|
Log-Analyse und Auswertung: Sophosmeldung: Troj/ZbotMem-B im MemoryWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
09.07.2013, 09:57 | #16 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory poste mal noch ein frisches FRST log.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 10:09 | #17 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Lieber Schrauber,
__________________hier ist das FRST Log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2013 Ran by Daniel (administrator) on 09-07-2013 11:03:39 Running from C:\Users\Daniel\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (VoipBuster) C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dropbox, Inc.) C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Oracle Corporation) C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe (Oracle Corporation) C:\Program Files (x86)\Java\jre7\bin\java.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.) HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [790688 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.) HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] () HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe, HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-27] (Google Inc.) HKCU\...\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN175050KX05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 [2676584 2011-09-16] (Hewlett-Packard Co.) HKCU\...\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized [19378496 2013-06-25] (VoipBuster) HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [STO Backup Service] C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe [199760 2012-01-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [STO Launcher Service] C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe /autorun [405584 2012-01-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-04-03] (Sophos Limited) HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll [218256 2013-04-03] (Sophos Limited) AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured.dll [221840 2013-04-03] (Sophos Limited) Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wikipedia.org/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - {623BD34C-6486-4770-B994-92555203C850} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=hxxp://shop.ebay.co.uk/?oemInLn=ieSrch-Q311&_nkw={searchTerms} SearchScopes: HKCU - {8C1B1A63-658F-4F07-BDC0-B7765C458695} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Freecorder 6 - {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll () Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {6B34ACCF-1B63-4E1A-8633-461917C75544} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Tcpip\Parameters: [DhcpNameServer] 141.2.22.74 141.2.149.10 Tcpip\..\Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: [NameServer]141.2.22.74,141.2.149.10 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default FF NewTab: www.bl.uk FF SelectedSearchEngine: Google FF Homepage: hxxp://www.bl.uk/ FF Keyword.URL: hxxp://www.google.com/search?q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.) FF Extension: Visualisateur 3D de 20-20 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\2020Player_IKEA@2020Technologies.com FF Extension: Deutsches Wörterbuch - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\de-DE@dictionaries.addons.mozilla.org FF Extension: Freecorder 6 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{132E58DE-22BF-44CA-A061-7FCE1E8BA1EC} FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [231936 2012-03-22] (Samsung Electronics Co., Ltd.) R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [217592 2013-04-03] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [159296 2013-04-03] (Sophos Limited) S3 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia) R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-04-03] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2013-04-03] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2890232 2013-04-03] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2010688 2013-04-03] (Sophos Limited) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1359408 2013-03-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-04-18] (Secunia) R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-04-03] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2013-04-03] (Sophos Limited) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2013-04-03] (Sophos Plc) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-09 11:03 - 2013-07-09 11:03 - 00000000 ____D C:\FRST 2013-07-09 11:01 - 2013-07-09 11:01 - 01776219 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-07-07 10:04 - 2013-07-07 10:03 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-07 10:04 - 2013-07-07 10:03 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-07 10:04 - 2013-07-07 10:03 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-07 10:04 - 2013-07-07 10:03 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-07 09:56 - 2013-07-07 09:56 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-07-07 09:54 - 2013-07-07 09:54 - 00903080 ____A (Oracle Corporation) C:\Users\Daniel\Desktop\jxpiinstall.exe 2013-07-05 11:17 - 2013-07-05 11:17 - 00001075 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-05 11:16 - 2013-07-05 11:16 - 00002521 ____A C:\Users\Public\Desktop\Skype.lnk 2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Users\Daniel\AppData\Local\Secunia PSI 2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-07-05 11:03 - 2013-07-05 11:03 - 03270960 ____A (Secunia) C:\Users\Daniel\Desktop\PSISetup7009.exe 2013-07-04 23:09 - 2013-07-04 23:09 - 00000000 ____D C:\ProgramData\Qualcomm Atheros 2013-07-04 22:58 - 2013-07-04 22:58 - 00000032 ____A C:\Windows\SysWOW64\setup.log 2013-07-04 22:57 - 2013-07-04 22:57 - 00000000 ____D C:\Program Files (x86)\Atheros WiFi Driver Installation 2013-07-04 22:57 - 2011-06-29 17:46 - 00066623 ____A C:\Windows\System32\athrextx.cat 2013-07-04 22:57 - 2011-06-21 01:03 - 02753536 ____A (Atheros Communications, Inc.) C:\Windows\System32\Drivers\athrx.sys 2013-07-04 22:57 - 2011-06-21 01:03 - 02753536 ____A (Atheros Communications, Inc.) C:\Windows\System32\athrx.sys 2013-07-04 22:54 - 2013-07-04 22:54 - 00005808 ____A C:\Windows\DPINST.LOG 2013-07-04 22:49 - 2013-07-04 22:49 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-07-04 