57bd-11e0-af24-001e3777819a}.TxR.blf 2012-04-09 18:56 - 2012-04-09 18:56 - 0000000 ____D C:\Users\David\AppData\Local\{2334A902-3CBD-4FFB-88A5-1BA3953D4778} 2012-04-09 18:56 - 2012-04-09 18:56 - 0000000 ____D C:\Users\David\AppData\Local\{000D2179-8D69-4DD7-BFB9-973877490E25} 2012-04-09 18:16 - 2012-04-09 18:15 - 0000000 ____D C:\Users\David\AppData\Local\{DE16C105-7869-49D1-9242-FE6602AE2914} 2012-04-09 18:15 - 2012-04-09 18:15 - 0000000 ____D C:\Users\David\AppData\Local\{EDE744F5-A7FF-439D-A315-C8E88E1EDD4F} 2012-04-05 19:59 - 2012-02-27 19:45 - 0000000 ____D C:\Users\All Users\CanonIJPLM 2012-04-05 19:59 - 2012-02-27 19:45 - 0000000 ____D C:\ProgramData\CanonIJPLM 2012-04-04 22:03 - 2012-04-04 22:02 - 0000000 ____D C:\Users\David\AppData\Local\{E6C1F8E9-6C64-4F63-9877-BCF8F0F14338} 2012-04-04 22:03 - 2010-11-16 22:58 - 0001096 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-04-04 22:02 - 2010-10-17 21:21 - 1118539 ____A C:\Windows\WindowsUpdate.log 2012-04-03 18:52 - 2012-04-03 18:52 - 0000000 ____D C:\Users\David\AppData\Local\{F5EE9A91-B0EF-4686-B9F3-47CBEA6D74C7} 2012-04-03 18:52 - 2012-04-03 18:52 - 0000000 ____D C:\Users\David\AppData\Local\{387FD345-4B38-4A24-9A04-054264FFA7F0} 2012-04-02 19:36 - 2012-04-02 19:35 - 0000000 ____D C:\Users\David\AppData\Local\{3E32F5DD-FB69-457E-A624-2F123CB7A8D9} 2012-04-02 19:35 - 2012-04-02 19:35 - 0000000 ____D C:\Users\David\AppData\Local\{3E858585-37B1-4A13-B89E-20407A7CB151} 2012-04-01 18:54 - 2010-10-17 21:31 - 1498506 ____A C:\Windows\System32\PerfStringBackup.INI 2012-04-01 18:52 - 2012-04-01 18:52 - 0000000 ____D C:\Users\David\AppData\Local\{901E1C5F-D0DD-4C2B-A668-C00B7C9C67B6} 2012-04-01 18:51 - 2012-04-01 18:51 - 0000000 ____D C:\Users\David\AppData\Local\{5567838F-7506-43E0-B61B-8EDF976DD6F1} 2012-04-01 18:51 - 2010-10-17 22:13 - 0000000 ____D C:\Users\David\AppData\Roaming\Apple Computer 2012-04-01 18:47 - 2012-04-01 18:47 - 0001753 ____A C:\Users\Public\Desktop\iTunes.lnk 2012-04-01 18:47 - 2012-04-01 18:47 - 0000000 ____D C:\Program Files\iTunes 2012-04-01 18:47 - 2012-04-01 18:47 - 0000000 ____D C:\Program Files\iPod 2012-04-01 18:47 - 2010-10-17 22:11 - 0000000 ____D C:\Program Files\Common Files\Apple 2012-03-21 23:40 - 2012-03-21 23:40 - 0000000 ____D C:\Users\David\AppData\Local\{98FAB908-9C9F-454E-A0C9-4123F9EF0C36} 2012-03-21 23:40 - 2012-03-21 23:40 - 0000000 ____D C:\Users\David\AppData\Local\{7157B293-6B76-49F9-A3FA-45E3C335658C} 2012-03-21 23:38 - 2009-07-14 06:33 - 0411440 ____A C:\Windows\System32\FNTCACHE.DAT 2012-03-21 23:37 - 2010-10-17 21:47 - 0035272 ____A C:\Windows\PFRO.log 2012-03-18 19:20 - 2012-03-18 19:20 - 0020111 ____A C:\Users\David\Desktop\BFTV Bild.png 2012-03-15 21:30 - 2012-03-15 21:30 - 0016896 ____A C:\Users\David\Desktop\Ferien BK.xls 2012-03-15 21:09 - 2009-07-14 04:04 - 0000499 ____A C:\Windows\win.ini 2012-03-12 23:40 - 2012-03-12 23:40 - 0000000 ____D C:\Users\David\AppData\Local\{3103B713-3633-4AB6-A301-C681BCD74556} 2012-03-12 23:40 - 2012-03-12 23:39 - 0000000 ____D C:\Users\David\AppData\Local\{DA59A69E-0B75-4F7F-B595-EA85EE63DBDD} 2012-03-12 20:04 - 2012-03-12 20:04 - 0000000 ____D C:\Users\David\AppData\Local\{45455288-F40B-4EB8-B98D-1EE7CC9B20AC} 2012-03-12 20:04 - 2012-03-12 20:03 - 0000000 ____D C:\Users\David\AppData\Local\{3654259C-2062-4A2F-84FD-4BD65EBB3AE2} 2012-03-12 19:57 - 2009-07-14 04:37 - 0000000 ____D C:\Windows\System32\de-DE 2012-03-11 20:22 - 2012-03-11 20:19 - 0004638 ____A C:\Windows\IE9_main.log 2012-03-11 20:21 - 2012-03-11 20:21 - 9705472 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2012-03-11 20:21 - 2012-03-11 20:21 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-03-11 20:21 - 2012-03-11 20:21 - 1798656 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-03-11 20:21 - 2012-03-11 20:21 - 12282368 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2012-03-11 20:21 - 2012-03-11 20:21 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0072822 ____A C:\Windows\System32\ieuinit.inf 2012-03-11 20:21 - 2012-03-11 20:21 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2012-03-11 20:21 - 2012-03-11 20:21 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2012-03-11 20:21 - 2012-03-11 20:21 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2012-03-11 20:21 - 2012-03-11 20:21 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2012-03-11 20:16 - 2012-03-11 20:16 - 0000000 ____D C:\Users\David\AppData\Local\{B277AD36-4091-4267-BB62-D3A3938991A5} 2012-03-11 20:16 - 2012-03-11 20:16 - 0000000 ____D C:\Users\David\AppData\Local\{67DEEC2F-697A-4DF5-8A58-5972D3AC8C36} 2012-03-04 14:34 - 2012-03-04 12:55 - 0029184 ____A C:\Users\David\Desktop\Lebenslauf_new.doc 2012-03-04 14:33 - 2012-03-04 13:47 - 3247104 ____A C:\Users\David\Desktop\Bewerbung Deckblatt.ppt 2012-03-04 12:39 - 2012-03-04 12:39 - 0034816 ____A C:\Users\David\Desktop\Lebenslauf für Stellenbewerbung.doc 2012-03-03 21:31 - 2012-03-03 19:01 - 0027648 ____A C:\Users\David\Desktop\Bewerbung.doc 2012-03-01 08:20 - 2012-03-01 08:20 - 0000000 ____D C:\Users\David\AppData\Local\{5680FBC4-027C-4F66-BEEF-7DC854273244} 2012-03-01 08:19 - 2012-03-01 08:19 - 0000000 ____D C:\Users\David\AppData\Local\{E67A1408-01B9-481F-AD60-0307030544ED} 