|
Log-Analyse und Auswertung: Sophosmeldung: Troj/ZbotMem-B im MemoryWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.07.2013, 16:29 | #1 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Hallo und guten Abend, ich hoffe, dass Ihr mir helfen könnt. Ich habe heute bemerkt, dass die Funktionen der AltGr und der Strg Taste vertauscht zu sein schienen. Auch wurden bestimmte Akzentzeichen (´, ^, etc.) doppelt ausgegeben, obwohl ich die Taste nur einmal, und zwar nicht in Kombination mit einer anderen Taste gedrückt hatte). Allerdings fiel mir auch auf, dass dieses Problem nicht immer in allen Programmen auftritt. (Ich verwende viele Tastaturoptionen und wechsle oft zwischen Sprachen hin und her.) So war "sticky notes" gar nicht, firefox zum Teil, IE, thunderbird und word non-stop davon betroffen. Eine Recherche erbrachte unter anderem, dass möglicherweise ein Trojaner/Virenbefall vorliegt. Ein Scan mit Sophos führte dann zur Meldung "Troj/ZBotMem-B has been detected in "UserMemory"". Entfernen sei nur manuell möglich. Eine weitere Suche hat dann auf diese Seite geführt. Ich hatte auch begonnen, die in der ersten Anleitung angewiesenen ersten drei Scans durchzuführen und defogger auf den Desktop heruntergeladen. Ich habe es (da Win 7) als administrator ausgeführt und wie angewiesen die Emulatoren deaktiviert. Allerdings kehrt das Programm nach dem Ende des Scans (ca. 0.5-1 sec Dauer) sofort wieder zum ersten Menü zurück und fragt nach, ob ich "disable" oder "re-enable" ausführen möchte. Im Eifer des Gefechts hab ich dann daneben geklickt als ich die Webseite nochmal anzeigen wollte und noch einmal "disable" gedrückt. Danach erschien wieder ok und dann das erste Menü (disable/re-enable). Ein Log wird beide male nicht angezeigt, allerdings war mir so, als sei kurz ein Fenster erschienen (nicht mal 1 sec lang), das denen sehr ähnelt, die beim Aufrufen von cmd erscheinen. Daher traue ich mich nicht die weiteren Schritte auszuführen. Ich wäre sehr dankbar, wenn mir hier weiter geholfen werden könnte. Vielen Dank und beste Grüße, piristibulus |
02.07.2013, 16:30 | #2 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Hi,
__________________Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ |
02.07.2013, 16:58 | #3 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Lieber Schrauber,
__________________vielen Dank für die schnelle Hilfe. Hier die logs: 1) FRST.txt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013 Ran by Daniel (administrator) on 02-07-2013 17:48:52 Running from C:\Users\Daniel\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (VoipBuster) C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Daniel\AppData\Roaming\Waeged\ihurp.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Dropbox, Inc.) C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.) HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [790688 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.) HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] () HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-27] (Google Inc.) HKCU\...\Run: [Google Update] "C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-03-28] (Google Inc.) HKCU\...\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN175050KX05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 [2676584 2011-09-16] (Hewlett-Packard Co.) HKCU\...\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation) HKCU\...\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized [19378496 2013-06-25] (VoipBuster) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18705664 2013-01-08] (Skype Technologies S.A.) HKCU\...\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.) HKCU\...\Run: [Cilehaze] C:\Users\Daniel\AppData\Roaming\Waeged\ihurp.exe [228864 2012-08-31] (The OpenSSL Project, hxxp://www.openssl.org/) HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [STO Backup Service] C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe [199760 2012-01-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [STO Launcher Service] C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe /autorun [405584 2012-01-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-04-03] (Sophos Limited) HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~2\SOPHOS~2.DLL [218256 2013-04-03] (Sophos Limited) AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~2\SOPHOS~1.DLL [221840 2013-04-03] (Sophos Limited) Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wikipedia.org/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://vaioportal.sony.eu SearchScopes: HKLM-x32 - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://start.funmoods.com/results.php?f=4&q={searchTerms}&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1Qzu0D0E0A0FyBzz0ByD0C0FyCzyyByC0AzytN0D0Tzu0CtBtCyCtN1L2XzutBtFtCtFtCtFtAtCtB&cr=765507789 SearchScopes: HKCU - {623BD34C-6486-4770-B994-92555203C850} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=hxxp://shop.ebay.co.uk/?oemInLn=ieSrch-Q311&_nkw={searchTerms} SearchScopes: HKCU - {8C1B1A63-658F-4F07-BDC0-B7765C458695} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Freecorder 6 - {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll () Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {6B34ACCF-1B63-4E1A-8633-461917C75544} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: [NameServer]141.2.22.74,141.2.149.10 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default FF user.js: detected! => C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\user.js FF NewTab: www.bl.uk FF SearchEngine: Google FF Homepage: hxxp://www.bl.uk/ FF Keyword.URL: hxxp://www.google.com/search?q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Extension: Visualisateur 3D de 20-20 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\2020Player_IKEA@2020Technologies.com FF Extension: Deutsches W?rterbuch - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\de-DE@dictionaries.addons.mozilla.org FF Extension: Freecorder 6 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{132E58DE-22BF-44CA-A061-7FCE1E8BA1EC} FF Extension: browserprotect - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\browserprotect@browserprotect.com.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: <?xml version="1.0"?> <RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#"> <Description about="urn:mozilla:install-manifest"> <em:id>smartwebprinting@hp.com</em:id> <em:version>4.60</em:version> <em:targetApplication> <!-- Firefox --> <Description> <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id> <em:minVersion>3.5.0.0</em:minVersion> <em:maxVersion>3.5.*.*</em:maxVersion> </Description> </em:targetApplication> <!-- front-end metadata --> <em:name>HP Smart Web Printing</em:name> <em:description>Print what you want, how you want.</em:description> <em:creator>hp.com</em:creator> <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL> <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL> <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL> <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform> </Description> </RDF> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: <?xml version="1.0"?> <RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#"> <Description about="urn:mozilla:install-manifest"> <em:id>smartwebprinting@hp.com</em:id> <em:version>4.60</em:version> <em:targetApplication> <!-- Firefox --> <Description> <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id> <em:minVersion>3.5.0.0</em:minVersion> <em:maxVersion>3.5.*.*</em:maxVersion> </Description> </em:targetApplication> <!-- front-end metadata --> <em:name>HP Smart Web Printing</em:name> <em:description>Print what you want, how you want.</em:description> <em:creator>hp.com</em:creator> <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL> <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL> <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL> <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform> </Description> </RDF> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [231936 2012-03-22] (Samsung Electronics Co., Ltd.) R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [217592 2013-04-03] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [159296 2013-04-03] (Sophos Limited) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-04-03] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2013-04-03] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2890232 2013-04-03] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2010688 2013-04-03] (Sophos Limited) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R3 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1021112 2011-03-30] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-04-03] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2013-04-03] (Sophos Limited) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2013-04-03] (Sophos Plc) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST 2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-07-02 17:06 - 2013-07-02 17:07 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log 2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable 2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe 2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-02 16:02 - 2013-07-02 16:03 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe 2013-07-01 15:40 - 2013-07-01 15:47 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml 2013-07-01 13:13 - 2013-07-01 21:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Vyde 2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Waeged 2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Qiebu 2013-06-26 14:28 - 2013-06-26 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk 2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx 2013-06-19 08:08 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-19 08:07 - 2013-06-19 08:08 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log 2013-06-19 08:07 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-17 23:38 - 2013-06-17 23:42 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx 2013-06-16 12:36 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-16 12:36 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-16 12:36 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-16 12:36 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-16 12:36 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-14 10:17 - 2013-06-20 15:13 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx 2013-06-12 17:54 - 2013-06-20 10:32 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx 2013-06-12 09:49 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-12 09:49 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-12 09:49 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-12 09:49 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-12 09:49 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-12 09:49 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 01:28 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 01:28 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 01:28 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 01:28 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 01:28 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 01:28 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 01:28 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 01:28 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 01:28 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 01:28 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 01:28 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 01:28 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 01:28 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 01:28 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 01:28 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 01:28 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-11 22:38 - 2013-07-02 15:57 - 00009676 ____A C:\Windows\setupact.log 2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log 2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx 2013-06-10 18:25 - 2013-06-13 10:16 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx 2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc ==================== One Month Modified Files and Folders ======= 2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST 2013-07-02 17:47 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-02 17:47 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-07-02 17:39 - 2012-03-27 19:43 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-02 17:10 - 2012-04-04 15:20 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job 2013-07-02 17:07 - 2013-07-02 17:06 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log 2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable 2013-07-02 17:06 - 2012-03-12 21:09 - 00000000 ____D C:\users\Daniel 2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe 2013-07-02 17:01 - 2012-04-06 15:34 - 00000258 ____A C:\Windows\Tasks\HP Photo Creations Messager.job 2013-07-02 16:51 - 2013-01-21 11:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-02 16:12 - 2012-04-15 21:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype 2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-02 16:03 - 2013-07-02 16:02 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe 2013-07-02 16:03 - 2012-06-13 23:11 - 00000000 ____D C:\Program Files\CCleaner 2013-07-02 16:01 - 2012-02-06 14:45 - 01601197 ____A C:\Windows\WindowsUpdate.log 2013-07-02 16:00 - 2012-03-26 15:06 - 00000000 ___RD C:\Users\Daniel\Dropbox 2013-07-02 16:00 - 2012-03-26 14:58 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Dropbox 2013-07-02 15:58 - 2012-03-27 19:43 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-02 15:57 - 2013-06-11 22:38 - 00009676 ____A C:\Windows\setupact.log 2013-07-02 15:57 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-02 15:42 - 2013-05-02 00:35 - 00000000 ____D C:\Users\Daniel\Documents\shamela-r1 2013-07-02 15:42 - 2012-03-29 01:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\shamela 2013-07-01 21:57 - 2012-04-04 15:20 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job 2013-07-01 21:43 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Vyde 2013-07-01 15:47 - 2013-07-01 15:40 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml 2013-07-01 13:47 - 2012-03-25 16:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Waeged 2013-07-01 13:13 - 2013-07-01 13:13 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Qiebu 2013-06-28 16:48 - 2012-03-24 20:21 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mozilla 2013-06-28 12:30 - 2013-02-22 22:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2013-06-28 12:11 - 2012-11-22 16:29 - 00000099 ____A C:\Users\Public\LMDebug.log 2013-06-27 08:44 - 2013-05-28 12:59 - 00177947 ____A C:\test.xml 2013-06-26 17:33 - 2012-04-24 23:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-26 16:02 - 2013-06-26 14:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-26 13:54 - 2012-04-26 19:34 - 00000000 ____D C:\Users\Daniel\Documents\Citavi 3 2013-06-26 00:00 - 2012-07-25 18:26 - 00000000 ____D C:\Users\Daniel\Documents\Calibre Library 2013-06-25 15:11 - 2009-07-14 07:13 - 00778834 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk 2013-06-25 09:17 - 2012-03-27 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google 2013-06-21 16:32 - 2012-07-07 22:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\dvdcss 2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx 2013-06-20 15:13 - 2013-06-14 10:17 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx 2013-06-20 14:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-06-20 10:32 - 2013-06-12 17:54 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx 2013-06-19 08:08 - 2013-06-19 08:07 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log 2013-06-19 08:08 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-17 23:42 - 2013-06-17 23:38 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx 2013-06-15 13:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-13 10:16 - 2013-06-10 18:25 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx 2013-06-12 21:48 - 2012-12-07 17:18 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-06-12 21:48 - 2012-02-06 14:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-06-12 21:47 - 2013-06-19 08:08 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-12 21:43 - 2013-06-19 08:07 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-12 17:51 - 2012-04-30 21:30 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-12 17:51 - 2012-04-30 21:30 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-12 12:44 - 2011-02-11 00:48 - 00000000 ____D C:\Windows\Panther 2013-06-12 09:49 - 2012-03-24 18:57 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log 2013-06-11 20:26 - 2009-07-14 07:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx 2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc 2013-06-08 16:08 - 2013-06-16 12:36 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-08 16:07 - 2013-06-16 12:36 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-08 16:06 - 2013-06-16 12:36 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-08 16:06 - 2013-06-16 12:36 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-08 16:06 - 2013-06-16 12:36 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-08 14:28 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-08 13:42 - 2013-06-16 12:36 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-08 13:13 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-07 23:02 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-06-07 09:58 - 2012-02-06 14:44 - 00000000 ____D C:\ProgramData\Sony Corporation ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-23 14:39 ==================== End Of Log ============================ 1) Addtion.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2013 Ran by Daniel at 2013-07-02 17:49:37 Running from C:\Users\Daniel\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) (x32) ?????? Windows Live (x32 Version: 15.4.3502.0922) ??????? ????????? Windows Live Mesh ActiveX ??? ?????????? ?????????? (x32 Version: 15.4.5722.2) ??????? ?????????? Windows Live Mesh ActiveX ??? ????????? ??????????? (x32 Version: 15.4.5722.2) ??????? ??????????? ??? Windows Live (x32 Version: 15.4.3502.0922) ???????? ??????? ActiveX ??? Windows Live Mesh ??? ?????????????? ????????? (x32 Version: 15.4.5722.2) ???????? ?????????? Windows Live (x32 Version: 15.4.3502.0922) ?????????? Windows Live (x32 Version: 15.4.3502.0922) ??????????? ?? Windows Live (x32 Version: 15.4.3502.0922) ???????????? Windows Live (x32 Version: 15.4.3502.0922) 6000E609_eDocs (x32 Version: 1.00.0000) 6000E609_Help (x32 Version: 1.00.0000) 6000E609a (x32 Version: 140.0.000.000) 64 Bit HP CIO Components Installer (Version: 6.2.2) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) ActiveX ???????? ?? Windows Live Mesh ?? ?????????? ?????? (x32 Version: 15.4.5722.2) ActiveX-kontroll f?r fj?rranslutningar f?r Windows Live Mesh (x32 Version: 15.4.5722.2) Adobe AIR (x32 Version: 2.5.1.17730) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader X (10.1.7) MUI (x32 Version: 10.1.7) Alps Pointing-device for VAIO Amazon MP3 Downloader 1.0.9 (x32) Amazon MP3-Downloader 1.0.9 (x32) A-PDF Number freeware 1.3 (x32) ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.142) ArcSoft WebCam Companion 4 (x32 Version: 4.0.21.392) BBC iPlayer Desktop (x32 Version: 3.0.11) Bing Bar (x32 Version: 7.0.610.0) Bluetooth Win7 Suite (64) (Version: 7.3.0.100) BPDSoftware (x32 Version: 140.0.000.000) BPDSoftware_Ini (x32 Version: 1.00.0000) BufferChm (x32 Version: 140.0.213.000) calibre (x32 Version: 0.9.29) CCleaner (Version: 4.03) Citavi (x32 Version: 3.4.0.2) Common Desktop Agent (Version: 1.53.0) Conexant HD Audio (Version: 8.54.0.53) Control ActiveX Windows Live Mesh pentru conexiuni la distan?? (x32 Version: 15.4.5722.2) Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2) Controlo ActiveX do Windows Live Mesh para Ligaç?es Remotas (x32 Version: 15.4.5722.2) Coptic Unicode (Version: 