22:49 - 2012-03-12 06:08 - 09888872 ____A (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll 2013-07-04 22:49 - 2012-03-12 06:08 - 00340072 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RtsPStor.sys 2013-07-04 22:10 - 2012-08-23 16:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll 2013-07-04 22:10 - 2012-08-23 16:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys 2013-07-04 22:10 - 2012-08-23 16:08 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbGD.sys 2013-07-04 22:10 - 2012-08-23 16:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys 2013-07-04 22:10 - 2012-08-23 15:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2013-07-04 22:10 - 2012-08-23 15:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2013-07-04 22:10 - 2012-08-23 15:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe 2013-07-04 22:10 - 2012-08-23 15:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll 2013-07-04 22:10 - 2012-08-23 15:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll 2013-07-04 22:10 - 2012-08-23 15:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll 2013-07-04 22:10 - 2012-08-23 15:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2013-07-04 22:10 - 2012-08-23 15:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll 2013-07-04 22:10 - 2012-08-23 15:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll 2013-07-04 22:10 - 2012-08-23 14:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll 2013-07-04 22:10 - 2012-08-23 13:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe 2013-07-04 22:10 - 2012-08-23 13:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2013-07-04 22:10 - 2012-08-23 13:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe 2013-07-04 22:10 - 2012-08-23 13:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2013-07-04 22:10 - 2012-08-23 12:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll 2013-07-04 22:10 - 2012-08-23 12:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll 2013-07-04 22:10 - 2012-08-23 12:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2013-07-04 22:10 - 2012-08-23 12:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe 2013-07-04 22:10 - 2012-08-23 11:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll 2013-07-04 22:10 - 2012-08-23 10:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2013-07-04 22:10 - 2012-08-23 10:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll 2013-07-04 22:09 - 2012-08-24 20:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2013-07-04 22:09 - 2012-08-24 20:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2013-07-04 22:09 - 2012-08-24 20:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2013-07-04 22:09 - 2012-08-24 20:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2013-07-04 22:09 - 2012-08-24 18:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-07-04 22:09 - 2012-08-24 18:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-07-04 22:09 - 2012-08-24 18:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-07-04 22:09 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll 2013-07-04 22:09 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2013-07-04 18:44 - 2013-07-04 23:26 - 00000000 ____D C:\Update 2013-07-04 18:28 - 2013-07-04 18:31 - 00001398 ____A C:\DelFix.txt 2013-07-04 18:24 - 2013-07-04 19:48 - 00000000 ___SD C:\ComboFix 2013-07-04 06:47 - 2013-07-04 08:58 - 00074277 ____A C:\Users\Daniel\Desktop\Problems of the historical and literary classification of.pptx 2013-07-03 11:11 - 2013-07-04 18:29 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 10:50 - 2013-07-08 10:23 - 00039146 ____A C:\Windows\PFRO.log 2013-07-02 19:40 - 2013-07-02 19:51 - 00000000 ____D C:\Windows\erdnt 2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-02 16:02 - 2013-07-02 16:03 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe 2013-07-01 15:40 - 2013-07-01 15:47 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml 2013-06-26 14:28 - 2013-06-26 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk 2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx 2013-06-19 08:07 - 2013-06-19 08:08 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log 2013-06-17 23:38 - 2013-06-17 23:42 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx 2013-06-16 12:36 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-16 12:36 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-16 12:36 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-16 12:36 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-16 12:36 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-14 10:17 - 2013-06-20 15:13 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx 2013-06-12 17:54 - 2013-06-20 10:32 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx 2013-06-12 09:49 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-12 09:49 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-12 09:49 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-12 09:49 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-12 09:49 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-12 09:49 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 01:28 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 01:28 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 01:28 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 01:28 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 01:28 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 01:28 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 01:28 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 01:28 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 01:28 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 01:28 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 01:28 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 01:28 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 01:28 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 01:28 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 01:28 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 01:28 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-11 22:38 - 2013-07-09 08:57 - 00012952 ____A C:\Windows\setupact.log 2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log 2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx 2013-06-10 18:25 - 2013-06-13 10:16 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx 2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc ==================== One Month Modified Files and Folders ======= 2013-07-09 11:03 - 2013-07-09 11:03 - 00000000 ____D C:\FRST 2013-07-09 11:01 - 2013-07-09 11:01 - 01776219 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-07-09 11:01 - 2012-04-06 15:34 - 00000258 ____A C:\Windows\Tasks\HP Photo Creations Messager.job 2013-07-09 10:51 - 2013-01-21 11:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-09 10:38 - 2012-03-27 19:43 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-09 10:16 - 2012-04-04 15:20 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job 2013-07-09 09:38 - 2012-03-27 19:43 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-09 09:08 - 2012-02-06 14:45 - 01168361 ____A C:\Windows\WindowsUpdate.log 2013-07-09 08:57 - 2013-06-11 22:38 - 00012952 ____A C:\Windows\setupact.log 2013-07-09 08:54 - 2012-03-26 14:58 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Dropbox 2013-07-09 08:33 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-09 08:33 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-09 08:26 - 2012-03-26 15:06 - 00000000 ___RD C:\Users\Daniel\Dropbox 2013-07-09 08:24 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-09 06:33 - 2012-04-04 15:20 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job 2013-07-08 12:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-07-08 12:17 - 2012-03-25 16:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-07-08 10:31 - 2012-11-22 16:29 - 00000099 ____A C:\Users\Public\LMDebug.log 2013-07-08 10:23 - 2013-07-03 10:50 - 00039146 ____A C:\Windows\PFRO.log 2013-07-07 10:03 - 2013-07-07 10:04 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-07 10:03 - 2013-07-07 10:04 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-07 10:03 - 2013-07-07 10:04 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-07 10:03 - 2013-07-07 10:04 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-07 10:03 - 2012-12-07 17:18 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-07-07 10:03 - 2012-02-06 14:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-07-07 09:57 - 2012-03-25 21:18 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe 2013-07-07 09:56 - 2013-07-07 09:56 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-07-07 09:56 - 2012-02-06 15:09 - 00000000 ____D C:\ProgramData\Adobe 2013-07-07 09:56 - 2012-02-06 15:09 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-07-07 09:54 - 2013-07-07 09:54 - 00903080 ____A (Oracle Corporation) C:\Users\Daniel\Desktop\jxpiinstall.exe 2013-07-05 12:44 - 2012-04-15 21:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype 2013-07-05 11:45 - 2013-05-16 23:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-05 11:45 - 2012-04-24 23:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-05 11:17 - 2013-07-05 11:17 - 00001075 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-05 11:16 - 2013-07-05 11:16 - 00002521 ____A C:\Users\Public\Desktop\Skype.lnk 2013-07-05 11:16 - 2012-02-06 15:24 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-05 11:16 - 2012-02-06 15:24 - 00000000 ____D C:\ProgramData\Skype 2013-07-05 11:13 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Java 2013-07-05 11:10 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files\Java 2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Users\Daniel\AppData\Local\Secunia PSI 2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-07-05 11:03 - 2013-07-05 11:03 - 03270960 ____A (Secunia) C:\Users\Daniel\Desktop\PSISetup7009.exe 2013-07-05 00:33 - 2012-02-06 14:48 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-05 00:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-07-04 23:26 - 2013-07-04 18:44 - 00000000 ____D C:\Update 2013-07-04 23:25 - 2012-02-06 14:59 - 00000000 ____D C:\Documentation 2013-07-04 23:22 - 2012-03-12 21:10 - 00000000 ____D C:\Users\Daniel\Documents\Bluetooth Folder 2013-07-04 23:11 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Sony 2013-07-04 23:11 - 2012-02-06 14:44 - 00000000 ____D C:\ProgramData\Sony Corporation 2013-07-04 23:11 - 2012-02-06 14:40 - 00000000 ____D C:\Program Files\Sony 2013-07-04 23:09 - 2013-07-04 23:09 - 00000000 ____D C:\ProgramData\Qualcomm Atheros 2013-07-04 22:58 - 2013-07-04 22:58 - 00000032 ____A C:\Windows\SysWOW64\setup.log 2013-07-04 22:57 - 2013-07-04 22:57 - 00000000 ____D C:\Program Files (x86)\Atheros WiFi Driver Installation 2013-07-04 22:56 - 2012-02-06 15:29 - 00000000 ____D C:\ProgramData\Atheros 2013-07-04 22:54 - 2013-07-04 22:54 - 00005808 ____A C:\Windows\DPINST.LOG 2013-07-04 22:49 - 2013-07-04 22:49 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-07-04 22:49 - 2012-02-06 14:53 - 00000000 ____D C:\Windows\SysWOW64\sda 2013-07-04 22:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-07-04 22:04 - 2011-02-11 01:03 - 00764746 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2013-07-04 22:03 - 2009-07-14 07:13 - 00764746 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-04 19:48 - 2013-07-04 18:24 - 00000000 ___SD C:\ComboFix 2013-07-04 18:31 - 2013-07-04 18:28 - 00001398 ____A C:\DelFix.txt 2013-07-04 18:29 - 2013-07-03 11:11 - 00000000 ____D C:\Windows\ERUNT 2013-07-04 18:20 - 2012-03-12 21:09 - 00000000 ____D C:\users\Daniel 2013-07-04 09:17 - 2013-02-22 22:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2013-07-04 08:58 - 2013-07-04 06:47 - 00074277 ____A C:\Users\Daniel\Desktop\Problems of the historical and literary classification of.pptx 2013-07-03 10:27 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-03 10:22 - 2013-03-28 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-02 19:53 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default 2013-07-02 19:51 - 2013-07-02 19:40 - 00000000 ____D C:\Windows\erdnt 2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-02 16:03 - 2013-07-02 16:02 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe 2013-07-02 16:03 - 2012-06-13 23:11 - 00000000 ____D C:\Program Files\CCleaner 2013-07-02 15:42 - 2013-05-02 00:35 - 00000000 ____D C:\Users\Daniel\Documents\shamela-r1 2013-07-02 15:42 - 2012-03-29 01:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\shamela 2013-07-01 15:47 - 2013-07-01 15:40 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml 2013-06-28 16:48 - 2012-03-24 20:21 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mozilla 