2012-02-27 20:30 - 2012-02-27 20:30 - 0000000 ____D C:\Users\David\AppData\Local\{ADE0BEF9-57A7-4E7A-956D-CFDAD5D295C1} 2012-02-27 20:30 - 2012-02-27 20:30 - 0000000 ____D C:\Users\David\AppData\Local\{5A04F38F-4864-4DD8-A1E8-E26786F380E0} 2012-02-27 19:47 - 2012-02-27 19:47 - 0000000 ___HD C:\Users\All Users\CanonIJMyPrinter 2012-02-27 19:47 - 2012-02-27 19:47 - 0000000 ___HD C:\ProgramData\CanonIJMyPrinter 2012-02-27 19:47 - 2011-10-09 19:31 - 0000000 ____D C:\Program Files\Canon 2012-02-27 19:45 - 2012-02-27 19:45 - 0000000 ___HD C:\Users\All Users\CanonIJFAX 2012-02-27 19:45 - 2012-02-27 19:45 - 0000000 ___HD C:\ProgramData\CanonIJFAX 2012-02-27 19:45 - 2012-02-27 19:45 - 0000000 ____D C:\Users\All Users\Canon IJ Network Tool 2012-02-27 19:45 - 2012-02-27 19:45 - 0000000 ____D C:\ProgramData\Canon IJ Network Tool 2012-02-27 19:45 - 2009-07-14 06:52 - 0000000 ____D C:\Windows\twain_32 2012-02-27 19:45 - 2009-07-14 04:37 - 0000000 __RSD C:\Windows\Media 2012-02-27 19:43 - 2012-02-27 19:43 - 0000000 ____D C:\Users\All Users\CanonIJWSpt 2012-02-27 19:43 - 2012-02-27 19:43 - 0000000 ____D C:\ProgramData\CanonIJWSpt 2012-02-27 19:40 - 2012-02-27 19:40 - 0000000 ___HD C:\Windows\System32\CanonIJ Uninstaller Information 2012-02-27 19:39 - 2012-02-27 19:39 - 0000000 ___HD C:\Program Files\CanonBJ 2012-02-27 19:39 - 2012-02-27 19:39 - 0000000 ____D C:\Windows\System32\STRING 2012-02-19 21:59 - 2011-12-06 20:55 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-02-19 21:58 - 2012-02-19 21:58 - 0000000 ____D C:\Users\David\AppData\Local\{8FB367EC-FD00-4DF6-842D-51FAC52AD592} 2012-02-19 21:57 - 2012-02-19 21:57 - 0000000 ____D C:\Users\David\AppData\Local\{853A0345-6631-4E86-94B5-6289CC0F830D} 2012-02-19 21:55 - 2010-10-17 21:26 - 0000174 ___SH C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini 2012-02-19 21:54 - 2010-10-17 21:45 - 0002322 ____A C:\Users\Public\Desktop\Norton 360.lnk 2012-02-19 21:53 - 2010-10-17 21:57 - 0000000 ____D C:\Program Files\Microsoft Silverlight 2012-02-19 21:50 - 2012-02-19 21:39 - 0007597 ____A C:\Users\David\AppData\Local\Resmon.ResmonCfg 2012-02-19 21:46 - 2011-06-17 23:21 - 0000000 ___HD C:\Program Files\InstallShield Installation Information 2012-02-19 21:44 - 2012-02-19 21:44 - 0000000 ____D C:\Users\David\AppData\Local\ElevatedDiagnostics 2012-02-15 11:01 - 2012-02-15 11:01 - 4547944 ____A (Apple, Inc.) C:\Windows\System32\usbaaplrc.dll 2012-02-15 11:01 - 2012-02-15 11:01 - 0043520 ____A (Apple, Inc.) C:\Windows\System32\Drivers\usbaapl.sys 2012-02-15 07:44 - 2012-03-13 23:51 - 0826368 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll 2012-02-15 06:22 - 2012-03-13 23:51 - 0177152 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-02-15 06:22 - 2012-03-13 23:51 - 0024064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys 2012-02-15 01:41 - 2012-02-15 01:40 - 0000000 ____D C:\Users\David\AppData\Local\{2CC84989-B0F1-4FEF-88D4-3DD5B893C7FE} 2012-02-15 01:40 - 2012-02-15 01:40 - 0000000 ____D C:\Users\David\AppData\Local\{3ACF1AAA-29AE-4EB2-9DBA-FD144ADDBB96} 2012-02-10 07:41 - 2012-03-14 19:56 - 1170944 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2012-02-10 07:41 - 2012-03-14 19:56 - 1074176 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2012-02-10 07:41 - 2012-03-14 19:56 - 0739840 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2012-02-10 07:41 - 2012-03-14 19:56 - 0218624 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2012-02-10 07:41 - 2012-03-14 19:56 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2012-02-09 23:42 - 2012-02-09 23:33 - 1220096 ____A C:\Users\David\Desktop\Gutschein für 1mal.doc 2012-02-07 23:22 - 2010-10-17 21:45 - 0000000 ____D C:\Program Files\Symantec 2012-02-07 23:21 - 2010-10-17 21:45 - 0126584 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-02-07 23:21 - 2010-10-17 21:45 - 0007468 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-02-07 23:21 - 2010-10-17 21:45 - 0000806 ____A C:\Windows\System32\Drivers\SYMEVENT.INF 2012-02-07 23:18 - 2011-06-17 16:58 - 0001940 ____A C:\Users\David\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini 2012-02-03 10:34 - 2010-11-22 20:46 - 0000000 ____D C:\Users\David\Desktop\Feuerwehr 2012-02-03 06:01 - 2012-03-14 19:57 - 2341376 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-01-31 21:57 - 2012-01-31 21:57 - 0006451 ____A C:\Users\David\Desktop\Rechnungsausgang.PNG 2012-01-29 12:47 - 2012-01-29 12:47 - 0024487 ____A C:\Users\David\Desktop\Offiziersvorbereitungskurs_AdF_Programm_2012_BFVDT_v0.2[1].pdf 2012-01-25 07:44 - 2012-03-13 23:51 - 0129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-01-25 07:44 - 2012-03-13 23:51 - 0057856 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-01-25 07:40 - 2012-03-13 23:51 - 0008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\User32.dll [2009-07-14 01:24] - [2009-07-14 03:16] - 0811520 ____A (Microsoft Corporation) 34B7E222E81FAFA885F0C5F2CFA56861 C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ========================= Memory info ====================== Percentage of memory in use: 26% Total physical RAM: 3070.43 MB Available physical RAM: 2248.35 MB Total Pagefile: 6139.14 MB Available Pagefile: 