Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 17.11.2013, 18:11   #16
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 17.11.2013, 19:14   #17
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Hallo.Geht bei mir leider nur so. FRST Additions Logfile:
[CODE]Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-11-2013 01
Ran by KH at 2013-11-17 08:47:26
Running from D:\Users\KH\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

Update for Microsoft Office 2007 (KB2508958)
2007 Microsoft Office system (Version: 12.0.6612.1000)
Adobe AIR (Version: 3.7.0.2090)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.152)
Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05)
Adobe Shockwave Player 12.0 (Version: 12.0.3.133)
Advanced System Optimizer (Version: 3.5.1000.15564)
AuthenTec TrueSuite (Version: 2.0.0.57)
Avira Internet Security Suite (Version: 14.0.1.719)
BEWERBUNGSMASTER
Canon MP250 series MP Drivers
D3DX10 (Version: 15.4.2368.0902)
DVD Audio Extractor 7.1.1
Fotogalerie (Version: 16.4.3508.0205)
FreePDF (Remove only)
GeForce Experience NvStream Client Components (Version: 1.6.28)
GPL Ghostscript 8.70
Hardcopy (Version: 2013.11.01)
HIGHRESAUDIO Manager 1.0 (Version: 1.0)
Intel® Matrix Storage Manager und Intel® Turbo Memory
Intel® Turbo Memory
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Junk Mail filter update (Version: 16.4.3508.0205)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office Outlook Connector (Version: 14.0.5118.5000)
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server Compact 3.5 SP1 English (Version: 3.5.5692.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Movie Maker (Version: 16.4.3508.0205)
MSVC80_x86 (Version: 1.0.1.0)
MSVC80_x86_v2 (Version: 1.0.3.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT110 (Version: 16.4.1108.0727)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Nero 12 (Version: 12.0.02900)
Nero 12 Content Pack (Version: 12.0.00400)
Nero Abstract Themes (Version: 12.0.11500)
Nero Audio Pack 1 (Version: 11.0.11500.110.0)
Nero BackItUp (Version: 12.5.11000)
Nero BackItUp Help (CHM) (Version: 12.0.13000)
Nero Blu-ray Player (Version: 12.0.20051)
Nero Blu-ray Player Help (CHM) (Version: 15.0.00015)
Nero Burning ROM (Version: 12.5.6000)
Nero Burning ROM Help (CHM) (Version: 12.0.3000)
Nero Cliparts (Version: 12.0.11500)
Nero ControlCenter (Version: 11.0.16700)
Nero ControlCenter Help (CHM) (Version: 15.0.00015)
Nero Core Components (Version: 11.0.22500)
Nero CoverDesigner (Version: 12.0.01500)
Nero CoverDesigner (Version: 12.0.10003)
Nero CoverDesigner Help (CHM) (Version: 12.0.2000)
Nero Disc Menus 1 (Version: 12.0.11500)
Nero Disc Menus 2 (Version: 12.0.11500)
Nero Disc Menus 3 (Version: 12.0.11500)
Nero Disc Menus Basic (Version: 12.0.11500)
Nero Effects Basic (Version: 15.0.10011)
Nero Express (Version: 12.5.7000)
Nero Express Help (CHM) (Version: 12.0.13000)
Nero Family and Events Themes (Version: 12.0.11500)
Nero Football (Soccer) Themes (Version: 12.0.11500)
Nero Holiday and Sports Themes (Version: 12.0.11500)
Nero Image Samples (Version: 15.0.10008)
Nero Info (Version: 15.1.0025)
Nero Kwik Themes Basic (Version: 12.0.11500)
Nero MediaHome (Version: 1.20.8300)
Nero MediaHome Help (CHM) (Version: 15.0.00018)
Nero PiP Effects 1 (Version: 12.0.11500)
Nero PiP Effects Basic (Version: 15.0.10008)
Nero Platinum Effects 12 (Version: 15.0.10011)
Nero Recode (Version: 12.5.6000)
Nero Recode Help (CHM) (Version: 12.0.12000)
Nero RescueAgent (Version: 12.0.11000)
Nero RescueAgent Help (CHM) (Version: 12.0.7000)
Nero Retro Film Themes (Version: 12.0.11700)
Nero SharedVideoCodecs (Version: 1.0.15003)
Nero SoundTrax (Version: 12.0.01700)
Nero SoundTrax (Version: 12.0.8000)
Nero SoundTrax Help (CHM) (Version: 12.0.14000)
Nero Update (Version: 11.0.13300.42.0)
Nero Video (Version: 12.5.4000)
Nero Video Help (CHM) (Version: 12.0.12000)
Nero Video Samples (Version: 12.0.11500)
Nero Video Transitions 1 (Version: 12.0.11500)
Nero WaveEditor (Version: 12.0.01000)
Nero WaveEditor (Version: 12.0.8000)
Nero WaveEditor Help (CHM) (Version: 12.0.7000)
neroxml (Version: 1.0.0)
NVIDIA 3D Vision Treiber 331.65 (Version: 331.65)
NVIDIA Display Control Panel (Version: 6.14.12.5721)
NVIDIA GeForce Experience 1.7.1 (Version: 1.7.1)
NVIDIA Grafiktreiber 331.65 (Version: 331.65)
NVIDIA Install Application (Version: 2.1002.140.952)
NVIDIA LED Visualizer 1.0 (Version: 1.0)
NVIDIA PhysX (Version: 9.13.0725)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA ShadowPlay 9.3.21 (Version: 9.3.21)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.3165)
NVIDIA Systemsteuerung 331.65 (Version: 331.65)
NVIDIA Update 9.3.21 (Version: 9.3.21)
NVIDIA Update Components (Version: 9.3.21)
NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9)
On Screen Display (Version: 7.04.1001)
Photo Common (Version: 16.4.3508.0205)
Photo Gallery (Version: 16.4.3508.0205)
Prerequisite installer (Version: 12.0.0003)
Realtek High Definition Audio Driver (Version: 6.0.1.5953)
Recuva (Version: 1.49)
RedMon - Redirection Port Monitor
SHIELD Streaming (Version: 1.6.53)
swMSM (Version: 12.0.0.1)
System Requirements Lab
Texas Instruments PCIxx21/x515/xx12 drivers. (Version: 2.00.0001)
TIPCI (Version: 2.00.0001)
TuneUp Utilities 2014 (de-DE) (Version: 14.0.1000.143)
TuneUp Utilities 2014 (Version: 14.0.1000.143)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (Version: 3)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition
Update für Microsoft Office Excel 2007 Help (KB963678)
Update für Microsoft Office Outlook 2007 Help (KB963677)
Update für Microsoft Office Powerpoint 2007 Help (KB963669)
Update für Microsoft Office Word 2007 Help (KB963665)
VLC media player 2.0.8 (Version: 2.0.8)
Welcome App (Start-up experience) (Version: 12.0.15000)
Windows Live Communications Platform (Version: 16.4.3508.0205)
Windows Live Essentials (Version: 16.4.3508.0205)
Windows Live Family Safety (Version: 16.4.3508.0205)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (Version: 16.4.3508.0205)
Windows Live Mail (Version: 16.4.3508.0205)
Windows Live Messenger (Version: 16.4.3508.0205)
Windows Live MIME IFilter (Version: 16.4.3508.0205)
Windows Live Photo Common (Version: 16.4.3508.0205)
Windows Live PIMT Platform (Version: 16.4.3508.0205)
Windows Live SOXE (Version: 16.4.3508.0205)
Windows Live SOXE Definitions (Version: 16.4.3508.0205)
Windows Live UX Platform (Version: 16.4.3508.0205)
Windows Live UX Platform Language Pack (Version: 16.4.3508.0205)
Windows Live Writer (Version: 16.4.3508.0205)
Windows Live Writer Resources (Version: 16.4.3508.0205)

==================== Restore Points =========================

13-11-2013 20:14:06 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2009-07-14 03:04 - 2013-11-13 17:01 - 00000027 ____A D:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {02AD40C0-9DBD-4C63-85D9-055847D0AC9C} - System32\Tasks\{B3F6DE9A-14F9-45EA-B53E-017F72C4B6BF} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {09E7E648-8D82-4758-80E3-1B7B3E7378F0} - System32\Tasks\{1E67335F-04B2-42AD-9C73-30B507FD9763} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {0A7EDE72-4D29-406D-860F-CF5A0ED5405F} - System32\Tasks\{C98999A9-1D91-45A4-8FE2-0F9714BB17CB} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {0B051E87-8782-47E4-924F-E166E185254B} - System32\Tasks\{BC9C531B-4E36-4C23-889B-2B938C00619E} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {11571DF0-D1E0-45F4-9B6A-DA6E65FAB28B} - System32\Tasks\{8B3AF785-FE82-40DE-893C-90BFF1292FF5} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {419AD1ED-1A7A-49FD-8598-02C5BA9671F0} - System32\Tasks\{C40B6C49-DBF0-453D-B491-644785F1D1CB} => D:\Program Files\VideoLAN\VLC\vlc.exe [2013-07-30] (VideoLAN)
Task: {4654FA3F-EAAF-472E-AA04-82E118BB3ACC} - System32\Tasks\{1745DFFB-8477-4723-8CB4-1323A66D941A} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {516BC98C-2130-4DF5-92AC-A58A5D743FAE} - System32\Tasks\{53F1D303-6633-4D35-A798-0A2178C336A7} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {5A42E282-47D5-4D84-8FB9-F2EBCDFC02A8} - System32\Tasks\{FE5D0990-A2A0-4774-A4B8-197C7311399E} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {5D010AB4-48E9-4147-AA07-A8596BA1A559} - System32\Tasks\{30C30732-63B4-4E98-A67F-CA87CE50BB5C} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {5DB7CED9-E113-4F14-99B8-E27EA7BE92AA} - System32\Tasks\{16D79578-BB70-4DFB-B260-9A69C050A9E3} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {6334C369-CEFD-49C9-B028-0966B5589E9C} - System32\Tasks\Advanced System Optimizer => D:\Program Files\Advanced System Optimizer 3\ASO3.exe [2013-09-18] (Systweak Software, (www.systweak.com))
Task: {68BAC488-4F9B-4843-84B0-F0FEC327887D} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-09-05] (Adobe Systems Incorporated)
Task: {6ADC9EB6-8D7B-4CDD-B886-FDEBD0C0F07B} - System32\Tasks\{72F3FF64-CF01-4CD7-87F6-64E92CD09B3C} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {6E382062-F0C8-45A8-A4C5-5B1132AABF91} - System32\Tasks\{AF071432-A608-4396-B049-701F3A96D5D3} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {6FFFE746-62ED-4EAC-959A-704EA2E11896} - System32\Tasks\Java Update Scheduler => D:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {7D76EBEA-5215-4057-94C2-C12F944D695C} - System32\Tasks\{C107B64E-A493-4FF8-A9E3-25587EEC3B88} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {81110996-47AA-40A9-BB23-58022BCC27E8} - System32\Tasks\{099F629D-8E05-4622-A8C5-6D66A7426BD0} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {813DCA1E-E736-4E19-8F7B-FB295E8C0242} - System32\Tasks\{6C029569-7575-4D61-82A1-9CAB5388590D} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {81F951E1-B528-44B2-AA69-C3CE5AE07290} - System32\Tasks\{72B23E82-D776-4799-9073-DD942D51B266} => D:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
Task: {852F63B1-80D1-446B-80F6-9E3B0831646F} - System32\Tasks\{5BBFC697-C918-4735-92C8-634473F726BA} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {9045B1DB-DBFF-4600-867C-00D9E93CE321} - System32\Tasks\{E0EC1149-06B1-42C4-A15F-6F0545EFB917} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {99B76AF2-3288-4EAD-9564-02835CD92E0C} - System32\Tasks\{155534ED-DC25-4767-9E3B-D5042B0D201D} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {9BB82677-C7AD-4CE2-BCEA-B22E5B37C685} - System32\Tasks\ASOService => D:\Program Files\Advanced System Optimizer 3\ASO3.exe [2013-09-18] (Systweak Software, (www.systweak.com))
Task: {9E693380-7249-4E4D-9EF2-CEC914DCCEF4} - System32\Tasks\{38A34D1A-9FF9-453A-8EF3-CCE2942D9124} => D:\Program Files\VideoLAN\VLC\vlc.exe [2013-07-30] (VideoLAN)
Task: {A5BCFC68-6C75-412B-A0F6-8201FA5340DA} - System32\Tasks\{81957F70-5E9F-43BA-8468-55061D7994C4} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {B12E3E36-3F93-4226-94EE-7B8492F47F3A} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => D:\Program Files\TuneUp Utilities 2014\OneClick.exe [2013-10-12] (TuneUp Software)
Task: {BEE39EC4-29CA-47F7-8E9A-29AC084F75A4} - System32\Tasks\hcdll2_ex_Win32 => D:\Program Files\Hardcopy\hcdll2_ex_Win32.exe [2013-07-17] ()
Task: {C2AD2526-81E3-40EA-93E0-E824DCA8D04D} - System32\Tasks\{81DA98CF-7346-4B48-B1C3-EB58FEEAC5DB} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {C8DBD8AF-E048-48E1-A8A1-C2EE920C088E} - System32\Tasks\Nero\Nero Info => D:\Program Files\Common Files\Nero\Nero Info\NeroInfo.exe [2013-08-27] (Nero AG)
Task: {CAC80EF2-14E4-4404-9646-DFEEAF4C0756} - System32\Tasks\CreateChoiceProcessTask => D:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {D0204C40-5FFA-4F90-BBF1-2B57835CC842} - System32\Tasks\{FAD9CCB1-8ED5-4D5D-96F6-3BE881E2B6AE} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {E5E5CB7A-0B81-4702-BD78-7C955C04BBFB} - System32\Tasks\{92ADBCB5-1875-447A-85AB-132F4BDE29D6} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {EE71AC5C-964A-4BEC-88B0-B904F976F3B3} - System32\Tasks\{057319AF-A3CE-488A-B50D-993C7EC2A3D5} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: {F40C7091-66E1-4120-9ADC-9863BB0A24B7} - System32\Tasks\{42D103BD-C4AC-4683-A2C5-3AF366C6F350} => D:\Program Files\VideoLAN\VLC\vlc.exe [2013-07-30] (VideoLAN)
Task: {FDC01269-07F6-4CCA-A10E-635210C6B9FA} - System32\Tasks\{571809EC-D46A-4470-8329-D6BA57E3B8D3} => D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE [2013-06-21] (Microsoft Corporation)
Task: D:\Windows\Tasks\ASOService.job => D:\Program Files\Advanced System Optimizer 3\aso3.exe