1.0.3.40) D3DX10 (x32 Version: 15.4.2368.0902) Deutsch (Orientalistik) (Version: 1.0.3.40) DeviceDiscovery (x32 Version: 140.0.213.000) Dropbox (HKCU Version: 2.0.22) Formant ActiveX programu Windows Live Mesh odpowiedzialny za obs?ug? po??cze? zdalnych (x32 Version: 15.4.5722.2) Free Audio CD to MP3 Converter version 1.3.12.1228 (x32 Version: 1.3.12.1228) Free YouTube to MP3 Converter version 3.11.22.508 (x32 Version: 3.11.22.508) Freecorder 6 (x32 Version: 2.1.10) Freecorder 6 Add-on for Firefox (x32 Version: 2.1.9) Freecorder 6 Applications (6.0.0.36) (x32 Version: 6.0.0.36) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922) Galeria fotografii us?ugi Windows Live (x32 Version: 15.4.3502.0922) Galerie de photos Windows Live (x32 Version: 15.4.3502.0922) Galerie foto Windows Live (x32 Version: 15.4.3502.0922) Google Talk Plugin (x32 Version: 4.1.3.13728) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358) Google Update Helper (x32 Version: 1.3.21.145) GPBaseService2 (x32 Version: 140.0.212.000) HP Customer Participation Program 14.0 (Version: 14.0) HP Imaging Device Functions 14.0 (Version: 14.0) HP Officejet 6000 E609 Series (Version: 14.0) HP Photo Creations (x32 Version: 1.0.0.5192) HP Photosmart 5510 series Basic Device Software (Version: 25.0.621.0) HP Photosmart 5510 series Help (x32 Version: 140.0.2.2) HP Photosmart 5510 series Product Improvement Study (Version: 25.0.621.0) HP Smart Web Printing 4.60 (Version: 4.60) HP Solution Center 14.0 (Version: 14.0) HP Update (x32 Version: 5.003.000.004) HPProductAssistant (x32 Version: 140.0.213.000) HPSSupply (x32 Version: 140.0.212.000) iDRS(tm) OCR Software by I.R.I.S (x32 Version: 1.00.13.00) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 7.0.0.1144) Intel(R) Processor Graphics (x32 Version: 8.15.10.2291) Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046) Java 7 Update 25 (x32 Version: 7.0.250) Java 7 Update 9 (64-bit) (Version: 7.0.90) Java Auto Updater (x32 Version: 2.1.9.5) Java(TM) 6 Update 22 (64-bit) (Version: 6.0.220) Java(TM) 6 Update 22 (x32 Version: 6.0.220) Junk Mail filter update (x32 Version: 15.4.3502.0922) MarketResearch (x32 Version: 140.0.214.000) Media Gallery (Version: 1.5.0.16020) Mesh Runtime (x32 Version: 15.4.5722.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 21.0 (x86 en-US) (x32 Version: 21.0) Mozilla Maintenance Service (x32 Version: 17.0.7) Mozilla Thunderbird 17.0.7 (x86 en-US) (x32 Version: 17.0.7) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) Network64 (Version: 140.0.215.000) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593) Ovl?dac? prvek ActiveX platformy Windows Live Mesh pro vzd?len? p?ipojen? (x32 Version: 15.4.5722.2) Ovl?dac? prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (x32 Version: 15.4.5722.2) PDF24 Creator 5.4.0 (x32) PMB (x32 Version: 5.5.02.12220) PMB VAIO Edition Plug-in (Version: 1.5.10.05300) PMB VAIO Edition Plug-in (x32 Version: 1.6.00.06010) Poczta us?ugi Windows Live (x32 Version: 15.4.3502.0922) Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922) ProductContext (x32 Version: 140.0.000.000) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922) Realtek PCIE Card Reader (x32 Version: 6.1.7600.77) Remote Keyboard (x32 Version: 1.1.1.03020) Remote Play with PlayStation 3 (x32 Version: 1.1.0.15070) Samsung Easy Printer Manager (x32 Version: 1.02.06.10) Samsung Network PC Fax (x32 Version: 1.05.29.00) Samsung Printer Live Update (x32 Version: 1.01.00.04) Samsung Scan Assistant (x32 Version: 1.04.45.00) Samsung SCX-3400 Series (x32 Version: 1.08 (07/05/2012)) SetIP (x32 Version: 1.05.03.00) Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0) Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0) Shop for HP Supplies (Version: 14.0) Skype Click to Call (x32 Version: 5.9.9216) Skype™ 6.1 (x32 Version: 6.1.129) SmarThru Office (x32 Version: 2.08.018) SmartWebPrinting (x32 Version: 140.0.213.000) SolutionCenter (x32 Version: 140.0.214.000) Sony Corporation (Version: 1.0.0) Sophos Anti-Virus (x32 Version: 10.2.8) Sophos AutoUpdate (x32 Version: 2.9.0.344) Sophos Virus Removal Tool (x32 Version: 2.3) Spybot - Search & Destroy (x32 Version: 2.0.12) SSLx64 (Version: 1.0.0) SSLx86 (x32 Version: 1.0.0) Status (x32 Version: 140.0.256.000) Toolbox (x32 Version: 140.0.428.000) TrayApp (x32 Version: 140.0.213.000) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Excel 2007 Help (KB963678) (x32) Update for Microsoft Office OneNote 2007 Help (KB963670) (x32) Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update for Microsoft Office Script Editor Help (KB963671) (x32) Update for Microsoft Office Word 2007 Help (KB963665) (x32) Uzak Ba?lant?lar ?çin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2) VAIO - Media Gallery (x32 Version: 1.5.0.16020) VAIO - PMB VAIO Edition Guide (x32 Version: 1.6.00.06030) VAIO - PMB VAIO Edition Plug-in (x32 Version: 1.6.00.06140) VAIO - Remote Keyboard (x32 Version: 1.0.1.03020) VAIO - Remote Play with PlayStation®3 (x32 Version: 1.1.0.15070) VAIO Care (x32 Version: 6.4.0.15030) VAIO Control Center (x32 Version: 4.5.0.03040) VAIO Data Restore Tool (x32 Version: 1.6.0.13140) VAIO Easy Connect (x32 Version: 1.0.0.03050) VAIO Event Service (x32 Version: 5.5.0.03040) VAIO Gate (x32 Version: 2.3.0.11090) VAIO Gate Default (x32 Version: 2.4.0.03240) VAIO Hardware Diagnostics (x32 Version: 4.2.0.14280) VAIO Hero Screensaver - Summer 2011 Screensaver (x32) VAIO Improvement (x32 Version: 1.0.0.14150) VAIO Improvement Validation (Version: 1.0.4.01190) VAIO Manual (x32 Version: 2.0.0.02250) VAIO Quick Web Access (x32 Version: 1.4.5.3) VAIO Sample Contents (x32 Version: 1.4.2.09010) VAIO Smart Network (x32 Version: 3.5.0.02280) VAIO Transfer Support (x32 Version: 1.4.0.14230) VAIO Update (x32 Version: 5.4.0.15300) VCCx86 (x32 Version: 1.0.0) VESx64 (Version: 1.0.0) VESx86 (x32 Version: 1.0.0) VIx64 (Version: 1.0.0) VIx86 (x32 Version: 1.0.0) VLC media player 2.0.7 (x32 Version: 2.0.7) VoipBuster (x32 Version: 4.12 build 689) VSNx64 (Version: 1.0.0) VWSTx86 (x32 Version: 1.0.0) WebReg (x32 Version: 140.0.213.017) Willi 2.120 (x32) WinDjView 2.0.2 (Version: 2.0.2) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3508.1109) Windows Live Fot?t?r (x32 Version: 15.4.3502.0922) Windows Live Foto?raf Galerisi (x32 Version: 15.4.3502.0922) Windows Live Fotogaléria (x32 Version: 15.4.3502.0922) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live Fotogalleri (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3508.1109) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2) Windows Live Mesh (x32 Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2) Windows Live Mesh ActiveX-vezérl? t?voli kapcsolatokhoz (x32 Version: 15.4.5722.2) Windows Live Meshin et?yhteyksien ActiveX-komponentti (x32 Version: 15.4.5722.2) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Liven asennusty?kalu (x32 Version: 15.4.3502.0922) Windows Liven s?hk?posti (x32 Version: 15.4.3502.0922) Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922) XMind 2012 (v3.3.1) (x32 Version: 3.3.1.201212250029) ==================== Restore Points ========================= 11-06-2013 23:25:24 Windows Update 12-06-2013 07:47:22 Windows Update 16-06-2013 10:35:40 Windows Update 19-06-2013 06:06:53 Installed Java 7 Update 25 21-06-2013 06:21:23 Windows Update 26-06-2013 04:28:26 Windows Update 02-07-2013 08:54:50 Windows Update ==================== Hosts content: ========================== 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.10sek.com 127.0.0.1 10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 www.123fporn.info 127.0.0.1 123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are more than 1000 lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {007BF961-35D6-4997-8668-9B21A46AB1EA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe No File Task: {0F00A5B5-10B7-4CB4-BDC0-0E943EEBE9C4} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation) Task: {12C233F7-78E0-49C1-884C-7C7C3AA6E686} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.) Task: {193F5D68-B659-45B1-B9B3-13053757E9B7} - System32\Tasks\{79AE494A-B00F-4E51-9D02-806671315170} => C:\DISK1\_MSSETUP.EXE No File Task: {20433116-3838-4598-A8C8-32E3CE8F5A33} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {3813C30A-E783-4F16-839B-37BF74D535C0} - System32\Tasks\{C8099E57-DB19-44A3-9811-99FF52A6DB76} => C:\DISK1\SETUP.EXE No File Task: {3F4DD9FF-74EB-45B0-9B17-DB32709EB2AA} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient No File Task: {400EC6C2-FB40-444D-8F2C-92DC643BC27A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe No File Task: {4140F79D-C63D-41AD-A02D-12BA3CE145D9} - System32\Tasks\{A23A174C-68F5-40CA-B941-FDC1289EB290} => C:\DISK1\SETUP.EXE No File Task: {506A37A0-548C-4545-9782-20845E993604} - System32\Tasks\{379DF08F-7A5B-40E4-A6C9-BF55B02B91FA} => C:\DISK1\SETUP.EXE No File Task: {51D461DA-22E9-441B-8384-2D30FA940668} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {5483E0E3-3A4F-48EA-8175-582EBDB71603} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation) Task: {59FFB27E-68A5-46AB-9334-ADE36FD089D3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {5A6454FA-9FF5-42AF-9655-25EBCB00A014} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation) Task: {69B5207D-6704-4205-AAD9-78074959E958} - System32\Tasks\{0819DC4F-BECD-4FDA-B9E0-B16466E48BF5} => C:\DISK1\_MSSETUP.EXE No File Task: {6FD03CBD-0AF3-4D88-B06F-D9DC145AF713} - System32\Tasks\{0754E513-E313-47B3-B55E-F56D009DB678} => C:\DISK1\SETUP.EXE No File Task: {726180E2-6A8E-42AC-B602-40066AFEE225} - System32\Tasks\{BC3BFA7F-7C59-413D-9DA1-B7D3F9A5CCA8} => C:\DISK1\SETUP.EXE No File Task: {952F479D-6606-43BA-9F59-F073D5B3BA16} - System32\Tasks\{22A55328-89D4-43AA-9BD6-97C07E551919} => C:\DISK1\SETUP.EXE No File Task: {9CDA80ED-4A92-4A36-8374-5A4452287999} - System32\Tasks\{019D57EB-6012-42C2-B389-E900B529DED9} => C:\DISK1\SETUP.EXE No File Task: {A389D2A1-B14E-4975-BC69-515565B77A59} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-11-16] (Sony Corporation) Task: {A4573A20-64C3-48F9-823C-A35856C347D4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.) Task: {AC899129-C248-4F9C-89A1-599035721B77} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {BA8DCE2D-E731-4726-A808-77995317348B} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update 5 => C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe [2011-03-30] (Sony Corporation) Task: {BE482682-93CD-460A-B2A1-C762BBB33684} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation) Task: {C4AE742F-5E88-468C-915D-D354017594D2} - System32\Tasks\{5CE0363D-A773-4F22-986E-E5749604663D} => C:\DISK1\SETUP.EXE No File Task: {C70B2CF8-D882-4075-94B1-0A64FA67997D} - System32\Tasks\{5F4BD8CD-A5F6-4489-BA38-BDEA07419348} => C:\DISK1\SETUP.EXE No File Task: {CB65759A-6A9E-4176-A807-B58ABD497F64} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {D24C2055-9D96-4E63-910F-B86BDA8DB7CF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe No File Task: {D3F7629C-0745-4E82-9309-2CECD6619BA2} - System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation) Task: {D45A9D9B-2AAC-4113-B249-779F7C7823C6} - System32\Tasks\User_Feed_Synchronization-{F8F9D594-1F59-4874-8B7E-773D45408B09} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation) Task: {DF4D8943-C503-473F-835B-F61D9227C79C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.) Task: {EC433C01-59C3-4645-A5CD-942EE01664F4} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-09-16] (Hewlett-Packard Co.) Task: {ECB25488-1BEF-461F-9480-51C9C7FE112E} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-11-16] (Sony Corporation) Task: {F831395A-A7F0-4603-9820-68D2996C9E95} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Faulty Device Manager Devices ============= Name: Officejet 6000 E609a Description: Officejet 6000 E609a Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Photosmart 5510 series Description: Photosmart 5510 series Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (07/02/2013 03:57:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2013 03:40:26 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2013 01:47:26 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2013 01:47:33 PM) (Source: Application Error) (User: ) Description: Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16611, time stamp: 0x5191e7aa Faulting module name: igd10umd32.dll, version: 8.15.10.2291, time stamp: 0x4d41a0db Exception code: 0xc0000005 Fault offset: 0x000e3331 Faulting process id: 0xd14 Faulting application start time: 0xIEXPLORE.EXE0 Faulting application path: IEXPLORE.EXE1 Faulting module path: IEXPLORE.EXE2 Report Id: IEXPLORE.EXE3 Error: (06/30/2013 05:27:21 PM) (Source: Application Error) (User: ) Description: Faulting application name: firefox.exe, version: 21.0.0.4879, time stamp: 0x518ec3cc Faulting module name: xul.dll, version: 21.0.0.4879, time stamp: 0x518ec306 Exception code: 0xc0000005 Fault offset: 0x001c9789 Faulting process id: 0x3240 Faulting application start time: 0xfirefox.exe0 Faulting application path: firefox.exe1 Faulting module path: firefox.exe2 Report Id: firefox.exe3 Error: (06/30/2013 04:00:16 PM) (Source: Application Hang) (User: ) Description: The program IEXPLORE.EXE version 10.0.9200.16611 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2344 Start Time: 01ce759858fda6b9 Termination Time: 34 Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Report Id: Error: (06/30/2013 03:11:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/28/2013 11:44:14 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (06/28/2013 04:47:46 PM) (Source: Application Error) (User: ) Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x0000000000021cca Faulting process id: 0x3b8 Faulting application start time: 0xsvchost.exe0 Faulting application path: svchost.exe1 Faulting module path: svchost.exe2 Report Id: svchost.exe3 Error: (06/28/2013 10:16:11 AM) (Source: Application Error) (User: ) Description: Faulting application name: swi_service.exe, version: 3.2.101.0, time stamp: 0x510feb76 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec49b8f Exception code: 0xc0000005 Fault offset: 0x00065fe4 Faulting process id: 0xd18 Faulting application start time: 0xswi_service.exe0 Faulting application path: swi_service.exe1 Faulting module path: swi_service.exe2 Report Id: swi_service.exe3 System errors: ============= Error: (07/02/2013 03:58:56 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (07/02/2013 03:58:50 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC) Error: (07/02/2013 03:57:38 PM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (07/02/2013 03:41:35 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (07/02/2013 03:41:26 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC) Error: (07/02/2013 03:40:14 PM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Error: (07/02/2013 01:48:31 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (07/02/2013 01:48:25 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC) Error: (07/02/2013 01:46:15 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (07/02/2013 10:43:16 AM) (Source: BTHUSB) (User: ) Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. Microsoft Office Sessions: ========================= Error: (09/02/2012 05:32:29 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5308 seconds with 1020 seconds of active time. This session ended with a crash. Error: (07/17/2012 09:38:23 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 17791 seconds with 5040 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 43% Total physical RAM: 8139.86 MB Available physical RAM: 4600.7 MB Total Pagefile: 16277.9 MB Available Pagefile: 12702.95 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:452.18 GB) (Free:349.93 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: A920C8D1) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 17:07 on 02/07/2013 (Daniel) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- piristibulus PS: sollte ich während dieser Diagnose-Phase etwas beachten, was das Verschicken von Mails mit word-Dokumente an andere etc. betrifft? Vielen Dank |
02.07.2013, 18:16 | #4 | |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im MemoryCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.07.2013, 19:01 | #5 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Lieber Schrauber, vielen Dank! Habe das Programm runtergelanden und mein wireless ausgeschaltet, dann Sophos und Windows Defender abgestellt und ebenso - dachte ich jedenfalls - Spybot. Dann kam jedoch ein pop-up, dass Spybot noch immer im Hintergrund am laufen sei. Ich habe dann "versucht", dieses über den Taskmanager abzuschalten. Ob es geklappt hat, weiss ich nicht. ComboFix gab die Meldung, es würde dennoch auf eigene Gefahr weiterlaufen. Hier ist das Log (einen Re-start hat das Programm nicht ausgeführt): Code:
ATTFilter ComboFix 13-07-02.03 - Daniel 02/07/2013 19:46:29.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1256.966.1033.18.8140.5182 [GMT 2:00] Running from: c:\users\Daniel\Desktop\ComboFix.exe AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337} SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Daniel\AppData\Local\assembly\tmp c:\users\Daniel\AppData\Roaming\Waeged c:\users\Daniel\AppData\Roaming\Waeged\ihurp.exe c:\users\Daniel\Documents\~WRL0005.tmp c:\windows\IsUn0407.exe . . ((((((((((((((((((((((((( Files Created from 2013-06-02 to 2013-07-02 ))))))))))))))))))))))))))))))) . . 2013-07-02 17:51 . 2013-07-02 17:51 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-02 15:48 . 2013-07-02 15:48 -------- d-----w- C:\FRST 2013-07-02 08:55 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7C9A529E-5E06-4E86-9532-509BACFD89BD}\mpengine.dll 2013-07-01 11:13 . 2013-07-01 19:43 -------- d-----w- c:\users\Daniel\AppData\Roaming\Vyde 2013-07-01 11:13 . 2013-07-01 11:13 -------- d-----w- c:\users\Daniel\AppData\Roaming\Qiebu 2013-06-26 12:28 . 2013-06-26 14:02 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2013-06-19 06:08 . 2013-06-12 19:47 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-12 07:49 . 2013-05-17 01:25 257536 ----a-w- c:\program files (x86)\Internet Explorer\ieproxy.dll 2013-06-11 23:28 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-12 19:48 . 2012-12-07 15:18 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-06-12 19:48 . 2012-02-06 12:56 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-06-12 15:51 . 2012-04-30 19:30 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-12 15:51 . 2012-04-30 19:30 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-12 07:49 . 2012-03-24 16:57 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-05-31 01:26 . 2013-05-31 01:26 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-05-31 01:26 . 2013-05-31 01:26 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-05-31 01:26 . 2013-05-31 01:26 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-05-31 01:26 . 2013-05-31 01:26 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-05-31 01:26 . 2013-05-31 01:26 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-05-31 01:26 . 2013-05-31 01:26 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-05-31 01:26 . 2013-05-31 01:26 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-05-31 01:26 . 2013-05-31 01:26 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-05-31 01:26 . 2013-05-31 01:26 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-05-31 01:26 . 2013-05-31 01:26 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-05-31 01:26 . 2013-05-31 01:26 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-05-31 01:26 . 2013-05-31 01:26 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-05-31 01:26 . 2013-05-31 01:26 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-05-31 01:26 . 2013-05-31 01:26 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-05-31 01:26 . 2013-05-31 01:26 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-05-31 01:26 . 2013-05-31 01:26 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-05-31 01:26 . 2013-05-31 01:26 81408 ----a-w- c:\windows\system32\icardie.dll 2013-05-31 01:26 . 