5167.84 MB Total Virtual: 2047.88 MB Available Virtual: 1958.08 MB ======================= Partitions ========================= 1 Drive c: () (Fixed) (Total:223.13 GB) (Free:156.33 GB) NTFS ==>[Drive with boot components (obtanied from BCD)] 2 Drive d: (HP_RECOVERY) (Fixed) (Total:9.75 GB) (Free:2.79 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: () (Removable) (Total:1.89 GB) (Free:0.36 GB) FAT Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 232 GB 1024 KB Datentr„ger 1 Online 1936 MB 0 B Partitions of Disk 0: =============== Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 223 GB 31 KB Partition 2 Prim„r 9 GB 223 GB ====================================================================================================== Disk: 0 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 C NTFS Partition 223 GB Fehlerfre System (partition with boot components) ====================================================================================================== Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 D HP_RECOVERY NTFS Partition 9 GB Fehlerfre ====================================================================================================== Partitions of Disk 1: =============== Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 1935 MB 16 KB ====================================================================================================== Disk: 1 Partition 1 Typ : 06 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 F FAT Wechselmed 1935 MB Fehlerfre ====================================================================================================== ========================================================== Last Boot: 2011-07-04 16:17 ======================= End Of Log ========================== |
Zitat:
|
Hier nochmals: Scan result of Farbar Recovery Scan Tool (FRST written by farbar) Version: 16-04-2012 Ran by SYSTEM at 23-04-2012 19:14:57 Running from F:\ Windows 7 Professional (X86) OS Language: German Standard The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [13826664 2009-10-03] (NVIDIA Corporation) HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-07] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM\...\Run: [] [x] HKLM\...\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.) HKLM\...\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2012-02-23] (Apple Inc.) HKLM\...\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM\...\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon [2569616 2010-07-25] (CANON INC.) HKLM\...\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE [452016 2010-09-09] (CANON INC.) HKLM\...\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421736 2012-03-27] (Apple Inc.) HKU\David\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4240760 2010-11-10] (Microsoft Corporation) HKU\David\...\Run: [RemotelessHelper] "C:\Program Files\SpotifyRemotelessHelper\SpotifyRemotelessHelper.exe" [2232320 2011-05-05] () HKU\David\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized [17351304 2011-10-13] (Skype Technologies S.A.) HKU\David\...\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 ================================ Services (Whitelisted) ================== 2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [136176 2010-11-16] (Google Inc.) 3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [136176 2010-11-16] (Google Inc.) 2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [137680 2010-07-27] () 2 MDM; "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" [322120 2003-06-19] (Microsoft Corporation) 2 N360; "C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe" /s "N360" /m "C:\Program Files\Norton 360\Engine\5.2.0.13\diMaster.dll" /prefetch:1 [262584 2011-04-01] (Symantec Corporation) 3 StorSvc; C:\Windows\System32\storsvc.dll [16384 2009-07-14] (Microsoft Corporation) 2 vpnagent; "C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe" [493248 2009-10-09] (Cisco Systems, Inc.) ========================== Drivers (Whitelisted) ============= 3 ATSwpWDF; C:\Windows\System32\Drivers\ATSwpWDF.sys [625224 2009-12-03] (AuthenTec, Inc.) 1 BHDrvx86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20120317.002\BHDrvx86.sys [820856 2012-03-02] (Symantec Corporation) 1 eeCtrl; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [374392 2012-02-15] (Symantec Corporation) 3 EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [106104 2012-02-05] (Symantec Corporation) 3 HpqRemHid; C:\Windows\System32\DRIVERS\HpqRemHid.sys [7168 2007-07-11] (Hewlett-Packard Development Company, L.P.) 1 IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120401.001\IDSvix86.sys [368248 2012-02-14] (Symantec Corporation) 2 MySQL; "C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld" --defaults-file="C:\Program Files\MySQL\MySQL Server 5.1\my.ini" MySQL [8960 2010-11-23] () 3 NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120402.002\NAVENG.SYS [86136 2012-02-02] (Symantec Corporation) 3 NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120402.002\NAVEX15.SYS [1576312 2012-02-02] (Symantec Corporation) 3 netw5v32; C:\Windows\System32\DRIVERS\netw5v32.sys [4231168 2009-07-13] (Intel Corporation) 2 