2013-06-27 08:44 - 2013-05-28 12:59 - 00177947 ____A C:\test.xml 2013-06-26 16:02 - 2013-06-26 14:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-26 13:54 - 2012-04-26 19:34 - 00000000 ____D C:\Users\Daniel\Documents\Citavi 3 2013-06-26 00:00 - 2012-07-25 18:26 - 00000000 ____D C:\Users\Daniel\Documents\Calibre Library 2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk 2013-06-25 09:17 - 2012-03-27 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google 2013-06-21 16:32 - 2012-07-07 22:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\dvdcss 2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx 2013-06-20 15:13 - 2013-06-14 10:17 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx 2013-06-20 10:32 - 2013-06-12 17:54 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx 2013-06-19 08:08 - 2013-06-19 08:07 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log 2013-06-17 23:42 - 2013-06-17 23:38 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx 2013-06-13 10:16 - 2013-06-10 18:25 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx 2013-06-12 17:51 - 2012-04-30 21:30 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-12 17:51 - 2012-04-30 21:30 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-12 12:44 - 2011-02-11 00:48 - 00000000 ____D C:\Windows\Panther 2013-06-12 09:49 - 2012-03-24 18:57 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log 2013-06-11 20:26 - 2009-07-14 07:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx 2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 20:07 ==================== End Of Log ============================ Hier auch noch das Addition Log: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2013 Ran by Daniel at 2013-07-09 11:04:56 Running from C:\Users\Daniel\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) (x32) 6000E609_eDocs (x32 Version: 1.00.0000) 6000E609_Help (x32 Version: 1.00.0000) 6000E609a (x32 Version: 140.0.000.000) 64 Bit HP CIO Components Installer (Version: 6.2.2) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) ActiveX контрола на Windows Live Mesh за отдалечени връзки (x32 Version: 15.4.5722.2) ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (x32 Version: 15.4.5722.2) Adobe AIR (x32 Version: 3.7.0.2090) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader XI (11.0.03) (x32 Version: 11.0.03) Alps Pointing-device for VAIO Amazon MP3 Downloader 1.0.9 (x32) Amazon MP3-Downloader 1.0.9 (x32) A-PDF Number freeware 1.3 (x32) ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.142) ArcSoft WebCam Companion 4 (x32 Version: 4.0.21.392) Atheros WiFi Driver Installation (x32 Version: 3.0) BBC iPlayer Desktop (x32 Version: 3.0.11) Bing Bar (x32 Version: 7.0.610.0) Bluetooth Win7 Suite (64) (Version: 7.3.0.100) BPDSoftware (x32 Version: 140.0.000.000) BPDSoftware_Ini (x32 Version: 1.00.0000) BufferChm (x32 Version: 140.0.213.000) calibre (x32 Version: 0.9.29) Citavi (x32 Version: 3.4.0.2) Common Desktop Agent (Version: 1.53.0) Conexant HD Audio (Version: 8.54.0.53) Control ActiveX Windows Live Mesh pentru conexiuni la distanță (x32 Version: 15.4.5722.2) Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2) Coptic Unicode (Version: 1.0.3.40) D3DX10 (x32 Version: 15.4.2368.0902) Deutsch (Orientalistik) (Version: 1.0.3.40) DeviceDiscovery (x32 Version: 140.0.213.000) Dropbox (HKCU Version: 2.0.22) eaner (Version: 4.03) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2) Free Audio CD to MP3 Converter version 1.3.12.1228 (x32 Version: 1.3.12.1228) Free YouTube to MP3 Converter version 3.11.22.508 (x32 Version: 3.11.22.508) Freecorder 6 (x32 Version: 2.1.10) Freecorder 6 Add-on for Firefox (x32 Version: 2.1.9) Freecorder 6 Applications (6.0.0.36) (x32 Version: 6.0.0.36) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922) Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922) Galerie de photos Windows Live (x32 Version: 15.4.3502.0922) Galerie foto Windows Live (x32 Version: 15.4.3502.0922) Google Talk Plugin (x32 Version: 4.1.3.13728) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358) Google Update Helper (x32 Version: 1.3.21.149) GPBaseService2 (x32 Version: 140.0.212.000) HP Customer Participation Program 14.0 (Version: 14.0) HP Imaging Device Functions 14.0 (Version: 14.0) HP Officejet 6000 E609 Series (Version: 14.0) HP Photo Creations (x32 Version: 1.0.0.5192) HP Photosmart 5510 series Basic Device Software (Version: 25.0.621.0) HP Photosmart 5510 series Help (x32 Version: 140.0.2.2) HP Photosmart 5510 series Product Improvement Study (Version: 25.0.621.0) HP Smart Web Printing 4.60 (Version: 4.60) HP Solution Center 14.0 (Version: 14.0) HP Update (x32 Version: 5.003.000.004) HPProductAssistant (x32 Version: 140.0.213.000) HPSSupply (x32 Version: 140.0.212.000) iDRS(tm) OCR Software by I.R.I.S (x32 Version: 1.00.13.00) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144) Intel(R) Processor Graphics (x32 Version: 8.15.10.2291) Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Junk Mail filter update (x32 Version: 15.4.3502.0922) MarketResearch (x32 Version: 140.0.214.000) Media Gallery (Version: 1.5.0.16020) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 en-GB) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) Mozilla Thunderbird 17.0.7 (x86 en-US) (x32 Version: 17.0.7) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) Network64 (Version: 140.0.215.000) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593) Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (x32 Version: 15.4.5722.2) Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (x32 Version: 15.4.5722.2) PDF24 Creator 5.4.0 (x32) PlayMemories Home Plug-in (Version: 2.0.00.14170) PlayMemories Home/PMB VAIO Edition Plug-in Ver.2.2 Upgrade Program (x32 Version: 2.2.00.18250) PMB (x32 Version: 5.5.02.12220) PMB VAIO Edition Plug-in (x32 Version: 1.6.00.06010) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922) ProductContext (x32 Version: 140.0.000.000) Qualcomm Atheros Direct Connect (x32 Version: 3.0) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922) Realtek PCIE Card Reader (x32 Version: 6.1.7601.92) Remote Keyboard (x32 Version: 1.1.1.07060) Remote Play with PlayStation 3 (x32 Version: 1.1.0.15070) Samsung Easy Printer Manager (x32 Version: 1.02.06.10) Samsung Network PC Fax (x32 Version: 1.05.29.00) Samsung Printer Live Update (x32 Version: 