==================== Loaded Modules (whitelisted) =============

2013-11-16 18:36 - 2012-07-05 14:56 - 00052800 _____ () D:\Program Files\Hardcopy\hardcopy_05.dll
2009-11-29 20:41 - 2009-11-29 20:41 - 00043520 _____ () D:\Windows\system32\CmdLineExt03.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: D:\ProgramData\TEMP:373E1720

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== Faulty Device Manager Devices =============

Name: FO13FF-65 PC-CAM
Description: USB-Videogerät
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/17/2013 00:56:02 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/17/2013 00:54:14 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/17/2013 00:53:24 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/16/2013 05:01:01 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/16/2013 04:59:11 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/16/2013 04:58:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/15/2013 01:17:10 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/15/2013 01:16:36 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"1".
Die abhängige Assemblierung "ACME,processorArchitecture="x86",type="win32",version="12.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/15/2013 01:16:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (11/15/2013 11:53:16 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".


System errors:
=============
Error: (11/17/2013 06:50:29 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/16/2013 08:18:54 PM) (Source: DCOM) (User: KH-PC)
Description: AnwendungsspezifischLokalAktivierung{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}KH-PCKHS-1-5-21-1393026197-2463848582-1862417882-1000LocalHost (unter Verwendung von LRPC)

Error: (11/16/2013 08:18:54 PM) (Source: DCOM) (User: KH-PC)
Description: AnwendungsspezifischLokalAktivierung{145B4335-FE2A-4927-A040-7C35AD3180EF}{145B4335-FE2A-4927-A040-7C35AD3180EF}KH-PCKHS-1-5-21-1393026197-2463848582-1862417882-1000LocalHost (unter Verwendung von LRPC)

Error: (11/16/2013 08:14:46 PM) (Source: DCOM) (User: KH-PC)
Description: AnwendungsspezifischLokalAktivierung{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}KH-PCKHS-1-5-21-1393026197-2463848582-1862417882-1000LocalHost (unter Verwendung von LRPC)

Error: (11/16/2013 08:14:46 PM) (Source: DCOM) (User: KH-PC)
Description: AnwendungsspezifischLokalAktivierung{145B4335-FE2A-4927-A040-7C35AD3180EF}{145B4335-FE2A-4927-A040-7C35AD3180EF}KH-PCKHS-1-5-21-1393026197-2463848582-1862417882-1000LocalHost (unter Verwendung von LRPC)

Error: (11/16/2013 07:54:18 PM) (Source: DCOM) (User: KH-PC)
Description: AnwendungsspezifischLokalAktivierung{D3DCB472-7261-43CE-924B-0704BD730D5F}{D3DCB472-7261-43CE-924B-0704BD730D5F}KH-PCKHS-1-5-21-1393026197-2463848582-1862417882-1000LocalHost (unter Verwendung von LRPC)

Error: (11/16/2013 07:54:18 PM) (Source: DCOM) (User: KH-PC)
Description: AnwendungsspezifischLokalAktivierung{145B4335-FE2A-4927-A040-7C35AD3180EF}{145B4335-FE2A-4927-A040-7C35AD3180EF}KH-PCKHS-1-5-21-1393026197-2463848582-1862417882-1000LocalHost (unter Verwendung von LRPC)

Error: (11/16/2013 07:20:23 PM) (Source: DCOM) (User: )
Description: D:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE -Embedding740{0006F020-0000-0000-C000-000000000046}

Error: (11/16/2013 06:45:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/16/2013 02:13:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Avira Echtzeit-Scanner" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.


Microsoft Office Sessions:
=========================
Error: (03/11/2013 11:41:23 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash.

Error: (01/25/2013 00:02:57 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 36 seconds with 0 seconds of active time. This session ended with a crash.

Error: (09/06/2012 05:25:20 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash.

Error: (09/06/2012 05:18:55 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6661.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 8 seconds with 0 seconds of active time. This session ended with a crash.

Error: (04/05/2012 11:32:36 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6607.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 6 seconds with 0 seconds of active time. This session ended with a crash.

Error: (02/13/2011 09:48:16 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 52 seconds with 0 seconds of active time. This session ended with a crash.

Error: (11/16/2010 09:09:47 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10 seconds with 0 seconds of active time. This session ended with a crash.

Error: (09/07/2010 08:46:31 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6535.5005, Microsoft Office Version: 12.0.6425.1000. This session lasted 156 seconds with 120 seconds of active time. This session ended with a crash.


==================== Memory info ===========================

Percentage of memory in use: 36%
Total physical RAM: 3069.98 MB
Available physical RAM: 1945.31 MB
Total Pagefile: 6136.19 MB
Available Pagefile: 4601.49 MB
Total Virtual: 2047.88 MB
Available Virtual: 1914.82 MB

==================== Drives ================================

Drive c: (Sicherung) (Fixed) (Total:48.05 GB) (Free:40.17 GB) NTFS
Drive d: (SYSTEM) (Fixed) (Total:100 GB) (Free:23.28 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 514 MB) (Disk ID: BE3BE039)
Partition 1: (Not Active) - (Size=513 MB) - (Type=1B)

==================== End Of Log ============================
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-11-2013 01
Ran by KH (administrator) on KH-PC on 17-11-2013 08:46:39
Running from D:\Users\KH\Desktop
Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(NVIDIA Corporation) D:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) D:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) D:\Program Files\Avira\AntiVir Desktop\sched.exe
(Systweak Software, (www.systweak.com)) D:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe
(Malwarebytes Corporation) D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(TuneUp Software) D:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
(Microsoft Corp.) D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Microsoft Corp.) D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Malwarebytes Corporation) D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(LG Electronics) D:\Program Files\LG Software\On Screen Display\HotKey.exe
(Intel Corporation) D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) D:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(shbox.de) D:\Program Files\FreePDF_XP\fpassist.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Avira Operations GmbH & Co. KG) D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
() D:\Users\KH\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(TuneUp Software) D:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() D:\Program Files\Hardcopy\hcdll2_ex_Win32.exe
(Avira Operations GmbH & Co. KG) D:\Program Files\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) D:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Avira Operations GmbH & Co. KG) D:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) D:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Nero AG) D:\Program Files\Nero\Update\NASvc.exe
(Microsoft Corporation) D:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) D:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [KeybdUtility] - D:\Program Files\LG Software\On Screen Display\HotKey.exe [2655800 2007-04-10] (LG Electronics)
HKLM\...\Run: [IAAnotif] - D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [IaNvSrv] - D:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe [33304 2009-07-13] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - D:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7772704 2009-10-06] (Realtek Semiconductor)
HKLM\...\Run: [FreePDF Assistant] - D:\Program Files\FreePDF_XP\fpassist.exe [385024 2009-09-05] (shbox.de)
HKLM\...\Run: [Nvtmru] - D:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - D:\Windows\system32\rundll32.exe D:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [mobilegeni daemon] - D:\Program Files\Mobogenie\DaemonProcess.exe [735936 2013-10-08] ()
HKLM\...\Run: [avgnt] - D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-14] (Avira Operations GmbH & Co. KG)
HKCU\...\Run: [AmazonMP3DownloaderHelper] - D:\Users\KH\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKCU\...\Policies\Explorer: [NoCDBurning] 0
BootExecute: 

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x5386F3198455CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
URLSearchHook: HKLM - (No Name) - {5786d022-540e-4699-b350-b4be0ae94b79} -  No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} -  No File
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CoolPic) - D:\Users\KH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blcefchbfgmakifmejncnbognjoadloc\2.0.0.429_0
CHR HKLM\...\Chrome\Extension: [iidmoehhpbghchkaogkhmcckhlhebekn] - D:\Program Files\iRobinHood\iRobinHood Addon\iRobinHoodPartnersVExtension1_58.crx

========================== Services (Whitelisted) =================

R2 AntiVirMailService; D:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [972872 2013-11-10] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; D:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; D:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-11-10] (Avira Operations GmbH & Co. KG)
R2 ASO3DiskOptimizer; D:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe [241448 2013-09-18] (Systweak Software, (www.systweak.com))
R2 MBAMScheduler; D:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NAUpdate; D:\Program Files\Nero\Update\NASvc.exe [762192 2013-07-18] (Nero AG)
R2 NvStreamSvc; D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14652704 2013-11-08] (NVIDIA Corporation)
R2 TuneUp.UtilitiesSvc; D:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [1739576 2013-10-12] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