rimmptsk; C:\Windows\System32\DRIVERS\rimmptsk.sys [48128 2009-06-25] (REDC) 2 rimsptsk; C:\Windows\System32\DRIVERS\rimsptsk.sys [44544 2009-06-25] (REDC) 2 rismxdp; C:\Windows\System32\DRIVERS\rixdptsk.sys [38400 2009-06-25] (REDC) 3 smserial; C:\Windows\System32\DRIVERS\smserial.sys [1068032 2009-07-13] (Motorola Inc.) 3 SRTSP; C:\Windows\System32\Drivers\N360\0502000.00D\SRTSP.SYS [516216 2011-03-31] (Symantec Corporation) 1 SRTSPX; C:\Windows\System32\drivers\N360\0502000.00D\SRTSPX.SYS [50168 2011-03-31] (Symantec Corporation) 0 SymDS; C:\Windows\System32\drivers\N360\0502000.00D\SYMDS.SYS [340088 2011-01-27] (Symantec Corporation) 0 SymEFA; C:\Windows\System32\drivers\N360\0502000.00D\SYMEFA.SYS [744568 2011-03-15] (Symantec Corporation) 3 SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [126584 2012-02-07] (Symantec Corporation) 1 SymIRON; C:\Windows\System32\drivers\N360\0502000.00D\Ironx86.SYS [136312 2011-01-27] (Symantec Corporation) 1 SymNetS; C:\Windows\System32\Drivers\N360\0502000.00D\SYMNETS.SYS [299640 2011-04-21] (Symantec Corporation) 3 vpnva; C:\Windows\System32\DRIVERS\vpnva.sys [20152 2009-10-09] (Cisco Systems, Inc.) ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-04-23 18:09 - 2012-02-28 02:52 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-04-23 18:09 - 2012-02-28 02:03 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-04-23 18:09 - 2011-08-27 15:22 - 0000000 __SHD C:\Config.Msi 2012-04-23 18:08 - 2012-03-11 19:21 - 9705984 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-04-23 18:08 - 2012-03-11 19:21 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-04-23 18:08 - 2012-03-11 19:21 - 12281856 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-04-23 18:08 - 2012-03-11 19:21 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-04-23 18:08 - 2012-02-28 02:18 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-04-23 18:08 - 2012-02-28 02:09 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-04-23 18:08 - 2012-02-28 02:06 - 1799168 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-04-23 18:08 - 2011-03-08 06:38 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-04-23 18:08 - 2010-12-21 06:38 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-04-23 18:08 - 2010-09-22 23:21 - 0019312 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys 2012-04-23 18:08 - 2009-07-14 02:16 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-04-23 18:08 - 2009-07-14 02:16 - 0172544 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2012-04-23 18:08 - 2009-07-14 02:14 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-04-23 18:08 - 2009-07-14 02:14 - 0158720 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll 2012-04-23 18:08 - 2009-07-14 02:11 - 0005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll 2012-04-23 18:06 - 2009-07-14 02:16 - 3902320 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-04-23 18:06 - 2009-07-13 22:40 - 3958128 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2012-04-22 17:46 - 2011-08-21 18:31 - 0000000 ____D C:\Users\David\AppData\Local\{0A70500B-8C44-466C-A6E5-29014A6610E3} 2012-04-22 17:46 - 2011-05-29 17:53 - 0000000 ____D C:\Users\David\AppData\Local\{75580811-E74C-4082-B102-98CB6F457A9C} 2012-04-22 17:34 - 2011-10-07 14:26 - 0000000 ____D C:\Users\David\AppData\Local\{8EB94645-DE0E-4463-94F5-443919F18E11} 2012-04-22 17:34 - 2011-09-07 17:37 - 0000000 ____D C:\Users\David\AppData\Local\{356CE8D9-4112-4097-AAF2-765ADDD5EA9B} 2012-04-18 15:45 - 2011-09-11 17:53 - 0031744 ____A C:\Users\David\Desktop\Löschdienst_summary.doc 2012-04-18 14:50 - 2012-04-18 14:36 - 0066048 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Loeschdienst_Druckl_.xls 2012-04-18 14:46 - 2012-04-18 14:36 - 0084480 ____A C:\Users\David\Desktop\TLF_übersicht.ppt 2012-04-18 14:01 - 2011-09-22 18:42 - 0047616 ____A C:\Users\David\Desktop\TLF_Einsatz_summary.doc 2012-04-18 09:53 - 2012-02-09 22:42 - 0060928 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Einsatz_TLF.xls 2012-04-17 13:28 - 2012-02-27 19:30 - 0000000 ____D C:\Users\David\AppData\Local\{AE6F1A14-B387-42A5-9BE2-B363942ADF31} 2012-04-17 13:28 - 2011-09-01 16:50 - 0000000 ____D C:\Users\David\AppData\Local\{5C6E33D0-2969-423C-AE54-8CD930F9D738} 2012-04-17 13:11 - 2012-01-02 20:25 - 0000000 ____D C:\Users\David\AppData\Local\{0B5E58C9-5824-4864-A6B9-53BCE7ED6F7E} 2012-04-17 13:11 - 2011-11-17 23:20 - 0000000 ____D C:\Users\David\AppData\Local\{018C9489-7539-4670-AC85-DF146FFD71DF} 2012-04-17 10:50 - 2012-04-16 05:24 - 0000000 ____D C:\FRST 2012-04-16 02:28 - 2010-11-23 19:06 - 0058782 ____A C:\OTL.Txt 2012-04-16 02:28 - 2010-10-17 20:26 - 0019538 ____A C:\Extras.Txt 2012-04-09 17:56 - 2011-08-31 14:34 - 0000000 ____D C:\Users\David\AppData\Local\{2334A902-3CBD-4FFB-88A5-1BA3953D4778} 2012-04-09 17:56 - 2011-06-17 21:28 - 0000000 ____D C:\Users\David\AppData\Local\{000D2179-8D69-4DD7-BFB9-973877490E25} 2012-04-09 17:15 - 2012-04-04 21:03 - 0000000 ____D C:\Users\David\AppData\Local\{EDE744F5-A7FF-439D-A315-C8E88E1EDD4F} 2012-04-09 17:15 - 2011-08-16 21:27 - 0000000 ____D C:\Users\David\AppData\Local\{DE16C105-7869-49D1-9242-FE6602AE2914} 2012-04-04 21:02 - 2012-03-01 07:19 - 0000000 ____D