2013-05-31 01:26 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-05-31 01:26 . 2013-05-31 01:26 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-05-31 01:26 . 2013-05-31 01:26 441856 ----a-w- c:\windows\system32\html.iec 2013-05-31 01:26 . 2013-05-31 01:26 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-05-31 01:26 . 2013-05-31 01:26 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-05-31 01:26 . 2013-05-31 01:26 216064 ----a-w- c:\windows\system32\msls31.dll 2013-05-31 01:26 . 2013-05-31 01:26 197120 ----a-w- c:\windows\system32\msrating.dll 2013-05-31 01:26 . 2013-05-31 01:26 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-05-31 01:26 . 2013-05-31 01:26 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-05-31 01:26 . 2013-05-31 01:26 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-05-31 01:26 . 2013-05-31 01:26 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-05-31 01:26 . 2013-05-31 01:26 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-05-31 01:26 . 2013-05-31 01:26 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-05-31 01:26 . 2013-05-31 01:26 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-05-31 01:26 . 2013-05-31 01:26 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-05-31 01:26 . 2013-05-31 01:26 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-05-31 01:26 . 2013-05-31 01:26 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-05-31 01:26 . 2013-05-31 01:26 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-05-31 01:26 . 2013-05-31 01:26 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-05-31 01:26 . 2013-05-31 01:26 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-05-31 01:26 . 2013-05-31 01:26 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-05-31 01:26 . 2013-05-31 01:26 235008 ----a-w- c:\windows\system32\url.dll 2013-05-31 01:26 . 2013-05-31 01:26 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-05-31 01:26 . 2013-05-31 01:26 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-05-31 01:26 . 2013-05-31 01:26 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-05-31 01:26 . 2013-05-31 01:26 149504 ----a-w- c:\windows\system32\occache.dll 2013-05-31 01:26 . 2013-05-31 01:26 144896 ----a-w- c:\windows\system32\wextract.exe 2013-05-31 01:26 . 2013-05-31 01:26 13824 ----a-w- c:\windows\system32\mshta.exe 2013-05-31 01:26 . 2013-05-31 01:26 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-05-31 01:26 . 2013-05-31 01:26 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-05-31 01:26 . 2013-05-31 01:26 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-05-31 01:26 . 2013-05-31 01:26 102912 ----a-w- c:\windows\system32\inseng.dll 2013-05-31 01:03 . 2013-05-31 01:03 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-05-31 01:03 . 2013-05-31 01:03 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-05-31 01:03 . 2013-05-31 01:03 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-05-31 01:03 . 2013-05-31 01:03 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-05-31 01:03 . 2013-05-31 01:03 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-05-31 01:03 . 2013-05-31 01:03 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-05-31 01:03 . 2013-05-31 01:03 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-05-31 01:03 . 2013-05-31 01:03 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-05-31 01:03 . 2013-05-31 01:03 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-05-31 01:03 . 2013-05-31 01:03 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-05-31 01:03 . 2013-05-31 01:03 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-05-31 01:03 . 2013-05-31 01:03 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-05-31 01:03 . 2013-05-31 01:03 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-05-31 01:03 . 2013-05-31 01:03 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-05-31 01:03 . 2013-05-31 01:03 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-05-31 01:03 . 2013-05-31 01:03 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2013-05-31 01:03 . 2013-05-31 01:03 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2013-05-31 01:03 . 2013-05-31 01:03 1643520 ----a-w- c:\windows\system32\DWrite.dll 2013-05-31 01:03 . 2013-05-31 01:03 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2013-05-31 01:03 . 2013-05-31 01:03 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2013-05-31 01:03 . 2013-05-31 01:03 1238528 ----a-w- c:\windows\system32\d3d10.dll 2013-05-31 01:03 . 2013-05-31 01:03 1175552 ----a-w- c:\windows\system32\FntCache.dll 2013-05-31 01:03 . 2013-05-31 01:03 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2013-05-31 01:03 . 2013-05-31 01:03 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll 2013-05-31 01:03 . 2013-05-31 01:03 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-05-31 01:03 . 2013-05-31 01:03 293376 ----a-w- c:\windows\SysWow64\dxgi.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{6B34ACCF-1B63-4E1A-8633-461917C75544}"= "c:\program files (x86)\Freecorder 6\tbcore3.dll" [2012-08-01 2711928] . [HKEY_CLASSES_ROOT\clsid\{6b34accf-1b63-4e1a-8633-461917c75544}] [HKEY_CLASSES_ROOT\TBSB00808.TBSB00808.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB00808.TBSB00808] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-03-27 39408] "HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-09-16 2676584] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "VoipBuster"="c:\program files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" [2013-06-25 19378496] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18705664] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312] "PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208] "STO Backup Service"="c:\program files (x86)\SmarThru Office\BackUpSvr.exe" [2012-01-13 199760] "STO Launcher Service"="c:\program files (x86)\SmarThru Office\x64\LegacyLauncher.exe" [2012-01-13 405584] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176] "Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2013-04-03 929272] "PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-03-20 162856] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . c:\users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968] OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService] @="service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [x] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x] R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys;c:\windows\SYSNATIVE\DRIVERS\sdcfilter.sys [x] R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x] R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x] R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x] R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x] R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x] R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys;c:\windows\SYSNATIVE\DRIVERS\SophosBootDriver.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys;c:\windows\SYSNATIVE\DRIVERS\savonaccess.sys [x] S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x] S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x] S2 Samsung Network Fax Server;Samsung Network Fax Server;c:\windows\system32\spool\drivers\x64\3\NetFaxServer64.exe;c:\windows\SYSNATIVE\spool\drivers\x64\3\NetFaxServer64.exe [x] S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [x] S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [x] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [x] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x] S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [x] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x] S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x] S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe;c:\program files\Sony\VAIO Update 5\VUAgent.exe [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-07-02 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 15:51] . 2013-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42] . 2013-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42] . 2013-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job - c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53] . 2013-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job - c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53] . 2013-07-02 c:\windows\Tasks\HP Photo Creations Messager.job - c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-04-29 790688] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-04-29 657568] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-29 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-29 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-29 418328] "CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2010-12-17 438784] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.wikipedia.org/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\Daniel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll TCP: DhcpNameServer = 192.168.178.1 TCP: Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: NameServer = 141.2.22.74,141.2.149.10 FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.bl.uk/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?q= FF - ExtSQL: !HIDDEN! 2012-05-11 13:13; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-Cilehaze - c:\users\Daniel\AppData\Roaming\Waeged\ihurp.exe Wow6432Node-HKLM-Run-<NO NAME> - (no file) Notify-SDWinLogon - SDWinLogon.dll HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start WebBrowser-{6B34ACCF-1B63-4E1A-8633-461917C75544} - (no file) HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector] "ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\"" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-07-02 19:53:32 ComboFix-quarantined-files.txt 2013-07-02 17:53 . Pre-Run: 375,567,732,736 bytes free Post-Run: 375,206,096,896 bytes free . - - End Of File - - B0D7EB9FC6935241137B2955187EDD93 D41D8CD98F00B204E9800998ECF8427E Piristibulus |
03.07.2013, 07:13 | #6 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Hi, Combofix-Skript
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST Log bitte. Noch Probleme?