S3 61883; D:\Windows\System32\DRIVERS\61883.sys [46976 2009-07-14] (Microsoft Corporation)
R2 avgntflt; D:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-11-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; D:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-11-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; D:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-10] (Avira Operations GmbH & Co. KG)
R2 avnetflt; D:\Windows\System32\DRIVERS\avnetflt.sys [67680 2013-11-10] (Avira Operations GmbH & Co. KG)
R3 btmhsf; D:\Windows\System32\DRIVERS\btmhsf.sys [225280 2011-07-19] (Intel Corporation)
R3 iBtFltCoex; D:\Windows\System32\DRIVERS\iBtFltCoex.sys [47104 2011-07-20] (Intel Corporation)
R3 MBAMProtector; D:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 NuidFltr; D:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
R3 nvvad_WaveExtensible; D:\Windows\System32\drivers\nvvad32v.sys [33568 2013-09-28] (NVIDIA Corporation)
R1 ssmdrv; D:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-11-10] (Avira GmbH)
R3 TuneUpUtilitiesDrv; D:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [12320 2013-09-18] (TuneUp Software)
U5 AppMgmt; D:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\D:\Users\KH\AppData\Local\Temp\catchme.sys [x]
S3 efipsk; \??\D:\Users\KH\AppData\Local\Temp\efipsk.sys [x]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [x]
U5 VWiFiFlt; D:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-17 08:46 - 2013-11-17 08:46 - 00009543 _____ D:\Users\KH\Desktop\FRST.txt
2013-11-17 08:45 - 2013-11-17 08:45 - 01091023 _____ (Farbar) D:\Users\KH\Desktop\FRST.exe
2013-11-16 20:55 - 2013-11-16 20:59 - 00000000 ____D D:\ProgramData\MFAData
2013-11-16 20:55 - 2013-11-16 20:55 - 00000000 ____D D:\Users\KH\AppData\Local\MFAData
2013-11-16 18:51 - 2013-11-16 18:51 - 00002365 _____ D:\Users\KH\Desktop\Hardcopy.LNK
2013-11-16 18:35 - 2013-11-16 18:36 - 00000000 ____D D:\Program Files\Hardcopy
2013-11-16 18:35 - 2013-11-16 18:35 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hardcopy - Bildschirmausdruck
2013-11-16 18:34 - 2013-11-16 18:36 - 00042847 _____ D:\Windows\Hardcopy.log
2013-11-16 18:34 - 2012-07-12 06:18 - 01707520 _____ (www.sw4you.de Siegfried Weckmann) D:\Windows\SwSetupu.exe
2013-11-16 18:33 - 2013-11-16 18:33 - 06438720 _____ D:\Users\KH\Desktop\hc0111.exe
2013-11-15 22:11 - 2013-11-16 15:22 - 00000000 ____D D:\Program Files\Recuva
2013-11-15 22:11 - 2013-11-15 22:11 - 00001805 _____ D:\Users\Public\Desktop\Recuva.lnk
2013-11-15 21:33 - 2013-11-15 21:33 - 00891184 _____ D:\Users\KH\Desktop\SecurityCheck.exe
2013-11-15 18:15 - 2013-11-15 18:15 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Avira
2013-11-15 18:14 - 2013-11-15 18:14 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Nero
2013-11-15 18:14 - 2013-11-15 18:14 - 00000000 ____D D:\Users\kh-pc\AppData\Local\Nero_AG
2013-11-15 18:13 - 2013-11-15 18:14 - 00000000 ____D D:\Users\kh-pc\AppData\Local\Nero
2013-11-15 18:10 - 2013-11-15 18:10 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Systweak
2013-11-14 21:15 - 2013-11-14 21:16 - 00000000 ___SD D:\ComboFix
2013-11-14 18:29 - 2013-11-14 18:29 - 00000000 ____D D:\Users\KH\AppData\Roaming\Systweak
2013-11-14 18:22 - 2013-11-14 18:22 - 00001409 _____ D:\Users\KH\Desktop\JRT.txt
2013-11-14 18:19 - 2013-11-14 18:19 - 00000000 ____D D:\Windows\ERUNT
2013-11-14 18:17 - 2013-11-14 18:17 - 01034531 _____ (Thisisu) D:\Users\KH\Desktop\JRT.exe
2013-11-14 18:13 - 2013-11-14 18:13 - 00040262 _____ D:\Users\KH\Desktop\Quarantine.txt
2013-11-14 18:12 - 2013-11-14 18:12 - 00015665 _____ D:\Users\KH\Desktop\AdwCleaner[R0].txt
2013-11-14 18:12 - 2013-11-14 18:12 - 00015441 _____ D:\Users\KH\Desktop\AdwCleaner[S0].txt
2013-11-14 18:00 - 2013-11-14 18:03 - 00000000 ____D D:\AdwCleaner
2013-11-14 17:58 - 2013-11-14 17:58 - 01085542 _____ D:\Users\KH\Desktop\adwcleaner.exe
2013-11-14 17:23 - 2013-11-14 17:23 - 00001077 _____ D:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-14 17:23 - 2013-11-14 17:23 - 00000000 ____D D:\Users\KH\AppData\Roaming\Malwarebytes
2013-11-14 17:23 - 2013-11-14 17:23 - 00000000 ____D D:\ProgramData\Malwarebytes
2013-11-14 17:23 - 2013-11-14 17:23 - 00000000 ____D D:\Program Files\Malwarebytes' Anti-Malware
2013-11-14 17:23 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mbam.sys
2013-11-13 17:13 - 2013-11-13 17:13 - 00023722 _____ D:\Users\KH\Desktop\ComboFix.txt
2013-11-13 17:12 - 2013-11-13 17:12 - 00003279 _____ D:\Users\KH\Desktop\ComboFix-quarantined-files.txt
2013-11-13 17:06 - 2013-11-13 17:06 - 00023722 _____ D:\ComboFix.txt
2013-11-13 16:47 - 2013-11-14 21:15 - 00000000 ____D D:\Qoobox
2013-11-13 16:47 - 2013-11-13 17:05 - 00000000 ____D D:\Windows\erdnt
2013-11-13 16:47 - 2011-06-26 07:45 - 00256000 _____ D:\Windows\PEV.exe
2013-11-13 16:47 - 2010-11-07 18:20 - 00208896 _____ D:\Windows\MBR.exe
2013-11-13 16:47 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) D:\Windows\NIRCMD.exe
2013-11-13 16:47 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) D:\Windows\SWREG.exe
2013-11-13 16:47 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) D:\Windows\SWSC.exe
2013-11-13 16:47 - 2000-08-31 01:00 - 00098816 _____ D:\Windows\sed.exe
2013-11-13 16:47 - 2000-08-31 01:00 - 00080412 _____ D:\Windows\grep.exe
2013-11-13 16:47 - 2000-08-31 01:00 - 00068096 _____ D:\Windows\zip.exe
2013-11-13 16:33 - 2013-11-13 16:33 - 05147957 ____R (Swearware) D:\Users\KH\Desktop\ComboFix.exe
2013-11-13 02:57 - 2013-10-02 01:42 - 00049152 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\TsUsbFlt.sys
2013-11-13 02:57 - 2013-10-02 01:32 - 00012800 _____ (Microsoft Corporation) D:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2013-11-13 02:57 - 2013-10-02 01:30 - 00014336 _____ (Microsoft Corporation) D:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2013-11-13 02:57 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) D:\Windows\system32\MsRdpWebAccess.dll
2013-11-13 02:57 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) D:\Windows\system32\wksprtPS.dll
2013-11-13 02:57 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) D:\Windows\system32\tsgqec.dll
2013-11-13 02:57 - 2013-10-02 00:45 - 00032256 _____ (Microsoft Corporation) D:\Windows\system32\TsUsbGDCoInstaller.dll
2013-11-13 02:57 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) D:\Windows\system32\rdvidcrl.dll
2013-11-13 02:57 - 2013-10-02 00:00 - 00076288 _____ (Microsoft Corporation) D:\Windows\system32\TSWbPrxy.exe
2013-11-13 02:57 - 2013-10-01 23:53 - 00350208 _____ (Microsoft Corporation) D:\Windows\system32\wksprt.exe
2013-11-13 02:57 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) D:\Windows\system32\mstsc.exe
2013-11-13 02:57 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) D:\Windows\system32\mstscax.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 02166272 _____ (Microsoft Corporation) D:\Windows\system32\iertutil.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 01926656 _____ (Microsoft Corporation) D:\Windows\system32\inetcpl.cpl
2013-11-13 02:50 - 2013-11-13 02:50 - 01818112 _____ (Microsoft Corporation) D:\Windows\system32\wininet.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 01156608 _____ (Microsoft Corporation) D:\Windows\system32\urlmon.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 01051136 _____ (Microsoft Corporation) D:\Windows\system32\mshtmlmedia.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00703488 _____ (Microsoft Corporation) D:\Windows\system32\ieapfltr.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00646144 _____ (Microsoft Corporation) D:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00645120 _____ (Microsoft Corporation) D:\Windows\system32\jsIntl.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00616104 _____ (Microsoft Corporation) D:\Windows\system32\ieapfltr.dat
2013-11-13 02:50 - 2013-11-13 02:50 - 00523776 _____ (Microsoft Corporation) D:\Windows\system32\msfeeds.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00367104 _____ (Microsoft Corporation) D:\Windows\system32\dxtmsft.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00337408 _____ (Microsoft Corporation) D:\Windows\system32\html.iec
2013-11-13 02:50 - 2013-11-13 02:50 - 00244736 _____ (Microsoft Corporation) D:\Windows\system32\dxtrans.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00238288 _____ (Microsoft Corporation) D:\Windows\system32\iedkcs32.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00233472 _____ (Microsoft Corporation) D:\Windows\system32\url.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00208896 _____ (Microsoft Corporation) D:\Windows\system32\ie4uinit.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00208384 _____ (Microsoft Corporation) D:\Windows\system32\webcheck.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00194048 _____ (Microsoft Corporation) D:\Windows\system32\elshyph.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00182272 _____ (Microsoft Corporation) D:\Windows\system32\msls31.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00164864 _____ (Microsoft Corporation) D:\Windows\system32\msrating.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00151552 _____ (Microsoft Corporation) D:\Windows\system32\iexpress.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00139264 _____ (Microsoft Corporation) D:\Windows\system32\wextract.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00083456 _____ (Microsoft Corporation) D:\Windows\system32\inseng.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00071680 _____ (Microsoft Corporation) D:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00069632 _____ (Microsoft Corporation) D:\Windows\system32\mshtmled.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00069120 _____ (Microsoft Corporation) D:\Windows\system32\icardie.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00062464 _____ (Microsoft Corporation) D:\Windows\system32\tdc.ocx
2013-11-13 02:50 - 2013-11-13 02:50 - 00061952 _____ (Microsoft Corporation) D:\Windows\system32\iesetup.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00043008 _____ (Microsoft Corporation) D:\Windows\system32\jsproxy.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00034816 _____ (Microsoft Corporation) D:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00032768 _____ (Microsoft Corporation) D:\Windows\system32\iernonce.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00024576 _____ (Microsoft Corporation) D:\Windows\system32\licmgr10.dll
2013-11-13 02:49 - 2013-11-13 02:53 - 00009945 _____ D:\Windows\IE11_main.log
2013-11-13 02:49 - 2013-11-13 02:49 - 17142784 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 11220992 _____ (Microsoft Corporation) D:\Windows\system32\ieframe.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 04240384 _____ (Microsoft Corporation) D:\Windows\system32\jscript9.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 02724864 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.tlb
2013-11-13 02:49 - 2013-11-13 02:49 - 00610304 _____ (Microsoft Corporation) D:\Windows\system32\jscript.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00553472 _____ (Microsoft Corporation) D:\Windows\system32\jscript9diag.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00454656 _____ (Microsoft Corporation) D:\Windows\system32\vbscript.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00440832 _____ (Microsoft Corporation) D:\Windows\system32\ieui.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00127488 _____ (Microsoft Corporation) D:\Windows\system32\occache.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00116736 _____ (Microsoft Corporation) D:\Windows\system32\iepeers.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00112128 _____ (Microsoft Corporation) D:\Windows\system32\ieUnatt.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00111616 _____ (Microsoft Corporation) D:\Windows\system32\IEAdvpack.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00108032 _____ (Microsoft Corporation) D:\Windows\system32\ieetwcollector.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00086016 _____ (Microsoft Corporation) D:\Windows\system32\iesysprep.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00074240 _____ (Microsoft Corporation) D:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00061952 _____ (Microsoft Corporation) D:\Windows\system32\MshtmlDac.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00056832 _____ (Microsoft Corporation) D:\Windows\system32\pngfilt.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00051200 _____ (Microsoft Corporation) D:\Windows\system32\ieetwproxystub.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00048640 _____ (Microsoft Corporation) D:\Windows\system32\mshtmler.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00043008 _____ (Microsoft Corporation) D:\Windows\system32\msfeedsbs.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00036352 _____ (Microsoft Corporation) D:\Windows\system32\imgutil.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00013312 _____ (Microsoft Corporation) D:\Windows\system32\mshta.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00012800 _____ (Microsoft Corporation) D:\Windows\system32\msfeedssync.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00004096 _____ (Microsoft Corporation) D:\Windows\system32\ieetwcollectorres.dll
2013-11-13 02:45 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) D:\Windows\system32\SmartcardCredentialProvider.dll
2013-11-13 02:45 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) D:\Windows\system32\authui.dll
2013-11-13 02:45 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) D:\Windows\system32\credui.dll
2013-11-13 02:45 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\ksecpkg.sys
2013-11-13 02:45 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\ksecdd.sys
2013-11-13 02:45 - 2013-09-25 02:57 - 00792576 _____ (Microsoft Corporation) D:\Windows\system32\TSWorkspace.dll
2013-11-13 02:45 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) D:\Windows\system32\schannel.dll
2013-11-13 02:45 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) D:\Windows\system32\sspicli.dll
2013-11-13 02:45 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) D:\Windows\system32\secur32.dll
2013-11-13 02:45 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) D:\Windows\system32\lsasrv.dll
2013-11-13 02:45 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) D:\Windows\system32\ncrypt.dll
2013-11-13 02:45 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) D:\Windows\system32\lsass.exe
2013-11-13 02:45 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) D:\Windows\system32\sspisrv.dll