C:\Users\David\AppData\Local\{E6C1F8E9-6C64-4F63-9877-BCF8F0F14338} 2012-04-03 17:52 - 2012-01-11 19:45 - 0000000 ____D C:\Users\David\AppData\Local\{F5EE9A91-B0EF-4686-B9F3-47CBEA6D74C7} 2012-04-03 17:52 - 2011-11-20 20:27 - 0000000 ____D C:\Users\David\AppData\Local\{387FD345-4B38-4A24-9A04-054264FFA7F0} 2012-04-02 18:35 - 2012-04-02 18:36 - 0000000 ____D C:\Users\David\AppData\Local\{3E858585-37B1-4A13-B89E-20407A7CB151} 2012-04-02 18:35 - 2011-08-20 08:01 - 0000000 ____D C:\Users\David\AppData\Local\{3E32F5DD-FB69-457E-A624-2F123CB7A8D9} 2012-04-01 17:52 - 2011-10-22 09:30 - 0000000 ____D C:\Users\David\AppData\Local\{901E1C5F-D0DD-4C2B-A668-C00B7C9C67B6} 2012-04-01 17:51 - 2011-10-15 10:33 - 0000000 ____D C:\Users\David\AppData\Local\{5567838F-7506-43E0-B61B-8EDF976DD6F1} 2012-04-01 17:47 - 2012-04-23 18:12 - 0000000 ____D C:\Program Files\iPod 2012-04-01 17:47 - 2012-04-01 17:47 - 0000000 ____D C:\Program Files\iTunes 2012-04-01 17:47 - 2011-11-22 19:19 - 0001753 ____A C:\Users\Public\Desktop\iTunes.lnk ============ 3 Months Modified Files and Folders =============== 2012-04-23 19:15 - 2012-04-17 10:50 - 0000000 ____D C:\FRST 2012-04-23 18:12 - 2012-04-23 18:09 - 0000000 __SHD C:\Config.Msi 2012-04-23 18:12 - 2010-11-16 21:58 - 0001092 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-04-23 18:12 - 2010-10-17 20:21 - 1308286 ____A C:\Windows\WindowsUpdate.log 2012-04-23 18:10 - 2010-10-17 20:31 - 1519874 ____A C:\Windows\System32\PerfStringBackup.INI 2012-04-23 18:08 - 2009-07-14 03:04 - 0000499 ____A C:\Windows\win.ini 2012-04-23 18:06 - 2012-02-27 18:45 - 0000000 ____D C:\Users\All Users\CanonIJPLM 2012-04-23 18:06 - 2012-02-27 18:45 - 0000000 ____D C:\ProgramData\CanonIJPLM 2012-04-23 18:05 - 2010-11-16 21:58 - 0001096 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-04-22 19:40 - 2011-01-16 20:31 - 0000000 ____D C:\Users\David\AppData\Roaming\Skype 2012-04-22 17:52 - 2009-07-14 05:34 - 0014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-04-22 17:52 - 2009-07-14 05:34 - 0014848 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-04-22 17:49 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\config\TxR 2012-04-22 17:47 - 2012-04-22 17:46 - 0000000 ____D C:\Users\David\AppData\Local\{0A70500B-8C44-466C-A6E5-29014A6610E3} 2012-04-22 17:46 - 2012-04-22 17:46 - 0000000 ____D C:\Users\David\AppData\Local\{75580811-E74C-4082-B102-98CB6F457A9C} 2012-04-22 17:46 - 2009-07-14 05:39 - 0030023 ____A C:\Windows\setupact.log 2012-04-22 17:44 - 2010-10-17 20:26 - 0000000 ____D C:\users\David 2012-04-22 17:44 - 2010-10-17 20:18 - 2414682112 __ASH C:\hiberfil.sys 2012-04-22 17:44 - 2009-07-14 05:53 - 0000006 ___AH C:\Windows\Tasks\SA.DAT 2012-04-22 17:44 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\wfp 2012-04-22 17:42 - 2010-10-17 20:45 - 0000000 ____D C:\Windows\System32\Drivers\N360 2012-04-22 17:42 - 2010-10-17 20:39 - 0000000 ____D C:\Users\All Users\Norton 2012-04-22 17:42 - 2010-10-17 20:39 - 0000000 ____D C:\ProgramData\Norton 2012-04-22 17:42 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\DriverStore 2012-04-22 17:41 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\registration 2012-04-22 17:41 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\Microsoft.NET 2012-04-22 17:39 - 2010-11-23 19:04 - 0000000 ____D C:\Users\All Users\MySQL 2012-04-22 17:39 - 2010-11-23 19:04 - 0000000 ____D C:\ProgramData\MySQL 2012-04-22 17:34 - 2012-04-22 17:34 - 0000000 ____D C:\Users\David\AppData\Local\{8EB94645-DE0E-4463-94F5-443919F18E11} 2012-04-22 17:34 - 2012-04-22 17:34 - 0000000 ____D C:\Users\David\AppData\Local\{356CE8D9-4112-4097-AAF2-765ADDD5EA9B} 2012-04-18 16:00 - 2012-04-18 15:45 - 0031744 ____A C:\Users\David\Desktop\Löschdienst_summary.doc 2012-04-18 15:41 - 2012-04-18 14:50 - 0066048 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Loeschdienst_Druckl_.xls 2012-04-18 14:47 - 2012-04-18 14:46 - 0084480 ____A C:\Users\David\Desktop\TLF_übersicht.ppt 2012-04-18 14:36 - 2012-04-18 14:01 - 0047616 ____A C:\Users\David\Desktop\TLF_Einsatz_summary.doc 2012-04-18 14:36 - 2012-04-18 09:53 - 0060928 ____A C:\Users\David\Desktop\HD_Lektionsvorbereitung_Einsatz_TLF.xls 2012-04-17 13:28 - 2012-04-17 13:28 - 0000000 ____D C:\Users\David\AppData\Local\{AE6F1A14-B387-42A5-9BE2-B363942ADF31} 2012-04-17 13:28 - 2012-04-17 13:28 - 0000000 ____D C:\Users\David\AppData\Local\{5C6E33D0-2969-423C-AE54-8CD930F9D738} 2012-04-17 13:11 - 2012-04-17 13:11 - 0000000 ____D C:\Users\David\AppData\Local\{0B5E58C9-5824-4864-A6B9-53BCE7ED6F7E} 2012-04-17 13:11 - 2012-04-17 13:11 - 0000000 ____D C:\Users\David\AppData\Local\{018C9489-7539-4670-AC85-DF146FFD71DF} 2012-04-16 05:24 - 2012-04-16 02:28 - 0058782 ____A C:\OTL.Txt 2012-04-16 05:24 - 2012-04-16 02:28 - 0019538 ____A C:\Extras.Txt 2012-04-09 17:56 - 2012-04-09 17:56 - 0000000 ____D C:\Users\David\AppData\Local\{2334A902-3CBD-4FFB-88A5-1BA3953D4778} 2012-04-09 17:56 - 2012-04-09 17:56 - 0000000 ____D C:\Users\David\AppData\Local\{000D2179-8D69-4DD7-BFB9-973877490E25} 2012-04-09 17:16 - 2012-04-09 17:15 - 0000000 ____D C:\Users\David\AppData\Local\{DE16C105-7869-49D1-9242-FE6602AE2914} 2012-04-09 17:15 - 2012-04-09 17:15 - 0000000 ____D C:\Users\David\AppData\Local\{EDE744F5-A7FF-439D-A315-C8E88E1EDD4F} 