__________________ --> Sophosmeldung: Troj/ZbotMem-B im Memory |
03.07.2013, 20:45 | #7 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Lieber Schrauber, vielen Dank für die Hilfe. Vorab erstmal, es scheint schon einiges bewirkt zu haben. Die Akzente und Sonderzeichen der fremdsprachlichen Tastaturbelegungen funktionieren wieder einwandfrei, und Akzente werden auch nicht mehr doppelt geschrieben. Hier nun die Logs: 1. ComboFix.txt: Code:
ATTFilter ComboFix 13-07-02.03 - Daniel 03/07/2013 10:23:36.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1256.966.1033.18.8140.5708 [GMT 2:00] Running from: c:\users\Daniel\Desktop\ComboFix.exe Command switches used :: c:\users\Daniel\Desktop\CFScript.txt AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337} SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Daniel\AppData\Roaming\Qiebu c:\users\Daniel\AppData\Roaming\Qiebu\azgo.xik c:\users\Daniel\AppData\Roaming\Vyde . . ((((((((((((((((((((((((( Files Created from 2013-06-03 to 2013-07-03 ))))))))))))))))))))))))))))))) . . 2013-07-03 08:27 . 2013-07-03 08:27 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-02 15:48 . 2013-07-02 15:48 -------- d-----w- C:\FRST 2013-07-02 08:55 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7C9A529E-5E06-4E86-9532-509BACFD89BD}\mpengine.dll 2013-06-26 12:28 . 2013-06-26 14:02 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird 2013-06-19 06:08 . 2013-06-12 19:47 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-12 07:49 . 2013-05-17 01:25 257536 ----a-w- c:\program files (x86)\Internet Explorer\ieproxy.dll 2013-06-11 23:28 . 2013-05-08 06:39 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-12 19:48 . 2012-12-07 15:18 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-06-12 19:48 . 2012-02-06 12:56 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-06-12 15:51 . 2012-04-30 19:30 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-12 15:51 . 2012-04-30 19:30 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-12 07:49 . 2012-03-24 16:57 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-05-31 01:26 . 2013-05-31 01:26 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-05-31 01:26 . 2013-05-31 01:26 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-05-31 01:26 . 2013-05-31 01:26 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-05-31 01:26 . 2013-05-31 01:26 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-05-31 01:26 . 2013-05-31 01:26 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-05-31 01:26 . 2013-05-31 01:26 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-05-31 01:26 . 2013-05-31 01:26 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-05-31 01:26 . 2013-05-31 01:26 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-05-31 01:26 . 2013-05-31 01:26 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-05-31 01:26 . 2013-05-31 01:26 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-05-31 01:26 . 2013-05-31 01:26 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-05-31 01:26 . 2013-05-31 01:26 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-05-31 01:26 . 2013-05-31 01:26 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-05-31 01:26 . 2013-05-31 01:26 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-05-31 01:26 . 2013-05-31 01:26 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-05-31 01:26 . 2013-05-31 01:26 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-05-31 01:26 . 2013-05-31 01:26 81408 ----a-w- c:\windows\system32\icardie.dll 2013-05-31 01:26 . 2013-05-31 01:26 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-05-31 01:26 . 2013-05-31 01:26 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-05-31 01:26 . 2013-05-31 01:26 441856 ----a-w- c:\windows\system32\html.iec 2013-05-31 01:26 . 2013-05-31 01:26 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-05-31 01:26 . 2013-05-31 01:26 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-05-31 01:26 . 2013-05-31 01:26 216064 ----a-w- c:\windows\system32\msls31.dll 2013-05-31 01:26 . 2013-05-31 01:26 197120 ----a-w- c:\windows\system32\msrating.dll 2013-05-31 01:26 . 2013-05-31 01:26 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-05-31 01:26 . 2013-05-31 01:26 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-05-31 01:26 . 2013-05-31 01:26 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-05-31 01:26 . 2013-05-31 01:26 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-05-31 01:26 . 2013-05-31 01:26 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-05-31 01:26 . 2013-05-31 01:26 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-05-31 01:26 . 2013-05-31 01:26 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-05-31 01:26 . 2013-05-31 01:26 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-05-31 01:26 . 2013-05-31 01:26 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-05-31 01:26 . 2013-05-31 01:26 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-05-31 01:26 . 2013-05-31 01:26 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-05-31 01:26 . 2013-05-31 01:26 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-05-31 01:26 . 2013-05-31 01:26 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-05-31 01:26 . 2013-05-31 01:26 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-05-31 01:26 . 2013-05-31 01:26 235008 ----a-w- c:\windows\system32\url.dll 2013-05-31 01:26 . 2013-05-31 01:26 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-05-31 01:26 . 2013-05-31 01:26 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-05-31 01:26 . 2013-05-31 01:26 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-05-31 01:26 . 2013-05-31 01:26 149504 ----a-w- c:\windows\system32\occache.dll 2013-05-31 01:26 . 2013-05-31 01:26 144896 ----a-w- c:\windows\system32\wextract.exe 2013-05-31 01:26 . 2013-05-31 01:26 13824 ----a-w- c:\windows\system32\mshta.exe 2013-05-31 01:26 . 2013-05-31 01:26 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-05-31 01:26 . 2013-05-31 01:26 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-05-31 01:26 . 2013-05-31 01:26 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-05-31 01:26 . 2013-05-31 01:26 102912 ----a-w- c:\windows\system32\inseng.dll 2013-05-31 01:03 . 2013-05-31 01:03 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-05-31 01:03 . 2013-05-31 01:03 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-05-31 01:03 . 2013-05-31 01:03 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-05-31 01:03 . 2013-05-31 01:03 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-05-31 01:03 . 2013-05-31 01:03 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-05-31 01:03 . 2013-05-31 01:03 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-05-31 01:03 . 2013-05-31 01:03 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-05-31 01:03 . 2013-05-31 01:03 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-05-31 01:03 . 2013-05-31 01:03 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-05-31 01:03 . 2013-05-31 01:03 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-05-31 01:03 . 2013-05-31 01:03 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-05-31 01:03 . 2013-05-31 01:03 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-05-31 01:03 . 2013-05-31 01:03 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-05-31 01:03 . 2013-05-31 01:03 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-05-31 01:03 . 2013-05-31 01:03 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-05-31 01:03 . 2013-05-31 01:03 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2013-05-31 01:03 . 2013-05-31 01:03 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2013-05-31 01:03 . 2013-05-31 01:03 1643520 ----a-w- c:\windows\system32\DWrite.dll 2013-05-31 01:03 . 2013-05-31 01:03 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2013-05-31 01:03 . 2013-05-31 01:03 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2013-05-31 01:03 . 2013-05-31 01:03 1238528 ----a-w- c:\windows\system32\d3d10.dll 2013-05-31 01:03 . 2013-05-31 01:03 1175552 ----a-w- c:\windows\system32\FntCache.dll 2013-05-31 01:03 . 2013-05-31 01:03 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2013-05-31 01:03 . 2013-05-31 01:03 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll 2013-05-31 01:03 . 2013-05-31 01:03 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-31 01:03 . 2013-05-31 01:03 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-05-31 01:03 . 2013-05-31 01:03 293376 ----a-w- c:\windows\SysWow64\dxgi.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{6B34ACCF-1B63-4E1A-8633-461917C75544}"= "c:\program files (x86)\Freecorder 6\tbcore3.dll" [2012-08-01 2711928] . [HKEY_CLASSES_ROOT\clsid\{6b34accf-1b63-4e1a-8633-461917c75544}] [HKEY_CLASSES_ROOT\TBSB00808.TBSB00808.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB00808.TBSB00808] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-03-27 39408] "HP Photosmart 5510 series (NET)"="c:\program files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" [2011-09-16 2676584] "VoipBuster"="c:\program files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" [2013-06-25 19378496] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-01-08 18705664] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160] "ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15 2757312] "PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-27 648032] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208] "STO Backup Service"="c:\program files (x86)\SmarThru Office\BackUpSvr.exe" [2012-01-13 199760] "STO Launcher Service"="c:\program files (x86)\SmarThru Office\x64\LegacyLauncher.exe" [2012-01-13 405584] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176] "Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2013-04-03 929272] "PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-03-20 162856] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . c:\users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968] OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService] @="service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [x] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x] R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys;c:\windows\SYSNATIVE\DRIVERS\sdcfilter.sys [x] R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [x] R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [x] R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x] R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x] R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x] R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x] R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys;c:\windows\SYSNATIVE\DRIVERS\SophosBootDriver.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys;c:\windows\SYSNATIVE\DRIVERS\savonaccess.sys [x] S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x] S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x] S2 Samsung Network Fax Server;Samsung Network Fax Server;c:\windows\system32\spool\drivers\x64\3\NetFaxServer64.exe;c:\windows\SYSNATIVE\spool\drivers\x64\3\NetFaxServer64.exe [x] S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [x] S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [x] S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [x] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x] S2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [x] S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x] S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x] S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x] S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe;c:\program files\Sony\VAIO Update 5\VUAgent.exe [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-07-03 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 15:51] . 2013-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42] . 2013-07-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27 17:42] . 2013-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job - c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53] . 2013-07-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job - c:\users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-04 22:53] . 2013-07-03 c:\windows\Tasks\HP Photo Creations Messager.job - c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2011-03-29 518784] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-04-29 790688] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-04-29 657568] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-29 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-29 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-29 418328] "Apoint"="c:\program files (x86)\Apoint\Apoint.exe" [BU] "CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2010-12-17 438784] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.wikipedia.org/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = <local> IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\Daniel\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll TCP: DhcpNameServer = 192.168.178.1 TCP: Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: NameServer = 141.2.22.74,141.2.149.10 FF - ProfilePath - c:\users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.bl.uk/ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?q= FF - ExtSQL: !HIDDEN! 2012-05-11 13:13; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run-<NO NAME> - (no file) Notify-SDWinLogon - SDWinLogon.dll WebBrowser-{6B34ACCF-1B63-4E1A-8633-461917C75544} - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector] "ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\"" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-07-03 10:30:00 ComboFix-quarantined-files.txt 2013-07-03 08:29 ComboFix2.txt 2013-07-02 17:53 . Pre-Run: 374,696,648,704 bytes free Post-Run: 374,614,482,944 bytes free . - - End Of File - - 849EECEAA11D9362AAFE6FBEF3CFEF45 D41D8CD98F00B204E9800998ECF8427E 2. AdwCleaner: Code:
ATTFilter # AdwCleaner v2.303 - Logfile created 07/03/2013 at 10:48:46 # Updated 08/06/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Daniel - SOFERMAHIR # Boot Mode : Normal # Running from : C:\Users\Daniel\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\extensions\browserprotect@browserprotect.com.xpi Folder Deleted : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com Key Deleted : HKLM\Software\DeviceVM Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AFB904C4-C255-4540-B97E-A75A34F1FFB0} ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16611 [OK] Registry is clean. -\\ Mozilla Firefox v21.0 (en-US) File : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\prefs.js C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\user.js ... Deleted ! [OK] File is clean. ************************* AdwCleaner[R1].txt - [19015 octets] - [27/03/2013 02:57:18] AdwCleaner[R2].txt - [19135 octets] - [28/03/2013 21:41:05] AdwCleaner[R3].txt - [19196 octets] - [28/03/2013 21:41:53] AdwCleaner[S1].txt - [324 octets] - [27/03/2013 02:57:50] AdwCleaner[S2].txt - [19913 octets] - [28/03/2013 21:42:02] AdwCleaner[S3].txt - [1575 octets] - [03/07/2013 10:48:46] ########## EOF - C:\AdwCleaner[S3].txt - [1635 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by Daniel on 03/07/2013 at 11:11:08.86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{3B5F6094-95AD-4B35-B413-E16D39E0C013} Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{46567E52-EAB1-4414-9BCD-43C6348F99C8} Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{5E521E1D-8E66-4E99-A05E-178569C823AC} Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{82B199CB-9F19-41FA-A999-6E26721021F6} Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{B636F192-E4D2-4279-848E-BBD2F30B56B0} Successfully deleted: [Empty Folder] C:\Users\Daniel\appdata\local\{F3B2E688-FFDD-4715-8118-48FC49BB049C} ~~~ FireFox Emptied folder: C:\Users\Daniel\AppData\Roaming\mozilla\firefox\profiles\16xncyrs.default\minidumps [187 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 03/07/2013 at 11:16:25.72 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=b8f46c7edbe67b4aa18d407f31e20020 # engine=14244 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-03 05:42:46 # local_time=2013-07-03 07:42:46 (+0100, W. Europe Daylight Time) # country="United Kingdom" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 34448 124503216 0 0 # compatibility_mode=8450 16777213 85 99 29323 7897465 0 0 # scanned=269401 # found=2 # cleaned=0 # scan_time=28857 sh=15133AE329D0B132CC4DD7A19DBAA4648A0E4DFC ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\6bddbdd6-50147857" sh=6D349F0A3BAEDE0999E5744595E97291BE26ABC6 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" 5: checkup.txt: Code:
ATTFilter Results of screen317's Security Check version 0.99.68 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! Windows Firewall Disabled! Sophos Anti-Virus WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Java(TM) 6 Update 22 Java 7 Update 25 Adobe Flash Player 11.7.700.224 Adobe Reader 10.1.7 Adobe Reader out of Date! Mozilla Firefox 21.0 Firefox out of Date! Mozilla Thunderbird (17.0.7) ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! Sophos Sophos Anti-Virus SavService.exe Sophos Sophos Anti-Virus SAVAdminService.exe Sophos Sophos Anti-Virus Web Control swc_service.exe Sophos Sophos Anti-Virus Web Intelligence swi_service.exe Sophos Sophos Anti-Virus SavMain.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 0% ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013 Ran by Daniel (administrator) on 03-07-2013 21:19:00 Running from C:\Users\Daniel\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe (VoipBuster) C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Dropbox, Inc.) C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update 5\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.) HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [790688 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-04-29] (Atheros Commnucations) HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.) HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] () HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-27] (Google Inc.) HKCU\...\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN175050KX05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 [2676584 2011-09-16] (Hewlett-Packard Co.) HKCU\...\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized [19378496 2013-06-25] (VoipBuster) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18705664 2013-01-08] (Skype Technologies S.A.) HKCU\...\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean [3713032 2012-11-13] (Safer-Networking Ltd.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation) HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM-x32\...\Run: [] [x] HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [STO Backup Service] C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe [199760 2012-01-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [STO Launcher Service] C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe /autorun [405584 2012-01-13] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-04-03] (Sophos Limited) HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation) AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll [218256 2013-04-03] (Sophos Limited) AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured.dll [221840 2013-04-03] (Sophos Limited) Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wikipedia.org/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKCU - {623BD34C-6486-4770-B994-92555203C850} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=hxxp://shop.ebay.co.uk/?oemInLn=ieSrch-Q311&_nkw={searchTerms} SearchScopes: HKCU - {8C1B1A63-658F-4F07-BDC0-B7765C458695} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Freecorder 6 - {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll () Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {6B34ACCF-1B63-4E1A-8633-461917C75544} - No File DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited) Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Winsock: Catalog9-x64 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: [NameServer]141.2.22.74,141.2.149.10 FireFox: ======== FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default FF NewTab: www.bl.uk FF SearchEngine: Google FF Homepage: hxxp://www.bl.uk/ FF Keyword.URL: hxxp://www.google.com/search?q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.) FF Extension: Visualisateur 3D de 20-20 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\2020Player_IKEA@2020Technologies.com FF Extension: Deutsches W?rterbuch - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\de-DE@dictionaries.addons.mozilla.org FF Extension: Freecorder 6 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{132E58DE-22BF-44CA-A061-7FCE1E8BA1EC} FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: <?xml version="1.0"?> <RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#"> <Description about="urn:mozilla:install-manifest"> <em:id>smartwebprinting@hp.com</em:id> <em:version>4.60</em:version> <em:targetApplication> <!-- Firefox --> <Description> <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id> <em:minVersion>3.5.0.0</em:minVersion> <em:maxVersion>3.5.*.*</em:maxVersion> </Description> </em:targetApplication> <!-- front-end metadata --> <em:name>HP Smart Web Printing</em:name> <em:description>Print what you want, how you want.</em:description> <em:creator>hp.com</em:creator> <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL> <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL> <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL> <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform> </Description> </RDF> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: <?xml version="1.0"?> <RDF xmlns="hxxp://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="hxxp://www.mozilla.org/2004/em-rdf#"> <Description about="urn:mozilla:install-manifest"> <em:id>smartwebprinting@hp.com</em:id> <em:version>4.60</em:version> <em:targetApplication> <!-- Firefox --> <Description> <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id> <em:minVersion>3.5.0.0</em:minVersion> <em:maxVersion>3.5.*.*</em:maxVersion> </Description> </em:targetApplication> <!-- front-end metadata --> <em:name>HP Smart Web Printing</em:name> <em:description>Print what you want, how you want.</em:description> <em:creator>hp.com</em:creator> <em:homepageURL>hxxp://www.hp.com/go/smartwebprinting</em:homepageURL> <em:aboutURL>chrome://hpsmartwebprinting/content/about.xul</em:aboutURL> <em:iconURL>chrome://hpsmartwebprinting/skin/toolbar-icon-normal-24.png</em:iconURL> <em:targetPlatform>WINNT_x86-msvc</em:targetPlatform> </Description> </RDF> - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 ==================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [231936 2012-03-22] (Samsung Electronics Co., Ltd.) R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [217592 2013-04-03] (Sophos Limited) R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [159296 2013-04-03] (Sophos Limited) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-04-03] (Sophos Limited) R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2013-04-03] (Sophos Limited) R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2890232 2013-04-03] (Sophos Limited) S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2010688 2013-04-03] (Sophos Limited) R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R3 VUAgent; C:\Program Files\Sony\VAIO Update 5\VUAgent.exe [1021112 2011-03-30] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-04-03] (Sophos Limited) S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2013-04-03] (Sophos Limited) S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2013-04-03] (Sophos Plc) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-03 21:17 - 2013-07-03 21:17 - 00001294 ____A C:\Users\Daniel\Desktop\checkup.txt 2013-07-03 21:09 - 2013-07-03 21:09 - 00890988 ____A C:\Users\Daniel\Desktop\SecurityCheck.exe 2013-07-03 11:30 - 2013-07-03 11:30 - 02347384 ____A (ESET) C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe 2013-07-03 11:16 - 2013-07-03 11:16 - 00001722 ____A C:\Users\Daniel\Desktop\JRT.txt 2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\JRT 2013-07-03 11:08 - 2013-07-03 11:09 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe 2013-07-03 10:50 - 2013-07-03 10:50 - 00000988 ____A C:\Windows\PFRO.log 2013-07-03 10:48 - 2013-07-03 10:48 - 00001704 ____A C:\AdwCleaner[S3].txt 2013-07-03 10:44 - 2013-07-03 10:45 - 00648201 ____A C:\Users\Daniel\Desktop\adwcleaner.exe 