1.01.00:04(2013-04-22)) Samsung Scan Assistant (x32 Version: 1.04.45.00) Samsung SCX-3400 Series (x32 Version: 1.08 (07/05/2012)) Secunia PSI (3.0.0.7009) (x32 Version: 3.0.0.7009) SetIP (x32 Version: 1.05.03.00) Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0) Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0) Shop for HP Supplies (Version: 14.0) Skype Click to Call (x32 Version: 5.9.9216) Skype™ 6.3 (x32 Version: 6.3.105) SmarThru Office (x32 Version: 2.08.018) SmartWebPrinting (x32 Version: 140.0.213.000) SolutionCenter (x32 Version: 140.0.214.000) Sony Corporation (Version: 1.0.0) Sophos Anti-Virus (x32 Version: 10.2.8) Sophos AutoUpdate (x32 Version: 2.9.0.344) Sophos Virus Removal Tool (x32 Version: 2.3) Spybot - Search & Destroy (x32 Version: 2.0.12) SSLx64 (Version: 1.0.0) SSLx86 (x32 Version: 1.0.0) Status (x32 Version: 140.0.256.000) Toolbox (x32 Version: 140.0.428.000) TrayApp (x32 Version: 140.0.213.000) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Excel 2007 Help (KB963678) (x32) Update for Microsoft Office OneNote 2007 Help (KB963670) (x32) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update for Microsoft Office Script Editor Help (KB963671) (x32) Update for Microsoft Office Word 2007 Help (KB963665) (x32) Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2) VAIO - Media Gallery (x32 Version: 1.5.0.16020) VAIO - PlayMemories Home Plug-in (x32 Version: 2.2.00.18250) VAIO - PMB VAIO Edition Guide (x32 Version: 1.6.00.06030) VAIO - Remote Keyboard (x32 Version: 1.1.0.07060) VAIO - Remote Play with PlayStation®3 (x32 Version: 1.1.0.15070) VAIO Care (x32 Version: 6.4.2.11150) VAIO Control Center (x32 Version: 4.5.0.03040) VAIO Data Restore Tool (x32 Version: 1.6.0.13140) VAIO Easy Connect (x32 Version: 1.1.2.01120) VAIO Event Service (x32 Version: 5.5.0.03040) VAIO Gate (x32 Version: 2.3.0.11090) VAIO Gate Default (x32 Version: 2.4.0.03240) VAIO Hardware Diagnostics (x32 Version: 4.2.0.14280) VAIO Hero Screensaver - Summer 2011 Screensaver (x32) VAIO Improvement (x32 Version: 1.0.0.14150) VAIO Improvement Validation (Version: 1.0.4.01190) VAIO Manual (x32 Version: 2.0.0.02250) VAIO Quick Web Access (x32 Version: 1.4.5.3) VAIO Sample Contents (x32 Version: 1.4.2.09010) VAIO Smart Network (x32 Version: 3.8.0.08120) VAIO Transfer Support (x32 Version: 1.4.0.14230) VAIO Update (x32 Version: 6.2.1.03260) VCCx86 (x32 Version: 1.0.0) VESx64 (Version: 1.0.0) VESx86 (x32 Version: 1.0.0) VIx64 (Version: 1.0.0) VIx86 (x32 Version: 1.0.0) VLC media player 2.0.7 (x32 Version: 2.0.7) VoipBuster (x32 Version: 4.12 build 689) VSNx64 (Version: 1.0.0) VSNx86 (x32 Version: 1.0.0) VU5x64 (Version: 1.1.0) VU5x86 (x32 Version: 1.1.0) VWSTx86 (x32 Version: 1.0.0) WebReg (x32 Version: 140.0.213.017) Willi 2.120 (x32) WinDjView 2.0.2 (Version: 2.0.2) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3508.1109) Windows Live Fotogaléria (x32 Version: 15.4.3502.0922) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live Fotogalleri (x32 Version: 15.4.3502.0922) Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922) Windows Live Fotótár (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3508.1109) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2) Windows Live Meshin etäyhteyksien ActiveX-komponentti (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922) Windows Liven sähköposti (x32 Version: 15.4.3502.0922) Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922) XMind 2012 (v3.3.1) (x32 Version: 3.3.1.201212250029) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922) Елемент керування Windows Live Mesh ActiveX для віддалених підключень (x32 Version: 15.4.5722.2) Основи Windows Live (x32 Version: 15.4.3502.0922) Основные компоненты Windows Live (x32 Version: 15.4.3502.0922) Почта Windows Live (x32 Version: 15.4.3502.0922) Фотоальбом Windows Live (x32 Version: 15.4.3502.0922) Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922) Фотоколекція Windows Live (x32 Version: 15.4.3502.0922) Элемент управления Windows Live Mesh ActiveX для удаленных подключений (x32 Version: 15.4.5722.2) ==================== Restore Points ========================= 04-07-2013 16:29:08 End of disinfection 04-07-2013 16:52:51 Removed VAIO Update 5 04-07-2013 16:53:57 Installed VAIO Update 04-07-2013 19:57:05 Windows Update 04-07-2013 20:09:51 Windows Update 04-07-2013 20:48:51 Installed Realtek PCIE Card Reader 04-07-2013 20:50:03 Installed VAIO Easy Connect 04-07-2013 20:51:00 Installed PMB VAIO Edition Plug-in Update Program 04-07-2013 20:51:49 Removed VAIO Care 04-07-2013 20:53:01 Installed VAIO Care 04-07-2013 20:55:45 Installed Qriocity 04-07-2013 20:56:31 Installed Atheros WiFi Driver Installation 04-07-2013 21:09:17 Installed Qualcomm Atheros Direct Connect 04-07-2013 22:29:58 Installed PlayMemories Home/PMB VAIO Edition Plug-in Ver.2.2 UpgǾ慴疘ࠈဏ愆А 07-07-2013 08:03:43 Installed Java 7 Update 25 ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-07-03 10:27 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {007BF961-35D6-4997-8668-9B21A46AB1EA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe No File Task: {0F00A5B5-10B7-4CB4-BDC0-0E943EEBE9C4} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation) Task: {12C233F7-78E0-49C1-884C-7C7C3AA6E686} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.) Task: {193F5D68-B659-45B1-B9B3-13053757E9B7} - System32\Tasks\{79AE494A-B00F-4E51-9D02-806671315170} => C:\DISK1\_MSSETUP.EXE No File Task: {20433116-3838-4598-A8C8-32E3CE8F5A33} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {2356794B-C110-452E-A8F4-657696B28605} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {2D38F468-16AA-4749-B2A4-1D9F42DC868A} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2013-03-26] (Sony Corporation) Task: {3813C30A-E783-4F16-839B-37BF74D535C0} - System32\Tasks\{C8099E57-DB19-44A3-9811-99FF52A6DB76} => C:\DISK1\SETUP.EXE No File Task: {3ACA6A05-8F03-4CFA-BCD3-93F38BF86D27} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation) Task: {3F4DD9FF-74EB-45B0-9B17-DB32709EB2AA} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient No File Task: {400EC6C2-FB40-444D-8F2C-92DC643BC27A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe No File Task: {4140F79D-C63D-41AD-A02D-12BA3CE145D9} - System32\Tasks\{A23A174C-68F5-40CA-B941-FDC1289EB290} => C:\DISK1\SETUP.EXE No File Task: {506A37A0-548C-4545-9782-20845E993604} - System32\Tasks\{379DF08F-7A5B-40E4-A6C9-BF55B02B91FA} => C:\DISK1\SETUP.EXE No File Task: {5483E0E3-3A4F-48EA-8175-582EBDB71603} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation) Task: {59FFB27E-68A5-46AB-9334-ADE36FD089D3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {69B5207D-6704-4205-AAD9-78074959E958} - System32\Tasks\{0819DC4F-BECD-4FDA-B9E0-B16466E48BF5} => C:\DISK1\_MSSETUP.EXE No File Task: {6FD03CBD-0AF3-4D88-B06F-D9DC145AF713} - System32\Tasks\{0754E513-E313-47B3-B55E-F56D009DB678} => C:\DISK1\SETUP.EXE No File Task: {726180E2-6A8E-42AC-B602-40066AFEE225} - System32\Tasks\{BC3BFA7F-7C59-413D-9DA1-B7D3F9A5CCA8} => C:\DISK1\SETUP.EXE No File Task: {8BD68BAD-AB09-4ABB-BB6E-34870347EF75} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation) Task: {952F479D-6606-43BA-9F59-F073D5B3BA16} - System32\Tasks\{22A55328-89D4-43AA-9BD6-97C07E551919} => C:\DISK1\SETUP.EXE No File Task: {9CDA80ED-4A92-4A36-8374-5A4452287999} - System32\Tasks\{019D57EB-6012-42C2-B389-E900B529DED9} => C:\DISK1\SETUP.EXE No File Task: {A389D2A1-B14E-4975-BC69-515565B77A59} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-11-16] (Sony Corporation) Task: {A4573A20-64C3-48F9-823C-A35856C347D4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.) Task: {AC899129-C248-4F9C-89A1-599035721B77} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {C4AE742F-5E88-468C-915D-D354017594D2} - System32\Tasks\{5CE0363D-A773-4F22-986E-E5749604663D} => C:\DISK1\SETUP.EXE No File Task: {C70B2CF8-D882-4075-94B1-0A64FA67997D} - System32\Tasks\{5F4BD8CD-A5F6-4489-BA38-BDEA07419348} => C:\DISK1\SETUP.EXE No File Task: {CB65759A-6A9E-4176-A807-B58ABD497F64} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {D24C2055-9D96-4E63-910F-B86BDA8DB7CF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe No File Task: {D3F7629C-0745-4E82-9309-2CECD6619BA2} - System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation) Task: {D45A9D9B-2AAC-4113-B249-779F7C7823C6} - System32\Tasks\User_Feed_Synchronization-{F8F9D594-1F59-4874-8B7E-773D45408B09} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation) Task: {D5914D9C-1ADC-4FFE-9159-E933F7B7BD34} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2013-03-26] (Sony Corporation) Task: {DF4D8943-C503-473F-835B-F61D9227C79C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.) Task: {EC433C01-59C3-4645-A5CD-942EE01664F4} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-09-16] (Hewlett-Packard Co.) Task: {ECB25488-1BEF-461F-9480-51C9C7FE112E} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-11-16] (Sony Corporation) Task: {F831395A-A7F0-4603-9820-68D2996C9E95} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Faulty Device Manager Devices ============= Name: Officejet 6000 E609a Description: Officejet 6000 E609a Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/09/2013 08:25:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2013 07:25:07 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2013 04:14:12 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2013 00:20:20 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2013 00:17:32 PM) (Source: Application Error) (User: ) Description: Faulting application name: firefox.exe, version: 22.0.0.4917, time stamp: 0x51c06b1b Faulting module name: xul.dll, version: 22.0.0.4917, time stamp: 0x51c06a5b Exception code: 0xc0000005 Fault offset: 0x00173668 Faulting process id: 0x1fd4 Faulting application start time: 0xfirefox.exe0 Faulting application path: firefox.exe1 Faulting module path: firefox.exe2 Report Id: firefox.exe3 Error: (07/08/2013 00:17:04 PM) (Source: Application Error) (User: ) Description: Faulting application name: services.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc10e Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x0000000000016ecf Faulting process id: 0x244 Faulting application start time: 0xservices.exe0 Faulting application path: services.exe1 Faulting module path: services.exe2 Report Id: services.exe3 Error: (07/08/2013 10:25:23 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/06/2013 10:35:21 PM) (Source: Application Error) (User: ) Description: Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x0000000000020a4a Faulting process id: 0x1020 Faulting application start time: 0xExplorer.EXE0 Faulting application path: Explorer.EXE1 Faulting module path: Explorer.EXE2 Report Id: Explorer.EXE3 Error: (07/06/2013 09:52:17 AM) (Source: Application Error) (User: ) Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x0000000000020a4a Faulting process id: 0x3fc Faulting application start time: 0xsvchost.exe0 Faulting application path: svchost.exe1 Faulting module path: svchost.exe2 Report Id: svchost.exe3 Error: (07/05/2013 00:42:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/09/2013 08:57:28 AM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (07/09/2013 08:25:19 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (07/09/2013 08:25:16 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC) Error: (07/09/2013 08:25:05 AM) (Source: Service Control Manager) (User: ) Description: The Windows Search service failed to start due to the following error: %%1053 Error: (07/09/2013 08:25:05 AM) (Source: Service Control Manager) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. Error: (07/09/2013 08:25:05 AM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (07/09/2013 08:23:59 AM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (07/09/2013 06:26:02 AM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (07/08/2013 10:18:29 PM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (07/08/2013 07:28:42 PM) (Source: Service Control Manager) (User: ) Description: The VAIO Care Performance Service service hung on starting. Microsoft Office Sessions: ========================= Error: (09/02/2012 05:32:29 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5308 seconds with 1020 seconds of active time. This session ended with a crash. Error: (07/17/2012 09:38:23 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 17791 seconds with 5040 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2013-07-03 10:27:34.458 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-07-03 10:27:34.395 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-07-03 10:27:34.349 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-07-03 10:27:34.302 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-07-02 19:51:09.694 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-07-02 19:51:09.648 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 8139.86 MB Available physical RAM: 4664.88 MB Total Pagefile: 16277.9 MB Available Pagefile: 13051.25 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:452.18 GB) (Free:351.36 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: A920C8D1) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Besten Dank und Grüße, Piristibulus |
09.07.2013, 10:47 | #18 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Hi,