2012-04-04 21:03 - 2012-04-04 21:02 - 0000000 ____D C:\Users\David\AppData\Local\{E6C1F8E9-6C64-4F63-9877-BCF8F0F14338} 2012-04-03 17:52 - 2012-04-03 17:52 - 0000000 ____D C:\Users\David\AppData\Local\{F5EE9A91-B0EF-4686-B9F3-47CBEA6D74C7} 2012-04-03 17:52 - 2012-04-03 17:52 - 0000000 ____D C:\Users\David\AppData\Local\{387FD345-4B38-4A24-9A04-054264FFA7F0} 2012-04-02 18:36 - 2012-04-02 18:35 - 0000000 ____D C:\Users\David\AppData\Local\{3E32F5DD-FB69-457E-A624-2F123CB7A8D9} 2012-04-02 18:35 - 2012-04-02 18:35 - 0000000 ____D C:\Users\David\AppData\Local\{3E858585-37B1-4A13-B89E-20407A7CB151} 2012-04-01 17:52 - 2012-04-01 17:52 - 0000000 ____D C:\Users\David\AppData\Local\{901E1C5F-D0DD-4C2B-A668-C00B7C9C67B6} 2012-04-01 17:51 - 2012-04-01 17:51 - 0000000 ____D C:\Users\David\AppData\Local\{5567838F-7506-43E0-B61B-8EDF976DD6F1} 2012-04-01 17:51 - 2010-10-17 21:13 - 0000000 ____D C:\Users\David\AppData\Roaming\Apple Computer 2012-04-01 17:47 - 2012-04-01 17:47 - 0001753 ____A C:\Users\Public\Desktop\iTunes.lnk 2012-04-01 17:47 - 2012-04-01 17:47 - 0000000 ____D C:\Program Files\iTunes 2012-04-01 17:47 - 2012-04-01 17:47 - 0000000 ____D C:\Program Files\iPod 2012-04-01 17:47 - 2010-10-17 21:11 - 0000000 ____D C:\Program Files\Common Files\Apple 2012-03-21 22:40 - 2012-03-21 22:40 - 0000000 ____D C:\Users\David\AppData\Local\{98FAB908-9C9F-454E-A0C9-4123F9EF0C36} 2012-03-21 22:40 - 2012-03-21 22:40 - 0000000 ____D C:\Users\David\AppData\Local\{7157B293-6B76-49F9-A3FA-45E3C335658C} 2012-03-21 22:38 - 2009-07-14 05:33 - 0411440 ____A C:\Windows\System32\FNTCACHE.DAT 2012-03-21 22:37 - 2010-10-17 20:47 - 0035272 ____A C:\Windows\PFRO.log 2012-03-18 18:20 - 2012-03-18 18:20 - 0020111 ____A C:\Users\David\Desktop\BFTV Bild.png 2012-03-15 20:30 - 2012-03-15 20:30 - 0016896 ____A C:\Users\David\Desktop\Ferien BK.xls 2012-03-12 22:40 - 2012-03-12 22:40 - 0000000 ____D C:\Users\David\AppData\Local\{3103B713-3633-4AB6-A301-C681BCD74556} 2012-03-12 22:40 - 2012-03-12 22:39 - 0000000 ____D C:\Users\David\AppData\Local\{DA59A69E-0B75-4F7F-B595-EA85EE63DBDD} 2012-03-12 19:04 - 2012-03-12 19:04 - 0000000 ____D C:\Users\David\AppData\Local\{45455288-F40B-4EB8-B98D-1EE7CC9B20AC} 2012-03-12 19:04 - 2012-03-12 19:03 - 0000000 ____D C:\Users\David\AppData\Local\{3654259C-2062-4A2F-84FD-4BD65EBB3AE2} 2012-03-12 18:57 - 2009-07-14 03:37 - 0000000 ____D C:\Windows\System32\de-DE 2012-03-11 19:22 - 2012-03-11 19:19 - 0004638 ____A C:\Windows\IE9_main.log 2012-03-11 19:21 - 2012-03-11 19:21 - 3695416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2012-03-11 19:21 - 2012-03-11 19:21 - 0580608 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0434176 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0367104 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2012-03-11 19:21 - 2012-03-11 19:21 - 0353792 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0353584 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0227840 ____A (Microsoft Corporation) C:\Windows\System32\ieaksie.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0223232 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0203776 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0163840 ____A (Microsoft Corporation) C:\Windows\System32\ieakui.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0162304 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0152064 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0130560 ____A (Microsoft Corporation) C:\Windows\System32\ieakeng.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0123392 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0118784 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0101888 ____A (Microsoft Corporation) C:\Windows\System32\admparse.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0086528 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0078848 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0076800 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0074752 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0074240 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0072822 ____A C:\Windows\System32\ieuinit.inf 2012-03-11 19:21 - 2012-03-11 19:21 - 0066048 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0063488 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2012-03-11 19:21 - 2012-03-11 19:21 - 0054272 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0041472 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0035840 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0031744 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0023552 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2012-03-11 19:21 - 2012-03-11 19:21 - 0011776 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2012-03-11 19:21 - 2012-03-11 19:21 - 0010752 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2012-03-11 19:16 - 2012-03-11 19:16 - 0000000 ____D C:\Users\David\AppData\Local\{B277AD36-4091-4267-BB62-D3A3938991A5} 2012-03-11 19:16 - 2012-03-11 19:16 - 0000000 ____D C:\Users\David\AppData\Local\{67DEEC2F-697A-4DF5-8A58-5972D3AC8C36} 2012-03-06 06:59 - 2012-04-23 18:06 - 3958128 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2012-03-06 