2013-11-13 02:45 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\cng.sys
2013-11-13 02:44 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) D:\Windows\system32\nshwfp.dll
2013-11-13 02:44 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) D:\Windows\system32\IKEEXT.DLL
2013-11-13 02:44 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) D:\Windows\system32\FWPUCLNT.DLL
2013-11-13 02:44 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) D:\Windows\system32\crypt32.dll
2013-11-13 02:44 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) D:\Windows\system32\gdi32.dll
2013-11-12 19:39 - 2013-11-12 19:39 - 00004091 _____ D:\Users\KH\Desktop\Gmer.txt
2013-11-12 19:12 - 2013-11-12 19:12 - 00158888 _____ D:\Windows\Minidump\111213-45879-01.dmp
2013-11-12 19:03 - 2013-11-12 19:03 - 00197992 _____ D:\Windows\Minidump\111213-48765-01.dmp
2013-11-12 18:11 - 2013-11-12 18:11 - 00377856 _____ D:\Users\KH\Desktop\gmer_2.1.19163.exe
2013-11-12 18:01 - 2013-11-12 18:01 - 00000000 ____D D:\FRST
2013-11-12 17:54 - 2013-11-12 17:57 - 00000466 _____ D:\Users\KH\Desktop\defogger_disable.log
2013-11-12 17:54 - 2013-11-12 17:54 - 00000000 _____ D:\Users\KH\defogger_reenable
2013-11-12 17:53 - 2013-11-12 17:53 - 00050477 _____ D:\Users\KH\Desktop\Defogger.exe
2013-11-12 17:48 - 2013-11-12 17:48 - 00000000 ____D D:\Users\KH\Documents\My Received Files
2013-11-12 17:48 - 2013-11-12 17:48 - 00000000 ____D D:\Users\KH\AppData\Roaming\MusicNet
2013-11-12 16:38 - 2013-11-12 16:38 - 00000000 ____D D:\Users\KH\AppData\Local\NVIDIA Corporation
2013-11-10 19:16 - 2013-11-10 19:16 - 00000000 ____D D:\Users\KH\AppData\Roaming\Avira
2013-11-10 19:15 - 2013-11-14 11:20 - 00137208 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avipbb.sys
2013-11-10 19:15 - 2013-11-14 11:20 - 00090400 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avgntflt.sys
2013-11-10 19:15 - 2013-11-10 19:15 - 00002022 _____ D:\Users\Public\Desktop\Avira Control Center.lnk
2013-11-10 19:15 - 2013-11-10 19:15 - 00000000 ____D D:\Program Files\Avira
2013-11-10 19:15 - 2013-11-10 19:09 - 00067680 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avnetflt.sys
2013-11-10 19:15 - 2013-11-10 19:09 - 00037352 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avkmgr.sys
2013-11-10 19:15 - 2013-11-10 19:09 - 00028520 _____ (Avira GmbH) D:\Windows\system32\Drivers\ssmdrv.sys
2013-11-10 19:06 - 2013-11-10 19:06 - 02296760 _____ D:\Users\KH\Desktop\avira_internet_security_suite.exe
2013-11-10 12:51 - 2013-11-10 12:51 - 00000000 ____D D:\Program Files\LucasArts
2013-11-10 12:01 - 2013-11-10 12:01 - 00000000 ____D D:\Users\KH\AppData\Local\Avg2014
2013-11-10 09:59 - 2013-11-10 09:59 - 00000000 ____D D:\Users\kh_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-10 09:59 - 2013-11-10 09:59 - 00000000 ____D D:\NVIDIA
2013-11-10 08:20 - 2013-11-10 08:20 - 00002165 _____ D:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2013-11-10 08:20 - 2013-11-10 08:20 - 00002145 _____ D:\Users\Public\Desktop\TuneUp Utilities 2014.lnk
2013-11-10 08:20 - 2013-11-10 08:20 - 00000000 ____D D:\Users\KH\AppData\Roaming\TuneUp Software
2013-11-10 08:20 - 2013-11-10 08:20 - 00000000 ____D D:\Program Files\TuneUp Utilities 2014
2013-11-10 08:20 - 2013-10-12 02:28 - 00036664 _____ (TuneUp Software) D:\Windows\system32\TURegOpt.exe
2013-11-10 08:20 - 2013-10-12 02:28 - 00025400 _____ (TuneUp Software) D:\Windows\system32\authuitu.dll
2013-11-10 08:19 - 2013-11-10 08:26 - 00000000 __SHD D:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-11-10 08:18 - 2013-11-10 08:19 - 32522152 _____ (TuneUp Software) D:\Users\KH\Desktop\TuneUpUtilities2014_de-DE.exe
2013-11-10 07:58 - 2013-11-10 07:58 - 00110072 _____ D:\Users\kh-pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-10 07:56 - 2013-11-10 07:58 - 00000000 ____D D:\Users\kh-pc
2013-11-10 07:56 - 2013-11-10 07:56 - 00001431 _____ D:\Users\kh-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-10 07:56 - 2013-11-10 07:56 - 00000020 ___SH D:\Users\kh-pc\ntuser.ini
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Startmenü
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Netzwerkumgebung
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Druckumgebung
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Documents\Eigene Musik
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Documents\Eigene Bilder
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\AppData\Local\Verlauf
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Adobe
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 ____D D:\Users\kh-pc\AppData\Local\VirtualStore
2013-11-10 07:56 - 2013-07-04 21:02 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Macromedia
2013-11-10 07:56 - 2009-10-26 14:45 - 00000000 ____D D:\Users\kh-pc\AppData\Local\Microsoft Help
2013-11-10 07:56 - 2009-07-14 05:42 - 00000000 ___RD D:\Users\kh-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-10 07:56 - 2009-07-14 05:37 - 00000000 ___RD D:\Users\kh-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-10 07:48 - 2013-11-10 11:00 - 00000428 _____ D:\Windows\Tasks\ASOService.job
2013-11-10 07:48 - 2013-11-10 07:48 - 00002256 _____ D:\Users\Public\Desktop\Intelligente PC-Wartung.lnk
2013-11-10 07:48 - 2013-11-10 07:48 - 00002204 _____ D:\Users\Public\Desktop\Advanced System Optimizer.lnk
2013-11-10 07:47 - 2013-11-10 07:53 - 00000000 ____D D:\Program Files\Advanced System Optimizer 3
2013-11-09 17:50 - 2013-11-09 17:55 - 00002216 _____ D:\Windows\system32\ASOROSet.bin
2013-11-09 15:33 - 2013-11-09 20:03 - 00271360 _____ D:\Users\KH\Documents\archive.pst
2013-11-09 14:32 - 2013-11-10 10:23 - 00271360 _____ D:\Users\KH\Documents\Outlook.pst
2013-11-09 13:57 - 2013-11-09 13:57 - 00110072 _____ D:\Users\kh_2.KH-PC.000\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 13:54 - 2013-11-09 14:06 - 00000000 ___RD D:\Users\kh_2.KH-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-09 13:54 - 2013-11-09 14:06 - 00000000 ____D D:\Users\kh_2.KH-PC.000
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Startmenü
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Netzwerkumgebung
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Druckumgebung
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Documents\Eigene Musik
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Documents\Eigene Bilder
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\AppData\Local\Verlauf
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Roaming\Adobe
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Local\VirtualStore
2013-11-09 13:54 - 2013-07-04 21:02 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Roaming\Macromedia
2013-11-09 13:54 - 2011-11-12 16:45 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Local\AskToolbar
2013-11-09 13:54 - 2009-10-26 14:45 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Local\Microsoft Help
2013-11-09 13:42 - 2013-11-09 13:42 - 00000000 ____D D:\Users\KH\Tracing
2013-11-09 13:36 - 2013-11-09 13:36 - 00000000 ____D D:\Users\KH\Desktop\kh_2
2013-11-09 12:46 - 2013-11-09 14:05 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\Nero
2013-11-09 12:46 - 2013-11-09 12:46 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Roaming\Nero
2013-11-09 12:46 - 2013-11-09 12:46 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\Nero_AG
2013-11-09 12:43 - 2013-11-09 12:43 - 00110072 _____ D:\Users\kh_2.KH-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 12:39 - 2013-11-09 14:06 - 00000000 ___RD D:\Users\kh_2.KH-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-09 12:39 - 2013-11-09 14:06 - 00000000 ____D D:\Users\kh_2.KH-PC
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\Startmenü
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\Netzwerkumgebung
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\Druckumgebung
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\AppData\Local\Verlauf
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Roaming\Adobe
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\VirtualStore
2013-11-09 12:39 - 2013-07-04 21:02 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Roaming\Macromedia
2013-11-09 12:39 - 2011-11-12 16:45 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\AskToolbar
2013-11-09 12:39 - 2009-10-26 14:45 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\Microsoft Help
2013-11-09 12:35 - 2013-11-09 15:33 - 00271360 _____ D:\Users\KH\Documents\bewerbung.pst
2013-11-09 11:32 - 2013-11-09 11:32 - 00000000 ____D D:\Users\KH\AppData\Local\Adobe
2013-11-09 11:27 - 2013-11-09 12:55 - 00271360 _____ D:\Users\KH\Desktop\Outlook.pst
2013-11-09 11:25 - 2013-11-10 15:46 - 00110072 _____ D:\Users\KH\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 11:25 - 2013-11-09 11:25 - 00000000 ____D D:\Users\KH\Documents\Amazon MP3
2013-11-09 10:49 - 2013-11-09 10:49 - 00110072 _____ D:\Users\xrcd73\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 10:48 - 2013-11-09 11:24 - 00000000 ____D D:\Users\xrcd73
2013-11-09 10:48 - 2013-11-09 11:23 - 00000000 ___RD D:\Users\xrcd73\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Startmenü
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Netzwerkumgebung
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Druckumgebung
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Documents\Eigene Musik
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Documents\Eigene Bilder
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\AppData\Local\Verlauf
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 ____D D:\Users\xrcd73\AppData\Roaming\Adobe
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 ____D D:\Users\xrcd73\AppData\Local\VirtualStore
2013-11-09 10:48 - 2013-07-04 21:02 - 00000000 ____D D:\Users\xrcd73\AppData\Roaming\Macromedia
2013-11-09 10:48 - 2011-11-12 16:45 - 00000000 ____D D:\Users\xrcd73\AppData\Local\AskToolbar
2013-11-09 10:48 - 2009-10-26 14:45 - 00000000 ____D D:\Users\xrcd73\AppData\Local\Microsoft Help
2013-11-09 10:41 - 2013-11-09 10:41 - 00000000 ____D D:\Users\kh_2\Desktop\KH
2013-11-09 10:39 - 2013-11-09 10:39 - 00110072 _____ D:\Users\kh_2\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 10:38 - 2013-11-09 11:24 - 00000000 ____D D:\Users\kh_2
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Startmenü
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Netzwerkumgebung
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Druckumgebung
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Documents\Eigene Musik
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Documents\Eigene Bilder
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\AppData\Local\Verlauf
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 ____D D:\Users\kh_2\AppData\Roaming\Adobe
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 ____D D:\Users\kh_2\AppData\Local\VirtualStore
2013-11-09 10:38 - 2013-07-04 21:02 - 00000000 ____D D:\Users\kh_2\AppData\Roaming\Macromedia
2013-11-09 10:38 - 2011-11-12 16:45 - 00000000 ____D D:\Users\kh_2\AppData\Local\AskToolbar
2013-11-09 10:38 - 2009-10-26 14:45 - 00000000 ____D D:\Users\kh_2\AppData\Local\Microsoft Help
2013-11-08 21:08 - 2013-11-09 19:33 - 00000000 ____D D:\Windows\system32\config\RCCBakup
2013-11-08 19:00 - 2013-11-08 19:00 - 00129536 _____ D:\Users\Public\AlexaNSISPlugin.4168.dll
2013-11-08 17:30 - 2013-11-09 14:05 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
2013-11-08 17:29 - 2013-11-14 18:03 - 00000000 ____D D:\Program Files\Uniblue
2013-11-08 17:29 - 2013-11-09 14:05 - 00000000 ____D D:\Program Files\iRobinHood
2013-11-08 17:28 - 2013-11-09 14:06 - 00000000 ____D D:\Program Files\CoolPic
2013-11-08 17:28 - 2013-11-09 14:05 - 00000000 ____D D:\Program Files\Mobogenie
2013-10-29 10:51 - 2013-11-10 12:01 - 00001812 _____ D:\Users\KH\Desktop\Gutschein_5_Tage_im_Schloss_Purschenstein_im_Erzgebirge_für_zwei_Personen.lnk
2013-10-28 21:13 - 2013-10-23 11:24 - 22933792 _____ (NVIDIA Corporation) D:\Windows\system32\nvoglv32.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 17560352 _____ (NVIDIA Corporation) D:\Windows\system32\nvcompiler.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 10410272 _____ (NVIDIA Corporation) D:\Windows\system32\Drivers\nvlddmkm.sys
2013-10-28 21:13 - 2013-10-23 11:24 - 09524088 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuda.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 09480328 _____ (NVIDIA Corporation) D:\Windows\system32\nvopencl.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 02946848 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuvid.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 02747168 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuvenc.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 01049888 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispco3233165.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 00893728 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispgenco3233165.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 00599840 _____ (NVIDIA Corporation) D:\Windows\system32\NvFBC.dll
2013-10-28 21:13 - 2013-10-23 11:24 - 00560416 _____ (NVIDIA Corporation) D:\Windows\system32\NvIFR.dll
2013-10-28 21:07 - 2013-11-08 21:47 - 00955168 _____ (NVIDIA Corporation) D:\Windows\system32\nvspcap.dll
2013-10-28 21:03 - 2013-09-28 00:01 - 00033568 _____ (NVIDIA Corporation) D:\Windows\system32\Drivers\nvvad32v.sys
2013-10-28 10:56 - 2013-11-10 12:01 - 00001327 _____ D:\Users\KH\Desktop\Kreativitätskindertagesstätte 13.11.13.lnk
2013-10-24 19:01 - 2013-11-10 12:01 - 00001367 _____ D:\Users\KH\Desktop\kita 001.lnk
2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) D:\Windows\system32\nvStreaming.exe
2013-10-22 19:07 - 2013-10-16 01:41 - 01049888 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispco3233158.dll
2013-10-22 19:07 - 2013-10-16 01:41 - 00893728 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispgenco3233158.dll
2013-10-21 08:52 - 2013-11-10 12:01 - 00001327 _____ D:\Users\KH\Desktop\Anja Hoffmann Erzieherin Lotusblüte.lnk
2013-10-21 05:05 - 2013-10-21 05:05 - 00264616 _____ (Oracle Corporation) D:\Windows\system32\javaws.exe
2013-10-21 05:05 - 2013-10-21 05:05 - 00175016 _____ (Oracle Corporation) D:\Windows\system32\javaw.exe
2013-10-21 05:05 - 2013-10-21 05:05 - 00174504 _____ (Oracle Corporation) D:\Windows\system32\java.exe
2013-10-21 05:05 - 2013-10-21 05:05 - 00094632 _____ (Oracle Corporation) D:\Windows\system32\WindowsAccessBridge.dll
2013-10-21 05:05 - 2013-10-21 05:05 - 00000000 ____D D:\ProgramData\Oracle
2013-10-21 05:05 - 2013-10-21 05:05 - 00000000 ____D D:\Program Files\Java
2013-10-21 05:05 - 2013-10-21 05:05 - 00000000 ____D D:\Program Files\Common Files\Java