__________________Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ |
09.07.2013, 11:29 | #19 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Hallo Schrauber, der Scan ist gelaufen, die Meldung kam, es sei nichts gefunden worden. Entsprechend wurde auch kein Clean-Up gestartet und kein Neustart durch den PC durchgeführt: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.06.0.1004 www.malwarebytes.org Database version: v2013.07.09.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16618 Daniel :: SOFERMAHIR [administrator] 09/07/2013 11:57:05 mbar-log-2013-07-09 (11-57-05).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P Scan options disabled: PUP Objects scanned: 246240 Time elapsed: 15 minute(s), 10 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Piristibulus |
09.07.2013, 11:31 | #20 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Meckert Sophos immer noch?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 11:33 | #21 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Nö, anscheinend nicht. Gestern kam ja auch die Warnmeldung nicht von Sophos, sondern vom "Action Center" in der Systemsteuerung. Sophos konnte da nichts finden ... LG, Piristibulus |
09.07.2013, 11:45 | #22 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Strange. beobachte das mal. Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 11:54 | #23 |
| Sophosmeldung: Troj/ZbotMem-B im Memory super, alles klar. ich werde es im Auge behalten und wenn es noch mal Probleme macht, dann eröffne ich einen neuen Thread. Noch mal vielen herzlichen Dank! Piristibulus |
09.07.2013, 11:55 | #24 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Meld dich einfach in diesem Thread nochmal
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 12:07 | #25 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Alles klar! Danke noch mal! Piristibulus |
09.07.2013, 12:16 | #26 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 13:04 | #27 |
| Sophosmeldung: Troj/ZbotMem-B im Memory komisch, während des Ausführens von DelFix meldete das Programm, es könne eine Datei unter Windows/ERUNT nicht gelöscht werden. Also eine Datei, die zu Delfix selbst gehört. 2 Minuten später schlug Sophos Alarm, und zwar gerade als DelFix fertig wurde. Es sei "HIPS/RegMod-009" gefunden worden und in die Quarantäne verschoben, aber als ich die Infos dort aufrufen wollte, hat Sophos bereits die Sache wieder aus dem Quarantänemanager entfernt gehabt. pühhh. Fehlalarm? Lags am DelFix? |
09.07.2013, 13:23 | #28 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Fehlalarm. Delfix neu laden laufen lassen, Sophos dabei deaktivieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.08.2013, 11:06 | #29 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Hallo, lieber Schrauber, die Fehlermeldung mit dem "Win32/Small.CA" ist erneut aufgetaucht. Heute morgen tauchte erneut die Fehlermeldung im Windows Action Center auf. Nach diesen Angaben, müsste der Virus gestern Abend um 21:04 "aufgetreten" sein, es kam aber definitiv zu diesem Zeitpunkt keine Meldung. Zuvor kam allerdings die Meldung "KRITISCHER FEHLER - Es ist ein kritischer Fehler aufgetreten. Windows wird in einer Minute heruntergefahren. Speichern Sie Ihre Daten" (bzw. auf Englisch, da mein Betriebssystem auf Englisch läuft) und der Computer startete sich neu. Dieser Fehler ist in den letzten Wochen öfters aufgetreten, allerdings niemals mit Virusmeldung. Heute morgen dann kam die Virusmeldung, zugleich konnte ich sehen, dass in der Sophos-Konfiguration auf einmal "on-access"-Scanning ausgeschaltet wurde und gleich die Meldung vom Windows-Action-Center kam, dass alle Sicherheitssoftware deaktiviert sei. Darauf startete Windows erneut neu, aber ohne Fehlermeldung. Sophos war danach wieder aktiv. Windows Defender nicht. Irgendwas ist also nicht ganz sauber, wie mir scheint. Ich habe daraufhin Sophos, Malewarebytes und Windows-Defender laufen lassen. (Malewarebytes noch mal upgedatet, danach WLAN ausgeschaltet). Es wurde aber nichts gefunden. Hier sind die Logs: 1) Malewarebytes: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.07.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Daniel :: SOFERMAHIR [Administrator] 07/08/2013 08:50:46 mbam-log-2013-08-07 (08-50-46).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 225861 Laufzeit: 21 Minute(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter 20130801 065706 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130801 070301 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130801 070302 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5362977 items. 20130801 070302 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130801 090228 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130801 090228 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363003 items. 20130801 090228 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130801 130227 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130801 130228 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363013 items. 20130801 130228 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130801 163646 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363013 items. 20130801 163646 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130801 164228 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130801 164229 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363019 items. 20130801 164229 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130801 192536 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363019 items. 20130801 192536 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130801 193150 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130801 193151 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363045 items. 