06:59 - 2012-04-23 18:06 - 3902320 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-03-04 13:34 - 2012-03-04 11:55 - 0029184 ____A C:\Users\David\Desktop\Lebenslauf_new.doc 2012-03-04 13:33 - 2012-03-04 12:47 - 3247104 ____A C:\Users\David\Desktop\Bewerbung Deckblatt.ppt 2012-03-04 11:39 - 2012-03-04 11:39 - 0034816 ____A C:\Users\David\Desktop\Lebenslauf für Stellenbewerbung.doc 2012-03-03 20:31 - 2012-03-03 18:01 - 0027648 ____A C:\Users\David\Desktop\Bewerbung.doc 2012-03-01 07:20 - 2012-03-01 07:20 - 0000000 ____D C:\Users\David\AppData\Local\{5680FBC4-027C-4F66-BEEF-7DC854273244} 2012-03-01 07:19 - 2012-03-01 07:19 - 0000000 ____D C:\Users\David\AppData\Local\{E67A1408-01B9-481F-AD60-0307030544ED} 2012-03-01 06:53 - 2012-04-23 18:08 - 0019312 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fs_rec.sys 2012-03-01 06:49 - 2012-04-23 18:08 - 0172544 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2012-03-01 06:45 - 2012-04-23 18:08 - 0158720 ____A (Microsoft Corporation) C:\Windows\System32\imagehlp.dll 2012-03-01 06:40 - 2012-04-23 18:08 - 0005120 ____A (Microsoft Corporation) C:\Windows\System32\wmi.dll 2012-02-28 02:52 - 2012-04-23 18:08 - 12281856 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-02-28 02:27 - 2012-04-23 18:08 - 9705984 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-02-28 02:18 - 2012-04-23 18:08 - 1799168 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-02-28 02:12 - 2012-04-23 18:08 - 1103360 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-02-28 02:11 - 2012-04-23 18:08 - 1427456 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-02-28 02:11 - 2012-04-23 18:08 - 1127424 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-02-28 02:09 - 2012-04-23 18:08 - 0231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-02-28 02:08 - 2012-04-23 18:08 - 0065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-02-28 02:06 - 2012-04-23 18:08 - 0716800 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-02-28 02:04 - 2012-04-23 18:08 - 1792000 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-02-28 02:03 - 2012-04-23 18:09 - 2382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-02-28 02:03 - 2012-04-23 18:09 - 0072704 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-02-28 01:59 - 2012-04-23 18:08 - 0176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-02-27 19:30 - 2012-02-27 19:30 - 0000000 ____D C:\Users\David\AppData\Local\{ADE0BEF9-57A7-4E7A-956D-CFDAD5D295C1} 2012-02-27 19:30 - 2012-02-27 19:30 - 0000000 ____D C:\Users\David\AppData\Local\{5A04F38F-4864-4DD8-A1E8-E26786F380E0} 2012-02-27 18:47 - 2012-02-27 18:47 - 0000000 ___HD C:\Users\All Users\CanonIJMyPrinter 2012-02-27 18:47 - 2012-02-27 18:47 - 0000000 ___HD C:\ProgramData\CanonIJMyPrinter 2012-02-27 18:47 - 2011-10-09 18:31 - 0000000 ____D C:\Program Files\Canon 2012-02-27 18:45 - 2012-02-27 18:45 - 0000000 ___HD C:\Users\All Users\CanonIJFAX 2012-02-27 18:45 - 2012-02-27 18:45 - 0000000 ___HD C:\ProgramData\CanonIJFAX 2012-02-27 18:45 - 2012-02-27 18:45 - 0000000 ____D C:\Users\All Users\Canon IJ Network Tool 2012-02-27 18:45 - 2012-02-27 18:45 - 0000000 ____D C:\ProgramData\Canon IJ Network Tool 2012-02-27 18:45 - 2009-07-14 05:52 - 0000000 ____D C:\Windows\twain_32 2012-02-27 18:45 - 2009-07-14 03:37 - 0000000 __RSD C:\Windows\Media 2012-02-27 18:43 - 2012-02-27 18:43 - 0000000 ____D C:\Users\All Users\CanonIJWSpt 2012-02-27 18:43 - 2012-02-27 18:43 - 0000000 ____D C:\ProgramData\CanonIJWSpt 2012-02-27 18:40 - 2012-02-27 18:40 - 0000000 ___HD C:\Windows\System32\CanonIJ Uninstaller Information 2012-02-27 18:39 - 2012-02-27 18:39 - 0000000 ___HD C:\Program Files\CanonBJ 2012-02-27 18:39 - 2012-02-27 18:39 - 0000000 ____D C:\Windows\System32\STRING 2012-02-19 20:59 - 2011-12-06 19:55 - 0414368 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-02-19 20:58 - 2012-02-19 20:58 - 0000000 ____D C:\Users\David\AppData\Local\{8FB367EC-FD00-4DF6-842D-51FAC52AD592} 2012-02-19 20:57 - 2012-02-19 20:57 - 0000000 ____D C:\Users\David\AppData\Local\{853A0345-6631-4E86-94B5-6289CC0F830D} 2012-02-19 20:55 - 2010-10-17 20:26 - 0000174 ___SH C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini 2012-02-19 20:54 - 2010-10-17 20:45 - 0002322 ____A C:\Users\Public\Desktop\Norton 360.lnk 2012-02-19 20:53 - 2010-10-17 20:57 - 0000000 ____D C:\Program Files\Microsoft Silverlight 2012-02-19 20:50 - 2012-02-19 20:39 - 0007597 ____A C:\Users\David\AppData\Local\Resmon.ResmonCfg 2012-02-19 20:46 - 2011-06-17 22:21 - 0000000 ___HD C:\Program Files\InstallShield Installation Information 2012-02-19 20:44 - 2012-02-19 20:44 - 0000000 ____D C:\Users\David\AppData\Local\ElevatedDiagnostics 2012-02-15 10:01 - 2012-02-15 10:01 - 4547944 ____A (Apple, Inc.) C:\Windows\System32\usbaaplrc.dll 2012-02-15 10:01 - 2012-02-15 10:01 - 0043520 ____A (Apple, Inc.) C:\Windows\System32\Drivers\usbaapl.sys 2012-02-15 06:44 - 2012-03-13 22:51 - 0826368 ____A (Microsoft Corporation) C:\Windows\System32\rdpcore.dll 2012-02-15 05:22 - 2012-03-13 22:51 - 0177152 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys 2012-02-15 05:22 - 2012-03-13 22:51 - 0024064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tdtcp.sys 2012-02-15 