==================== One Month Modified Files and Folders =======

2013-11-17 08:46 - 2013-11-17 08:46 - 00009543 _____ D:\Users\KH\Desktop\FRST.txt
2013-11-17 08:45 - 2013-11-17 08:45 - 01091023 _____ (Farbar) D:\Users\KH\Desktop\FRST.exe
2013-11-17 06:57 - 2009-07-14 05:34 - 00014928 ____H D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-17 06:57 - 2009-07-14 05:34 - 00014928 ____H D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-17 06:54 - 2009-10-25 15:54 - 01621084 _____ D:\Windows\system32\PerfStringBackup.INI
2013-11-17 06:49 - 2009-10-25 16:17 - 00000000 ____D D:\ProgramData\NVIDIA
2013-11-17 06:49 - 2009-07-14 05:53 - 00000006 ____H D:\Windows\Tasks\SA.DAT
2013-11-17 06:49 - 2009-07-14 05:39 - 00328722 _____ D:\Windows\setupact.log
2013-11-17 02:56 - 2009-10-25 15:35 - 01977577 _____ D:\Windows\WindowsUpdate.log
2013-11-16 20:59 - 2013-11-16 20:55 - 00000000 ____D D:\ProgramData\MFAData
2013-11-16 20:55 - 2013-11-16 20:55 - 00000000 ____D D:\Users\KH\AppData\Local\MFAData
2013-11-16 18:51 - 2013-11-16 18:51 - 00002365 _____ D:\Users\KH\Desktop\Hardcopy.LNK
2013-11-16 18:36 - 2013-11-16 18:35 - 00000000 ____D D:\Program Files\Hardcopy
2013-11-16 18:36 - 2013-11-16 18:34 - 00042847 _____ D:\Windows\Hardcopy.log
2013-11-16 18:35 - 2013-11-16 18:35 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hardcopy - Bildschirmausdruck
2013-11-16 18:33 - 2013-11-16 18:33 - 06438720 _____ D:\Users\KH\Desktop\hc0111.exe
2013-11-16 16:04 - 2009-10-25 15:53 - 00000000 ____D D:\Users\KH
2013-11-16 15:22 - 2013-11-15 22:11 - 00000000 ____D D:\Program Files\Recuva
2013-11-15 22:11 - 2013-11-15 22:11 - 00001805 _____ D:\Users\Public\Desktop\Recuva.lnk
2013-11-15 21:56 - 2009-10-25 16:17 - 00148746 _____ D:\Windows\PFRO.log
2013-11-15 21:33 - 2013-11-15 21:33 - 00891184 _____ D:\Users\KH\Desktop\SecurityCheck.exe
2013-11-15 18:15 - 2013-11-15 18:15 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Avira
2013-11-15 18:14 - 2013-11-15 18:14 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Nero
2013-11-15 18:14 - 2013-11-15 18:14 - 00000000 ____D D:\Users\kh-pc\AppData\Local\Nero_AG
2013-11-15 18:14 - 2013-11-15 18:13 - 00000000 ____D D:\Users\kh-pc\AppData\Local\Nero
2013-11-15 18:10 - 2013-11-15 18:10 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Systweak
2013-11-14 22:41 - 2009-07-14 09:47 - 00000000 ____D D:\Windows\DigitalLocker
2013-11-14 21:16 - 2013-11-14 21:15 - 00000000 ___SD D:\ComboFix
2013-11-14 21:15 - 2013-11-13 16:47 - 00000000 ____D D:\Qoobox
2013-11-14 20:11 - 2012-04-09 17:29 - 00692616 _____ (Adobe Systems Incorporated) D:\Windows\system32\FlashPlayerApp.exe
2013-11-14 20:11 - 2011-05-19 04:59 - 00071048 _____ (Adobe Systems Incorporated) D:\Windows\system32\FlashPlayerCPLApp.cpl
2013-11-14 18:29 - 2013-11-14 18:29 - 00000000 ____D D:\Users\KH\AppData\Roaming\Systweak
2013-11-14 18:22 - 2013-11-14 18:22 - 00001409 _____ D:\Users\KH\Desktop\JRT.txt
2013-11-14 18:19 - 2013-11-14 18:19 - 00000000 ____D D:\Windows\ERUNT
2013-11-14 18:17 - 2013-11-14 18:17 - 01034531 _____ (Thisisu) D:\Users\KH\Desktop\JRT.exe
2013-11-14 18:13 - 2013-11-14 18:13 - 00040262 _____ D:\Users\KH\Desktop\Quarantine.txt
2013-11-14 18:12 - 2013-11-14 18:12 - 00015665 _____ D:\Users\KH\Desktop\AdwCleaner[R0].txt
2013-11-14 18:12 - 2013-11-14 18:12 - 00015441 _____ D:\Users\KH\Desktop\AdwCleaner[S0].txt
2013-11-14 18:03 - 2013-11-14 18:00 - 00000000 ____D D:\AdwCleaner
2013-11-14 18:03 - 2013-11-08 17:29 - 00000000 ____D D:\Program Files\Uniblue
2013-11-14 18:03 - 2012-12-21 13:42 - 00000000 ____D D:\Program Files\Mozilla Firefox
2013-11-14 17:58 - 2013-11-14 17:58 - 01085542 _____ D:\Users\KH\Desktop\adwcleaner.exe
2013-11-14 17:44 - 2009-07-14 05:52 - 00000000 ____D D:\Windows\addins
2013-11-14 17:23 - 2013-11-14 17:23 - 00001077 _____ D:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-14 17:23 - 2013-11-14 17:23 - 00000000 ____D D:\Users\KH\AppData\Roaming\Malwarebytes
2013-11-14 17:23 - 2013-11-14 17:23 - 00000000 ____D D:\ProgramData\Malwarebytes
2013-11-14 17:23 - 2013-11-14 17:23 - 00000000 ____D D:\Program Files\Malwarebytes' Anti-Malware
2013-11-14 11:20 - 2013-11-10 19:15 - 00137208 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avipbb.sys
2013-11-14 11:20 - 2013-11-10 19:15 - 00090400 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avgntflt.sys
2013-11-13 21:14 - 2009-07-14 03:37 - 00000000 ____D D:\Windows\rescache
2013-11-13 17:13 - 2013-11-13 17:13 - 00023722 _____ D:\Users\KH\Desktop\ComboFix.txt
2013-11-13 17:12 - 2013-11-13 17:12 - 00003279 _____ D:\Users\KH\Desktop\ComboFix-quarantined-files.txt
2013-11-13 17:06 - 2013-11-13 17:06 - 00023722 _____ D:\ComboFix.txt
2013-11-13 17:06 - 2009-07-14 03:37 - 00000000 __RHD D:\Users\Default
2013-11-13 17:06 - 2009-07-14 03:37 - 00000000 ___RD D:\Users\Public
2013-11-13 17:05 - 2013-11-13 16:47 - 00000000 ____D D:\Windows\erdnt
2013-11-13 17:01 - 2009-07-14 03:04 - 00000215 _____ D:\Windows\system.ini
2013-11-13 16:59 - 2009-07-14 03:03 - 51380224 _____ D:\Windows\system32\config\software.bak
2013-11-13 16:59 - 2009-07-14 03:03 - 21757952 _____ D:\Windows\system32\config\system.bak
2013-11-13 16:59 - 2009-07-14 03:03 - 00524288 _____ D:\Windows\system32\config\default.bak
2013-11-13 16:59 - 2009-07-14 03:03 - 00262144 _____ D:\Windows\system32\config\sam.bak
2013-11-13 16:59 - 2009-07-14 03:03 - 00028672 _____ D:\Windows\system32\config\security.bak
2013-11-13 16:33 - 2013-11-13 16:33 - 05147957 ____R (Swearware) D:\Users\KH\Desktop\ComboFix.exe
2013-11-13 05:52 - 2009-07-14 09:47 - 00000000 ____D D:\Windows\system32\Drivers\de-DE
2013-11-13 05:52 - 2009-07-14 03:37 - 00000000 ____D D:\Windows\system32\de-DE
2013-11-13 02:56 - 2009-10-26 12:30 - 00000000 ____D D:\ProgramData\Microsoft Help
2013-11-13 02:53 - 2013-11-13 02:49 - 00009945 _____ D:\Windows\IE11_main.log
2013-11-13 02:50 - 2013-11-13 02:50 - 02166272 _____ (Microsoft Corporation) D:\Windows\system32\iertutil.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 01926656 _____ (Microsoft Corporation) D:\Windows\system32\inetcpl.cpl
2013-11-13 02:50 - 2013-11-13 02:50 - 01818112 _____ (Microsoft Corporation) D:\Windows\system32\wininet.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 01156608 _____ (Microsoft Corporation) D:\Windows\system32\urlmon.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 01051136 _____ (Microsoft Corporation) D:\Windows\system32\mshtmlmedia.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00703488 _____ (Microsoft Corporation) D:\Windows\system32\ieapfltr.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00646144 _____ (Microsoft Corporation) D:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00645120 _____ (Microsoft Corporation) D:\Windows\system32\jsIntl.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00616104 _____ (Microsoft Corporation) D:\Windows\system32\ieapfltr.dat
2013-11-13 02:50 - 2013-11-13 02:50 - 00523776 _____ (Microsoft Corporation) D:\Windows\system32\msfeeds.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00367104 _____ (Microsoft Corporation) D:\Windows\system32\dxtmsft.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00337408 _____ (Microsoft Corporation) D:\Windows\system32\html.iec
2013-11-13 02:50 - 2013-11-13 02:50 - 00244736 _____ (Microsoft Corporation) D:\Windows\system32\dxtrans.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00238288 _____ (Microsoft Corporation) D:\Windows\system32\iedkcs32.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00233472 _____ (Microsoft Corporation) D:\Windows\system32\url.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00208896 _____ (Microsoft Corporation) D:\Windows\system32\ie4uinit.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00208384 _____ (Microsoft Corporation) D:\Windows\system32\webcheck.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00194048 _____ (Microsoft Corporation) D:\Windows\system32\elshyph.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00182272 _____ (Microsoft Corporation) D:\Windows\system32\msls31.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00164864 _____ (Microsoft Corporation) D:\Windows\system32\msrating.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00151552 _____ (Microsoft Corporation) D:\Windows\system32\iexpress.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00139264 _____ (Microsoft Corporation) D:\Windows\system32\wextract.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00083456 _____ (Microsoft Corporation) D:\Windows\system32\inseng.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00071680 _____ (Microsoft Corporation) D:\Windows\system32\RegisterIEPKEYs.exe
2013-11-13 02:50 - 2013-11-13 02:50 - 00069632 _____ (Microsoft Corporation) D:\Windows\system32\mshtmled.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00069120 _____ (Microsoft Corporation) D:\Windows\system32\icardie.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00062464 _____ (Microsoft Corporation) D:\Windows\system32\tdc.ocx
2013-11-13 02:50 - 2013-11-13 02:50 - 00061952 _____ (Microsoft Corporation) D:\Windows\system32\iesetup.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00043008 _____ (Microsoft Corporation) D:\Windows\system32\jsproxy.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00034816 _____ (Microsoft Corporation) D:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00032768 _____ (Microsoft Corporation) D:\Windows\system32\iernonce.dll
2013-11-13 02:50 - 2013-11-13 02:50 - 00024576 _____ (Microsoft Corporation) D:\Windows\system32\licmgr10.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 17142784 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 11220992 _____ (Microsoft Corporation) D:\Windows\system32\ieframe.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 04240384 _____ (Microsoft Corporation) D:\Windows\system32\jscript9.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 02724864 _____ (Microsoft Corporation) D:\Windows\system32\mshtml.tlb