20130801 193151 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130801 220216 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130801 220217 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363055 items. 20130801 220217 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130802 054517 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130802 054518 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363070 items. 20130802 054518 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130802 084330 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363070 items. 20130802 084331 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130802 084928 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130802 084929 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363082 items. 20130802 084930 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130802 220635 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363082 items. 20130802 220635 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130802 221233 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130802 221234 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363129 items. 20130802 221234 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130803 094248 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130803 094249 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363137 items. 20130803 094249 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130803 211249 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130803 211251 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363140 items. 20130803 211251 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130804 104401 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130804 104402 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363156 items. 20130804 104402 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130804 164349 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130804 164350 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363163 items. 20130804 164350 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130804 205054 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130804 205055 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363169 items. 20130804 205055 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130805 052837 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130805 052838 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363182 items. 20130805 052838 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130805 083531 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130805 083532 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363196 items. 20130805 083532 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130805 110925 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363196 items. 20130805 110925 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130805 121459 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130805 121500 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363204 items. 20130805 121500 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130805 141446 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130805 141447 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363215 items. 20130805 141447 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130805 191907 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363215 items. 20130805 191909 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130805 202215 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130805 202216 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363234 items. 20130805 202216 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130806 061330 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130806 061331 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363244 items. 20130806 061331 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130806 083042 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130806 083043 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363252 items. 20130806 083043 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130806 105720 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363252 items. 20130806 105720 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130806 110322 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130806 110323 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363274 items. 20130806 110323 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130806 154343 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363274 items. 20130806 154343 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130806 154935 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130806 154936 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363289 items. 20130806 154936 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130806 185144 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363289 items. 20130806 185144 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130807 064144 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363348 items. 20130807 064144 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130807 064658 Scan 'Scan my computer' started. 20130807 075004 Scan 'Scan my computer' completed. 20130807 075004 Summary of results for scan 'Scan my computer': Items scanned: 166999 Errors: 0 Items quarantined: 0 Items dealt with: 0 20130807 094714 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130807 094715 Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363355 items. 20130807 094715 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. Soll ich evtl. Windows komplett neu aufspielen? Allerdings bin ich mir nicht sicher, wie ich das mache, da mein Vaio ohne Installationsdiskette kam. Ich habe allerdings einen Produktkey bekommen. Beste Grüße und vielen Dank, Piristibulus |
07.08.2013, 19:20 | #30 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Schau dich mal im Forum um, komischerweise haben alle Leute mit diesem "Fehler" Sophod installiert
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Sophosmeldung: Troj/ZbotMem-B im Memory |
administrator, anleitung, anzeige, anzeigen, befall, beste grüße, bestimmte, cmd, defogger, desktop, detected, doppelt, entfernen, firefox, guten, log, meldung, problem, programme, scan, seite, sophos, strg, suche, troj/zbotmem-b, webseite, win, zeichen |