00:41 - 2012-02-15 00:40 - 0000000 ____D C:\Users\David\AppData\Local\{2CC84989-B0F1-4FEF-88D4-3DD5B893C7FE} 2012-02-15 00:40 - 2012-02-15 00:40 - 0000000 ____D C:\Users\David\AppData\Local\{3ACF1AAA-29AE-4EB2-9DBA-FD144ADDBB96} 2012-02-10 06:41 - 2012-03-14 18:56 - 1170944 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2012-02-10 06:41 - 2012-03-14 18:56 - 1074176 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2012-02-10 06:41 - 2012-03-14 18:56 - 0739840 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2012-02-10 06:41 - 2012-03-14 18:56 - 0218624 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2012-02-10 06:41 - 2012-03-14 18:56 - 0161792 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2012-02-09 22:42 - 2012-02-09 22:33 - 1220096 ____A C:\Users\David\Desktop\Gutschein für 1mal.doc 2012-02-07 22:22 - 2010-10-17 20:45 - 0000000 ____D C:\Program Files\Symantec 2012-02-07 22:21 - 2010-10-17 20:45 - 0126584 ____A (Symantec Corporation) C:\Windows\System32\Drivers\SYMEVENT.SYS 2012-02-07 22:21 - 2010-10-17 20:45 - 0007468 ____A C:\Windows\System32\Drivers\SYMEVENT.CAT 2012-02-07 22:21 - 2010-10-17 20:45 - 0000806 ____A C:\Windows\System32\Drivers\SYMEVENT.INF 2012-02-07 22:18 - 2011-06-17 15:58 - 0001940 ____A C:\Users\David\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini 2012-02-03 09:34 - 2010-11-22 19:46 - 0000000 ____D C:\Users\David\Desktop\Feuerwehr 2012-02-03 05:01 - 2012-03-14 18:57 - 2341376 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-01-31 20:57 - 2012-01-31 20:57 - 0006451 ____A C:\Users\David\Desktop\Rechnungsausgang.PNG 2012-01-29 11:47 - 2012-01-29 11:47 - 0024487 ____A C:\Users\David\Desktop\Offiziersvorbereitungskurs_AdF_Programm_2012_BFVDT_v0.2[1].pdf 2012-01-25 06:44 - 2012-03-13 22:51 - 0129536 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll 2012-01-25 06:44 - 2012-03-13 22:51 - 0057856 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll 2012-01-25 06:40 - 2012-03-13 22:51 - 0008192 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\User32.dll [2009-07-14 00:24] - [2009-07-14 02:16] - 0811520 ____A (Microsoft Corporation) 34B7E222E81FAFA885F0C5F2CFA56861 C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ========================= Memory info ====================== Percentage of memory in use: 11% Total physical RAM: 4094.43 MB Available physical RAM: 3631.79 MB Total Pagefile: 4092.71 MB Available Pagefile: 3631.52 MB Total Virtual: 2047.88 MB Available Virtual: 1967.2 MB ======================= Partitions ========================= 1 Drive c: () (Fixed) (Total:223.13 GB) (Free:153.08 GB) NTFS ==>[Drive with boot components (obtanied from BCD)] 2 Drive d: (HP_RECOVERY) (Fixed) (Total:9.75 GB) (Free:2.79 GB) NTFS ==>[System with boot components (obtained from reading drive)] 4 Drive f: () (Removable) (Total:1.89 GB) (Free:0.36 GB) FAT 5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 232 GB 1024 KB Datentr„ger 1 Online 1936 MB 0 B Partitions of Disk 0: =============== Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 223 GB 31 KB Partition 2 Prim„r 9 GB 223 GB ====================================================================================================== Disk: 0 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 C NTFS Partition 223 GB Fehlerfre ====================================================================================================== Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 D HP_RECOVERY NTFS Partition 9 GB Fehlerfre ====================================================================================================== Partitions of Disk 1: =============== Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 1935 MB 16 KB ====================================================================================================== Disk: 1 Partition 1 Typ : 06 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 F FAT Wechselmed 1935 MB Fehlerfre ====================================================================================================== ========================================================== Last Boot: 2011-07-04 15:17 ======================= End Of Log ========================== |
Schritt 1: Fix mit FRST Drücke bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKLM\...\Run: [] [x]
Schließe FRST64. Gib folgende Befehle ein (gefolgt von Enter): Code: copy C:\OTL.Txt F: Kann der Rechner wieder gestartet werden? |
Der Computer startet wider ja. Hier die drei files Fixlog: Fix result of Farbar Recovery Tool (FRST written by farbar) Version: 16-04-2012 Ran by SYSTEM at 2012-04-24 22:54:56 R:1 Running from F:\ ============================================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HKLM\...\Run: [] [x] Value not found. ==== End of Fixlog ==== Extras:OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 4/16/2012 12:22:06 AM - Run OTL:OTL Logfile: OTL EXTRAS Logfile: Code: OTL logfile created on: 4/16/2012 12:22:06 AM - Run --- --- --- |
Schritt 1: defogger Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Klicke den Re-enable Button nicht ohne Anweisung. Schritt 2: GMER Bitte
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:18 Uhr. |
Copyright ©2000-2025, Trojaner-Board