2013-11-13 02:49 - 2013-11-13 02:49 - 00610304 _____ (Microsoft Corporation) D:\Windows\system32\jscript.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00553472 _____ (Microsoft Corporation) D:\Windows\system32\jscript9diag.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00454656 _____ (Microsoft Corporation) D:\Windows\system32\vbscript.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00440832 _____ (Microsoft Corporation) D:\Windows\system32\ieui.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00127488 _____ (Microsoft Corporation) D:\Windows\system32\occache.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00116736 _____ (Microsoft Corporation) D:\Windows\system32\iepeers.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00112128 _____ (Microsoft Corporation) D:\Windows\system32\ieUnatt.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00111616 _____ (Microsoft Corporation) D:\Windows\system32\IEAdvpack.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00108032 _____ (Microsoft Corporation) D:\Windows\system32\ieetwcollector.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00086016 _____ (Microsoft Corporation) D:\Windows\system32\iesysprep.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00074240 _____ (Microsoft Corporation) D:\Windows\system32\SetIEInstalledDate.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00061952 _____ (Microsoft Corporation) D:\Windows\system32\MshtmlDac.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00056832 _____ (Microsoft Corporation) D:\Windows\system32\pngfilt.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00051200 _____ (Microsoft Corporation) D:\Windows\system32\ieetwproxystub.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00048640 _____ (Microsoft Corporation) D:\Windows\system32\mshtmler.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00043008 _____ (Microsoft Corporation) D:\Windows\system32\msfeedsbs.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00036352 _____ (Microsoft Corporation) D:\Windows\system32\imgutil.dll
2013-11-13 02:49 - 2013-11-13 02:49 - 00013312 _____ (Microsoft Corporation) D:\Windows\system32\mshta.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00012800 _____ (Microsoft Corporation) D:\Windows\system32\msfeedssync.exe
2013-11-13 02:49 - 2013-11-13 02:49 - 00004096 _____ (Microsoft Corporation) D:\Windows\system32\ieetwcollectorres.dll
2013-11-13 02:48 - 2013-07-11 17:06 - 00000000 ____D D:\Windows\system32\MRT
2013-11-13 02:46 - 2009-10-25 16:23 - 80340640 _____ (Microsoft Corporation) D:\Windows\system32\MRT.exe
2013-11-12 19:39 - 2013-11-12 19:39 - 00004091 _____ D:\Users\KH\Desktop\Gmer.txt
2013-11-12 19:12 - 2013-11-12 19:12 - 00158888 _____ D:\Windows\Minidump\111213-45879-01.dmp
2013-11-12 19:12 - 2012-06-27 20:31 - 00000000 ____D D:\Windows\Minidump
2013-11-12 19:03 - 2013-11-12 19:03 - 00197992 _____ D:\Windows\Minidump\111213-48765-01.dmp
2013-11-12 18:58 - 2009-10-25 15:53 - 00000000 ____D D:\Users\KH\AppData\Local\VirtualStore
2013-11-12 18:39 - 2013-07-27 16:49 - 00001912 _____ D:\Windows\epplauncher.mif
2013-11-12 18:11 - 2013-11-12 18:11 - 00377856 _____ D:\Users\KH\Desktop\gmer_2.1.19163.exe
2013-11-12 18:01 - 2013-11-12 18:01 - 00000000 ____D D:\FRST
2013-11-12 17:57 - 2013-11-12 17:54 - 00000466 _____ D:\Users\KH\Desktop\defogger_disable.log
2013-11-12 17:54 - 2013-11-12 17:54 - 00000000 _____ D:\Users\KH\defogger_reenable
2013-11-12 17:53 - 2013-11-12 17:53 - 00050477 _____ D:\Users\KH\Desktop\Defogger.exe
2013-11-12 17:48 - 2013-11-12 17:48 - 00000000 ____D D:\Users\KH\Documents\My Received Files
2013-11-12 17:48 - 2013-11-12 17:48 - 00000000 ____D D:\Users\KH\AppData\Roaming\MusicNet
2013-11-12 16:38 - 2013-11-12 16:38 - 00000000 ____D D:\Users\KH\AppData\Local\NVIDIA Corporation
2013-11-10 20:59 - 2009-07-14 05:41 - 00000749 ___RH D:\Windows\WindowsShell.Manifest
2013-11-10 20:59 - 2009-07-14 03:37 - 00000000 __RHD D:\Users\Public\Libraries
2013-11-10 19:16 - 2013-11-10 19:16 - 00000000 ____D D:\Users\KH\AppData\Roaming\Avira
2013-11-10 19:15 - 2013-11-10 19:15 - 00002022 _____ D:\Users\Public\Desktop\Avira Control Center.lnk
2013-11-10 19:15 - 2013-11-10 19:15 - 00000000 ____D D:\Program Files\Avira
2013-11-10 19:15 - 2011-11-12 16:45 - 00000000 ____D D:\ProgramData\Avira
2013-11-10 19:09 - 2013-11-10 19:15 - 00067680 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avnetflt.sys
2013-11-10 19:09 - 2013-11-10 19:15 - 00037352 _____ (Avira Operations GmbH & Co. KG) D:\Windows\system32\Drivers\avkmgr.sys
2013-11-10 19:09 - 2013-11-10 19:15 - 00028520 _____ (Avira GmbH) D:\Windows\system32\Drivers\ssmdrv.sys
2013-11-10 19:06 - 2013-11-10 19:06 - 02296760 _____ D:\Users\KH\Desktop\avira_internet_security_suite.exe
2013-11-10 15:46 - 2013-11-09 11:25 - 00110072 _____ D:\Users\KH\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-10 15:46 - 2009-07-14 05:33 - 00415560 _____ D:\Windows\system32\FNTCACHE.DAT
2013-11-10 15:43 - 2011-03-20 15:40 - 00000000 ____D D:\Program Files\Microsoft Works
2013-11-10 15:43 - 2011-03-20 15:40 - 00000000 ____D D:\Program Files\Common Files\DESIGNER
2013-11-10 15:42 - 2009-07-14 09:57 - 00000000 ____D D:\Windows\ShellNew
2013-11-10 15:37 - 2009-07-14 03:04 - 00000478 _____ D:\Windows\win.ini
2013-11-10 12:51 - 2013-11-10 12:51 - 00000000 ____D D:\Program Files\LucasArts
2013-11-10 12:41 - 2013-04-18 05:32 - 00000000 ____D D:\Users\KH\AppData\Roaming\player
2013-11-10 12:01 - 2013-11-10 12:01 - 00000000 ____D D:\Users\KH\AppData\Local\Avg2014
2013-11-10 12:01 - 2013-10-29 10:51 - 00001812 _____ D:\Users\KH\Desktop\Gutschein_5_Tage_im_Schloss_Purschenstein_im_Erzgebirge_für_zwei_Personen.lnk
2013-11-10 12:01 - 2013-10-28 10:56 - 00001327 _____ D:\Users\KH\Desktop\Kreativitätskindertagesstätte 13.11.13.lnk
2013-11-10 12:01 - 2013-10-24 19:01 - 00001367 _____ D:\Users\KH\Desktop\kita 001.lnk
2013-11-10 12:01 - 2013-10-21 08:52 - 00001327 _____ D:\Users\KH\Desktop\Anja Hoffmann Erzieherin Lotusblüte.lnk
2013-11-10 11:40 - 2013-01-24 13:07 - 00000000 ____D D:\Users\KH\AppData\Local\Nero
2013-11-10 11:21 - 2009-07-14 03:37 - 00000000 ____D D:\Windows\system32\NDF
2013-11-10 11:00 - 2013-11-10 07:48 - 00000428 _____ D:\Windows\Tasks\ASOService.job
2013-11-10 10:52 - 2013-07-19 18:07 - 00000000 ____D D:\Users\KH\AppData\Roaming\DVDVideoSoft
2013-11-10 10:27 - 2009-10-26 13:43 - 00000000 ____D D:\ProgramData\SFirm32
2013-11-10 10:23 - 2013-11-09 14:32 - 00271360 _____ D:\Users\KH\Documents\Outlook.pst
2013-11-10 09:59 - 2013-11-10 09:59 - 00000000 ____D D:\Users\kh_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-10 09:59 - 2013-11-10 09:59 - 00000000 ____D D:\NVIDIA
2013-11-10 09:46 - 2009-10-25 19:09 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-11-10 08:26 - 2013-11-10 08:19 - 00000000 __SHD D:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-11-10 08:26 - 2013-09-09 13:36 - 00000000 __SHD D:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2013-11-10 08:26 - 2009-10-26 14:22 - 00000000 ___HD D:\ProgramData\{8F84A085-61F5-420C-99B2-2BCE2C37763C}
2013-11-10 08:26 - 2009-10-26 12:30 - 00000000 ____D D:\Users\KH\AppData\Local\Microsoft Help
2013-11-10 08:21 - 2013-09-09 13:36 - 00000000 ____D D:\ProgramData\TuneUp Software
2013-11-10 08:20 - 2013-11-10 08:20 - 00002165 _____ D:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2013-11-10 08:20 - 2013-11-10 08:20 - 00002145 _____ D:\Users\Public\Desktop\TuneUp Utilities 2014.lnk
2013-11-10 08:20 - 2013-11-10 08:20 - 00000000 ____D D:\Users\KH\AppData\Roaming\TuneUp Software
2013-11-10 08:20 - 2013-11-10 08:20 - 00000000 ____D D:\Program Files\TuneUp Utilities 2014
2013-11-10 08:19 - 2013-11-10 08:18 - 32522152 _____ (TuneUp Software) D:\Users\KH\Desktop\TuneUpUtilities2014_de-DE.exe
2013-11-10 07:58 - 2013-11-10 07:58 - 00110072 _____ D:\Users\kh-pc\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-10 07:58 - 2013-11-10 07:56 - 00000000 ____D D:\Users\kh-pc
2013-11-10 07:56 - 2013-11-10 07:56 - 00001431 _____ D:\Users\kh-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-11-10 07:56 - 2013-11-10 07:56 - 00000020 ___SH D:\Users\kh-pc\ntuser.ini
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Startmenü
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Netzwerkumgebung
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Druckumgebung
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Documents\Eigene Musik
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\Documents\Eigene Bilder
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 _SHDL D:\Users\kh-pc\AppData\Local\Verlauf
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 ____D D:\Users\kh-pc\AppData\Roaming\Adobe
2013-11-10 07:56 - 2013-11-10 07:56 - 00000000 ____D D:\Users\kh-pc\AppData\Local\VirtualStore
2013-11-10 07:53 - 2013-11-10 07:47 - 00000000 ____D D:\Program Files\Advanced System Optimizer 3
2013-11-10 07:48 - 2013-11-10 07:48 - 00002256 _____ D:\Users\Public\Desktop\Intelligente PC-Wartung.lnk
2013-11-10 07:48 - 2013-11-10 07:48 - 00002204 _____ D:\Users\Public\Desktop\Advanced System Optimizer.lnk
2013-11-09 20:25 - 2013-01-24 13:08 - 00000000 ____D D:\Users\KH\AppData\Roaming\Nero
2013-11-09 20:03 - 2013-11-09 15:33 - 00271360 _____ D:\Users\KH\Documents\archive.pst
2013-11-09 19:33 - 2013-11-08 21:08 - 00000000 ____D D:\Windows\system32\config\RCCBakup
2013-11-09 17:55 - 2013-11-09 17:50 - 00002216 _____ D:\Windows\system32\ASOROSet.bin
2013-11-09 15:33 - 2013-11-09 12:35 - 00271360 _____ D:\Users\KH\Documents\bewerbung.pst
2013-11-09 14:06 - 2013-11-09 13:54 - 00000000 ___RD D:\Users\kh_2.KH-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-09 14:06 - 2013-11-09 13:54 - 00000000 ____D D:\Users\kh_2.KH-PC.000
2013-11-09 14:06 - 2013-11-09 12:39 - 00000000 ___RD D:\Users\kh_2.KH-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-09 14:06 - 2013-11-09 12:39 - 00000000 ____D D:\Users\kh_2.KH-PC
2013-11-09 14:06 - 2013-11-08 17:28 - 00000000 ____D D:\Program Files\CoolPic
2013-11-09 14:06 - 2009-07-14 03:37 - 00000000 ____D D:\Windows\system32\wfp
2013-11-09 14:05 - 2013-11-09 12:46 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\Nero
2013-11-09 14:05 - 2013-11-08 17:30 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
2013-11-09 14:05 - 2013-11-08 17:29 - 00000000 ____D D:\Program Files\iRobinHood
2013-11-09 14:05 - 2013-11-08 17:28 - 00000000 ____D D:\Program Files\Mobogenie
2013-11-09 14:05 - 2013-08-25 22:08 - 00000000 ____D D:\Users\KH\AppData\Roaming\Audacity
2013-11-09 14:05 - 2013-02-14 20:22 - 00000000 ___RD D:\Users\KH\Desktop\lplex-0.3-win64
2013-11-09 14:05 - 2013-02-14 20:06 - 00000000 ____D D:\Users\KH\AppData\Roaming\lplex
2013-11-09 14:05 - 2013-01-21 15:47 - 00000000 ___RD D:\Users\KH\SkyDrive
2013-11-09 14:05 - 2013-01-15 20:07 - 00000000 ____D D:\Users\KH\AppData\Roaming\Pegasys Inc
2013-11-09 14:05 - 2013-01-05 22:26 - 00000000 ____D D:\Users\KH\AppData\Roaming\dvdcss
2013-11-09 14:05 - 2013-01-03 20:04 - 00000000 ____D D:\Program Files\Cypheros
2013-11-09 14:05 - 2013-01-03 13:14 - 00000000 ____D D:\Users\KH\AppData\Roaming\vlc
2013-11-09 14:05 - 2011-01-08 22:17 - 00000000 ____D D:\Users\KH\AppData\Roaming\PhotoScape
2013-11-09 14:05 - 2010-11-07 10:54 - 00000000 ____D D:\Program Files\LuminanceHDR-2.0.1
2013-11-09 14:05 - 2009-11-17 17:23 - 00000000 ____D D:\Users\KH\AppData\Local\{6CDD08D2-4502-44F0-9753-3D5B10261DFE}
2013-11-09 14:05 - 2009-11-04 09:58 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ghostscript
2013-11-09 14:05 - 2009-10-26 14:20 - 00000000 ____D D:\Program Files\WIN-CASA2009
2013-11-09 14:05 - 2009-10-25 15:53 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-09 14:05 - 2009-10-25 15:53 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-11-09 14:05 - 2009-07-14 05:52 - 00000000 ____D D:\Windows\system32\WinBioDatabase
2013-11-09 14:05 - 2009-07-14 03:37 - 00000000 ____D D:\Windows\registration
2013-11-09 14:04 - 2013-08-24 18:17 - 00000000 ____D D:\Users\KH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon
2013-11-09 14:04 - 2013-01-11 22:03 - 00000000 ____D D:\Users\KH\AppData\Roaming\Digiarty
2013-11-09 14:04 - 2013-01-09 11:42 - 00000000 ____D D:\Users\KH\AppData\Roaming\Sony
2013-11-09 14:04 - 2012-01-17 22:07 - 00000000 ____D D:\Users\KH\AppData\Roaming\Canneverbe Limited
2013-11-09 14:04 - 2009-10-25 16:03 - 00000000 ____D D:\Users\KH\AppData\Roaming\Macromedia
2013-11-09 14:04 - 2009-10-25 16:03 - 00000000 ____D D:\Users\KH\AppData\Roaming\Adobe
2013-11-09 14:03 - 2013-09-06 20:24 - 00000000 ____D D:\Users\KH\AppData\Local\NVIDIA
2013-11-09 14:03 - 2013-01-24 13:08 - 00000000 ____D D:\Users\KH\AppData\Local\Nero_AG
2013-11-09 14:03 - 2013-01-09 11:50 - 00000000 ____D D:\Users\KH\AppData\Local\Sony
2013-11-09 14:03 - 2011-01-07 18:56 - 00000000 ____D D:\Users\KH\AppData\Local\Panasonic
2013-11-09 14:03 - 2009-11-15 16:24 - 00000000 ____D D:\Users\KH\AppData\Local\Microsoft Games
2013-11-09 14:02 - 2009-07-14 03:37 - 00000000 ____D D:\Program Files\Common Files\microsoft shared
2013-11-09 13:57 - 2013-11-09 13:57 - 00110072 _____ D:\Users\kh_2.KH-PC.000\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Startmenü
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Netzwerkumgebung
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Druckumgebung
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Documents\Eigene Musik
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\Documents\Eigene Bilder
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 _SHDL D:\Users\kh_2.KH-PC.000\AppData\Local\Verlauf
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Roaming\Adobe
2013-11-09 13:54 - 2013-11-09 13:54 - 00000000 ____D D:\Users\kh_2.KH-PC.000\AppData\Local\VirtualStore
2013-11-09 13:42 - 2013-11-09 13:42 - 00000000 ____D D:\Users\KH\Tracing
2013-11-09 13:36 - 2013-11-09 13:36 - 00000000 ____D D:\Users\KH\Desktop\kh_2
2013-11-09 12:55 - 2013-11-09 11:27 - 00271360 _____ D:\Users\KH\Desktop\Outlook.pst
2013-11-09 12:46 - 2013-11-09 12:46 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Roaming\Nero
2013-11-09 12:46 - 2013-11-09 12:46 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\Nero_AG
2013-11-09 12:43 - 2013-11-09 12:43 - 00110072 _____ D:\Users\kh_2.KH-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\Startmenü
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\Netzwerkumgebung
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\Druckumgebung
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 _SHDL D:\Users\kh_2.KH-PC\AppData\Local\Verlauf
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Roaming\Adobe
2013-11-09 12:39 - 2013-11-09 12:39 - 00000000 ____D D:\Users\kh_2.KH-PC\AppData\Local\VirtualStore
2013-11-09 12:31 - 2012-12-31 12:55 - 00000000 ____D D:\Program Files\Technisat
2013-11-09 12:31 - 2009-12-08 20:45 - 00000000 ____D D:\Users\KH\AppData\Local\Google
2013-11-09 11:32 - 2013-11-09 11:32 - 00000000 ____D D:\Users\KH\AppData\Local\Adobe
2013-11-09 11:25 - 2013-11-09 11:25 - 00000000 ____D D:\Users\KH\Documents\Amazon MP3
2013-11-09 11:24 - 2013-11-09 10:48 - 00000000 ____D D:\Users\xrcd73
2013-11-09 11:24 - 2013-11-09 10:38 - 00000000 ____D D:\Users\kh_2
2013-11-09 11:23 - 2013-11-09 10:48 - 00000000 ___RD D:\Users\xrcd73\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-11-09 10:49 - 2013-11-09 10:49 - 00110072 _____ D:\Users\xrcd73\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Startmenü
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Netzwerkumgebung
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Druckumgebung
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Documents\Eigene Musik
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\Documents\Eigene Bilder
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 _SHDL D:\Users\xrcd73\AppData\Local\Verlauf
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 ____D D:\Users\xrcd73\AppData\Roaming\Adobe
2013-11-09 10:48 - 2013-11-09 10:48 - 00000000 ____D D:\Users\xrcd73\AppData\Local\VirtualStore
2013-11-09 10:41 - 2013-11-09 10:41 - 00000000 ____D D:\Users\kh_2\Desktop\KH
2013-11-09 10:39 - 2013-11-09 10:39 - 00110072 _____ D:\Users\kh_2\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Startmenü
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Netzwerkumgebung
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Druckumgebung
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Documents\Eigene Musik
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\Documents\Eigene Bilder
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 _SHDL D:\Users\kh_2\AppData\Local\Verlauf
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 ____D D:\Users\kh_2\AppData\Roaming\Adobe
2013-11-09 10:38 - 2013-11-09 10:38 - 00000000 ____D D:\Users\kh_2\AppData\Local\VirtualStore
2013-11-08 21:47 - 2013-10-28 21:07 - 00955168 _____ (NVIDIA Corporation) D:\Windows\system32\nvspcap.dll
2013-11-08 19:00 - 2013-11-08 19:00 - 00129536 _____ D:\Users\Public\AlexaNSISPlugin.4168.dll
2013-11-04 21:40 - 2009-07-14 05:53 - 00032632 _____ D:\Windows\Tasks\SCHEDLGU.TXT
2013-10-28 21:18 - 2010-07-11 10:18 - 00000000 ____D D:\Program Files\NVIDIA Corporation
2013-10-28 21:07 - 2010-07-11 10:18 - 00000000 ____D D:\ProgramData\NVIDIA Corporation
2013-10-23 11:24 - 2013-10-28 21:13 - 22933792 _____ (NVIDIA Corporation) D:\Windows\system32\nvoglv32.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 17560352 _____ (NVIDIA Corporation) D:\Windows\system32\nvcompiler.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 10410272 _____ (NVIDIA Corporation) D:\Windows\system32\Drivers\nvlddmkm.sys
2013-10-23 11:24 - 2013-10-28 21:13 - 09524088 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuda.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 09480328 _____ (NVIDIA Corporation) D:\Windows\system32\nvopencl.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 02946848 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuvid.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 02747168 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuvenc.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 01049888 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispco3233165.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 00893728 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispgenco3233165.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 00599840 _____ (NVIDIA Corporation) D:\Windows\system32\NvFBC.dll
2013-10-23 11:24 - 2013-10-28 21:13 - 00560416 _____ (NVIDIA Corporation) D:\Windows\system32\NvIFR.dll
2013-10-23 11:24 - 2013-10-15 16:35 - 15855568 _____ (NVIDIA Corporation) D:\Windows\system32\nvwgf2um.dll
2013-10-23 11:24 - 2013-10-15 16:35 - 15212336 _____ (NVIDIA Corporation) D:\Windows\system32\nvd3dum.dll
2013-10-23 11:24 - 2013-09-19 20:30 - 00018174 _____ D:\Windows\system32\nvinfo.pb
2013-10-23 11:24 - 2010-07-11 10:17 - 02695200 _____ (NVIDIA Corporation) D:\Windows\system32\nvapi.dll
2013-10-23 08:19 - 2010-06-07 16:47 - 04318496 _____ (NVIDIA Corporation) D:\Windows\system32\nvcpl.dll
2013-10-23 08:19 - 2010-06-07 16:47 - 03036448 _____ (NVIDIA Corporation) D:\Windows\system32\nvsvc.dll
2013-10-23 08:19 - 2010-06-07 16:47 - 02555168 _____ (NVIDIA Corporation) D:\Windows\system32\nvsvcr.dll
2013-10-23 08:19 - 2010-06-07 16:47 - 00664352 _____ (NVIDIA Corporation) D:\Windows\system32\nvvsvc.exe
2013-10-23 08:19 - 2010-06-07 16:47 - 00209184 _____ (NVIDIA Corporation) D:\Windows\system32\nvmctray.dll
2013-10-23 08:19 - 2010-06-07 16:47 - 00062752 _____ (NVIDIA Corporation) D:\Windows\system32\nvshext.dll
2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) D:\Windows\system32\nvStreaming.exe
2013-10-21 15:50 - 2009-10-28 08:49 - 00000000 ____D D:\Windows\pss
2013-10-21 05:05 - 2013-10-21 05:05 - 00264616 _____ (Oracle Corporation) D:\Windows\system32\javaws.exe
2013-10-21 05:05 - 2013-10-21 05:05 - 00175016 _____ (Oracle Corporation) D:\Windows\system32\javaw.exe
2013-10-21 05:05 - 2013-10-21 05:05 - 00174504 _____ (Oracle Corporation) D:\Windows\system32\java.exe
2013-10-21 05:05 - 2013-10-21 05:05 - 00094632 _____ (Oracle Corporation) D:\Windows\system32\WindowsAccessBridge.dll
2013-10-21 05:05 - 2013-10-21 05:05 - 00000000 ____D D:\ProgramData\Oracle
2013-10-21 05:05 - 2013-10-21 05:05 - 00000000 ____D D:\Program Files\Java
2013-10-21 05:05 - 2013-10-21 05:05 - 00000000 ____D D:\Program Files\Common Files\Java

Files to move or delete:
====================
D:\Users\Public\AlexaNSISPlugin.4168.dll


Some content of TEMP:
====================
D:\Users\KH\AppData\Local\Temp\avgnt.exe
D:\Users\kh-pc\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

D:\Windows\explorer.exe => MD5 is legit
D:\Windows\System32\winlogon.exe => MD5 is legit
D:\Windows\System32\wininit.exe => MD5 is legit
D:\Windows\System32\svchost.exe => MD5 is legit
D:\Windows\System32\services.exe => MD5 is legit
D:\Windows\System32\User32.dll => MD5 is legit
D:\Windows\System32\userinit.exe => MD5 is legit
D:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-11-10 17:36

==================== End Of Log ============================
         
--- --- ---

--- --- ---
__________________


Alt 18.11.2013, 10:10   #18
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKLM\...\Run: [mobilegeni daemon] - D:\Program Files\Mobogenie\DaemonProcess.exe [735936 2013-10-08] ()
D:\Program Files\Mobogenie
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
__________________

Alt 18.11.2013, 16:14   #19
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Hallo.Ich hoffe es ist alles richtig.MfG C.Hoffmann Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 17-11-2013 02
Ran by KH at 2013-11-18 16:09:23 Run:1
Running from D:\Users\KH\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
HKLM\...\Run: [mobilegeni daemon] - D:\Program Files\Mobogenie\DaemonProcess.exe [735936 2013-10-08] ()
D:\Program Files\Mobogenie
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\mobilegeni daemon => Value deleted successfully.
D:\Program Files\Mobogenie => Moved successfully.

==== End of Fixlog ====

Alt 19.11.2013, 10:32   #20
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Kommt die Meldung beim Start noch?

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 19.11.2013, 10:56   #21
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Meldung ist weg!!! Danke!!!Kurze Frage ,unsere Daten also Bilder, Musik, Word-Dateien ,Alte-MaILS usw. sind immer noch nicht für uns zugänglich!!Kommen wir jemals wieder dort ran??Oder bleiben diese für immer weg??Wir sind nicht berechtigt diese zu öffnen , so ist immer die Meldung!!Danke schon mal für deine riesige Hilfe!!!

Mfg Claas

Alt 19.11.2013, 14:30   #22
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Wo liegen die? mach bitte mal nen Screenshot von dem Ordner.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.11.2013, 06:47   #23
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Hallo.Ich muß meine Frau nochmal richtig stellen.Ein paar Dokumente sind noch da,können nicht geöffnet werden.die anderen Dokumentenordner alle weg.Von 1000 Bilder sind noch 50 da,die Ordner sind alle weg.Musik und Videos alles weg,außer 3 Ordner die aber leer sind.Auf dem Desktop waren Videos,Musik und Dokumente gespeichert alles weg.Der persönliche Ordner und die gelöschten emails im Outlook alles weg.Wenn das Outlook gestartet wird zeigt er an das er den Archivordner nicht findet.Haben wir jetzt ein Benutzerkonto gelöscht oder hatte einer Zugang durch den Trojaner auf den Computer.MfG Claas

Alt 20.11.2013, 13:16   #24
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Seit wann genau ist das so?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.11.2013, 13:36   #25
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



seit 09.11.13 am Vormittag!!!

Liebe Grüße Claas

Alt 21.11.2013, 09:39   #26
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Also bevor wir hier angefangen haben.

Das ist super schwer nachuvollziehen. Ich würde jetzt mal mit Linux oder so booten ud schauen ob Du die Daten dann siehst. Wenn nicht sind sie weg.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 22.11.2013, 06:19   #27
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Hallo.Wie genau geht das,muß ich mir ein zweites Betriebssystem laden.MfG Claas

Alt 22.11.2013, 16:39   #28
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



schau mal hier:

Hilfe nach dem Crash: Datenrettung und Backup mit Linux - computerwoche.de
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 24.11.2013, 13:40   #29
xrcd73
 
TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Hallo.Habe alle gelöschten Dateien ca 30GB auf eine externe Festplatte mit Renee Undeleter wieder hergestellt.Konnte mir auch alles vorher anschauen und nun habe ich kein Zugriff auf die Dateien und Ordner auf die Festplatte.Der angegebene Pfad ist nicht vorhanden.MfG C.Hoffmann

Alt 25.11.2013, 08:05   #30
schrauber
/// the machine
/// TB-Ausbilder
 

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Standard

TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )



Du hast die Daten wiederhergestellt, auf die Externe Platte gepackt, und auf diese hast Du nun keinen Zugriff? Schon mal abgestöpselt und neu angestöpselt?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )
.dll, bereit, dateien verschwunden, dokumente, extension.mismatch, meldung, pup.optional.alexatb.a, pup.optional.amazontb.a, pup.optional.coolpic, pup.optional.iminent.a, pup.optional.offerbox.a, pup.optional.okitspace.a, pup.optional.opencandy, pup.optional.pcperformer.a, pup.optional.pcspeedup.a, pup.optional.smartbar.a, pup.optional.snapdo, pup.optional.sweetim, pup.optional.sweetim.a, pup.optional.vplmedia.a, tr/crypt.xpack.ge, tr/crypt.xpack.gen, tr/dropper.gen, trojan.browserprotect, versprochen, videos




Ähnliche Themen: TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )


  1. TR/Crypt.XPACK.Gen3 alle dateien verschwunden
    Plagegeister aller Art und deren Bekämpfung - 06.01.2014 (7)
  2. TR/Crypt.XPACK.Gen + TR/Dropper.Gen
    Plagegeister aller Art und deren Bekämpfung - 16.01.2012 (30)
  3. Desktop Verknüpfungen verschwunden nachdem Crypt.XPACK.Gen entdeckt wurde!
    Plagegeister aller Art und deren Bekämpfung - 07.01.2012 (24)
  4. TR/Crypt.XPACK und TR/Dropper.Gen auf Win XP gefunden, wie kann er entfernt werden ?
    Plagegeister aller Art und deren Bekämpfung - 12.12.2011 (1)
  5. W32/Induc.A, TR/Dropper.Gen, TR/Crypt.ZPACK.Gen, TR/Crypt.XPACK.Gen3 gefunden - wie entfernen
    Plagegeister aller Art und deren Bekämpfung - 01.12.2010 (5)
  6. TR/Crypt.XPACK.Gen3 und TR/Dropper.Gen in C:\Windows\Temp\
    Plagegeister aller Art und deren Bekämpfung - 17.10.2010 (4)
  7. Dropper.Gen und Crypt.XPACK.Gen 3 tauchen immer wieder auf
    Plagegeister aller Art und deren Bekämpfung - 10.10.2010 (3)
  8. TR/Dropper.gen und TR/Crypt.XPACK.Gen und TR/Crypt.XPACK.Gen2 und TR/Dldr.Agent.cxyf.3
    Plagegeister aller Art und deren Bekämpfung - 29.07.2010 (32)
  9. AntiVir: TR/Dropper.Gen & TR/Crypt.XPACK.gen
    Plagegeister aller Art und deren Bekämpfung - 26.04.2010 (4)
  10. Hilfe! Trojaner TR/Crypt.XPACK.Gen und TR/Dropper.Gen
    Plagegeister aller Art und deren Bekämpfung - 31.03.2010 (22)
  11. Massives Trojaner Problem TR/Crypt.XPACK.Gen TR/dropper.Gen TR/Crypt.ASPM.Gen
    Plagegeister aller Art und deren Bekämpfung - 21.03.2010 (1)
  12. HILFE! Habe TR/Dropper.Gen und TR/Crypt.Xpack.Gen was soll ich tun?
    Log-Analyse und Auswertung - 14.08.2009 (1)
  13. TR/Dropper.Gen und/oder TR/Crypt.XPACK.Gen
    Plagegeister aller Art und deren Bekämpfung - 29.04.2009 (7)
  14. TR/Dropper.Gen, W32/Sality.Y und TR/Crypt.XPACK.Gen,
    Plagegeister aller Art und deren Bekämpfung - 30.03.2009 (2)
  15. TR/Crypt.XPACK.Gen und TR/Dropper.Gen schwer zu entfernen!?!
    Plagegeister aller Art und deren Bekämpfung - 02.03.2009 (31)
  16. TR/Crypt.Xpack.gen + TR/Dropper.gen
    Log-Analyse und Auswertung - 10.02.2009 (2)
  17. Entfernung von BOO/Sinowal.A, TR/Crypt.XPACK.Gen und TR/Dropper.Gen
    Plagegeister aller Art und deren Bekämpfung - 07.08.2008 (25)

Zum Thema TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) - Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, - TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden )...
Archiv
Du betrachtest: TR/Dropper.Gen und TR/Crypt.XPack.Gen ( Dateien verschwunden ) auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.