2013-07-03 10:30 - 2013-07-03 10:30 - 00034657 ____A C:\ComboFix.txt 2013-07-03 10:22 - 2013-07-03 10:30 - 00000000 ____D C:\ComboFix 2013-07-03 10:04 - 2013-07-03 10:05 - 05084414 ____R (Swearware) C:\Users\Daniel\Desktop\ComboFix.exe 2013-07-02 20:03 - 2013-07-02 19:53 - 00035060 ____A C:\Users\Daniel\Desktop\ComboFix.txt 2013-07-02 19:45 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:45 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:45 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:45 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:45 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:45 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:45 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:45 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:40 - 2013-07-03 10:30 - 00000000 ____D C:\Qoobox 2013-07-02 19:40 - 2013-07-02 19:51 - 00000000 ____D C:\Windows\erdnt 2013-07-02 17:49 - 2013-07-02 17:50 - 00031125 ____A C:\Users\Daniel\Desktop\Addition.txt 2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST 2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-07-02 17:06 - 2013-07-02 17:07 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log 2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable 2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe 2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-02 16:02 - 2013-07-02 16:03 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe 2013-07-01 15:40 - 2013-07-01 15:47 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml 2013-06-26 14:28 - 2013-06-26 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk 2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx 2013-06-19 08:08 - 2013-06-12 21:47 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-19 08:08 - 2013-06-12 21:43 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-19 08:07 - 2013-06-19 08:08 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log 2013-06-19 08:07 - 2013-06-12 21:43 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-17 23:38 - 2013-06-17 23:42 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx 2013-06-16 12:36 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-16 12:36 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-16 12:36 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-16 12:36 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-16 12:36 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-16 12:36 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-16 12:36 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-14 10:17 - 2013-06-20 15:13 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx 2013-06-12 17:54 - 2013-06-20 10:32 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx 2013-06-12 09:49 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-06-12 09:49 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-06-12 09:49 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-06-12 09:49 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-06-12 09:49 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-06-12 09:49 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-06-12 09:49 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-06-12 09:49 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-06-12 01:28 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll 2013-06-12 01:28 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll 2013-06-12 01:28 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll 2013-06-12 01:28 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-06-12 01:28 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-06-12 01:28 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe 2013-06-12 01:28 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2013-06-12 01:28 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2013-06-12 01:28 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll 2013-06-12 01:28 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-06-12 01:28 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-06-12 01:28 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2013-06-12 01:28 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2013-06-12 01:28 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-06-12 01:28 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-06-12 01:28 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll 2013-06-12 01:28 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll 2013-06-11 22:38 - 2013-07-03 12:40 - 00010012 ____A C:\Windows\setupact.log 2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log 2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx 2013-06-10 18:25 - 2013-06-13 10:16 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx 2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc ==================== One Month Modified Files and Folders ======= 2013-07-03 21:17 - 2013-07-03 21:17 - 00001294 ____A C:\Users\Daniel\Desktop\checkup.txt 2013-07-03 21:16 - 2012-04-04 15:20 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job 2013-07-03 21:10 - 2012-02-06 14:45 - 01726655 ____A C:\Windows\WindowsUpdate.log 2013-07-03 21:09 - 2013-07-03 21:09 - 00890988 ____A C:\Users\Daniel\Desktop\SecurityCheck.exe 2013-07-03 21:01 - 2012-04-06 15:34 - 00000258 ____A C:\Windows\Tasks\HP Photo Creations Messager.job 2013-07-03 20:51 - 2013-01-21 11:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-03 20:39 - 2012-03-27 19:43 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-03 12:40 - 2013-06-11 22:38 - 00010012 ____A C:\Windows\setupact.log 2013-07-03 11:36 - 2009-07-14 07:13 - 00778834 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-03 11:35 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-03 11:35 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-03 11:30 - 2013-07-03 11:30 - 02347384 ____A (ESET) C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe 2013-07-03 11:30 - 2012-04-15 21:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype 2013-07-03 11:30 - 2012-03-26 15:06 - 00000000 ___RD C:\Users\Daniel\Dropbox 2013-07-03 11:30 - 2012-03-26 14:58 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Dropbox 2013-07-03 11:27 - 2012-03-27 19:43 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-03 11:27 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-03 11:16 - 2013-07-03 11:16 - 00001722 ____A C:\Users\Daniel\Desktop\JRT.txt 2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 11:11 - 2013-07-03 11:11 - 00000000 ____D C:\JRT 2013-07-03 11:09 - 2013-07-03 11:08 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Daniel\Desktop\JRT.exe 2013-07-03 10:50 - 2013-07-03 10:50 - 00000988 ____A C:\Windows\PFRO.log 2013-07-03 10:48 - 2013-07-03 10:48 - 00001704 ____A C:\AdwCleaner[S3].txt 2013-07-03 10:45 - 2013-07-03 10:44 - 00648201 ____A C:\Users\Daniel\Desktop\adwcleaner.exe 2013-07-03 10:30 - 2013-07-03 10:30 - 00034657 ____A C:\ComboFix.txt 2013-07-03 10:30 - 2013-07-03 10:22 - 00000000 ____D C:\ComboFix 2013-07-03 10:30 - 2013-07-02 19:40 - 00000000 ____D C:\Qoobox 2013-07-03 10:27 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-03 10:22 - 2013-03-28 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-03 10:05 - 2013-07-03 10:04 - 05084414 ____R (Swearware) C:\Users\Daniel\Desktop\ComboFix.exe 2013-07-03 06:16 - 2012-04-04 15:20 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job 2013-07-02 19:53 - 2013-07-02 20:03 - 00035060 ____A C:\Users\Daniel\Desktop\ComboFix.txt 2013-07-02 19:53 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default 2013-07-02 19:51 - 2013-07-02 19:40 - 00000000 ____D C:\Windows\erdnt 2013-07-02 17:50 - 2013-07-02 17:49 - 00031125 ____A C:\Users\Daniel\Desktop\Addition.txt 2013-07-02 17:48 - 2013-07-02 17:48 - 00000000 ____D C:\FRST 2013-07-02 17:44 - 2013-07-02 17:44 - 01933556 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2013-07-02 17:07 - 2013-07-02 17:06 - 00000474 ____A C:\Users\Daniel\Desktop\defogger_disable.log 2013-07-02 17:06 - 2013-07-02 17:06 - 00000000 ____A C:\Users\Daniel\defogger_reenable 2013-07-02 17:06 - 2012-03-12 21:09 - 00000000 ____D C:\users\Daniel 2013-07-02 17:04 - 2013-07-02 17:04 - 00050477 ____A C:\Users\Daniel\Desktop\Defogger.exe 2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-07-02 16:03 - 2013-07-02 16:02 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe 2013-07-02 16:03 - 2012-06-13 23:11 - 00000000 ____D C:\Program Files\CCleaner 2013-07-02 15:42 - 2013-05-02 00:35 - 00000000 ____D C:\Users\Daniel\Documents\shamela-r1 2013-07-02 15:42 - 2012-03-29 01:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\shamela 2013-07-01 15:47 - 2013-07-01 15:40 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml 2013-07-01 13:47 - 2012-03-25 16:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps 2013-06-28 16:48 - 2012-03-24 20:21 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mozilla 2013-06-28 12:30 - 2013-02-22 22:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc 2013-06-28 12:11 - 2012-11-22 16:29 - 00000099 ____A C:\Users\Public\LMDebug.log 2013-06-27 08:44 - 2013-05-28 12:59 - 00177947 ____A C:\test.xml 2013-06-26 17:33 - 2012-04-24 23:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-26 16:02 - 2013-06-26 14:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-26 13:54 - 2012-04-26 19:34 - 00000000 ____D C:\Users\Daniel\Documents\Citavi 3 2013-06-26 00:00 - 2012-07-25 18:26 - 00000000 ____D C:\Users\Daniel\Documents\Calibre Library 2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk 2013-06-25 09:17 - 2012-03-27 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google 2013-06-21 16:32 - 2012-07-07 22:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\dvdcss 2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx 2013-06-20 15:13 - 2013-06-14 10:17 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx 2013-06-20 14:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF 2013-06-20 10:32 - 2013-06-12 17:54 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx 2013-06-19 08:08 - 2013-06-19 08:07 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log 2013-06-19 08:08 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Java 2013-06-17 23:42 - 2013-06-17 23:38 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx 2013-06-15 13:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-06-13 10:16 - 2013-06-10 18:25 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx 2013-06-12 21:48 - 2012-12-07 17:18 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-06-12 21:48 - 2012-02-06 14:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-06-12 21:47 - 2013-06-19 08:08 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-06-12 21:43 - 2013-06-19 08:08 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-06-12 21:43 - 2013-06-19 08:07 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-06-12 17:51 - 2012-04-30 21:30 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-12 17:51 - 2012-04-30 21:30 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-12 12:44 - 2011-02-11 00:48 - 00000000 ____D C:\Windows\Panther 2013-06-12 09:49 - 2012-03-24 18:57 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log 2013-06-11 20:26 - 2009-07-14 07:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx 2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc 2013-06-08 16:08 - 2013-06-16 12:36 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-06-08 16:07 - 2013-06-16 12:36 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-06-08 16:06 - 2013-06-16 12:36 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-06-08 16:06 - 2013-06-16 12:36 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-06-08 16:06 - 2013-06-16 12:36 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-06-08 14:28 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-06-08 13:42 - 2013-06-16 12:36 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-06-08 13:40 - 2013-06-16 12:36 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-06-08 13:13 - 2013-06-16 12:36 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-06-07 23:02 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-06-07 09:58 - 2012-02-06 14:44 - 00000000 ____D C:\ProgramData\Sony Corporation ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 20:07 ==================== End Of Log ============================ 3 Anmerkungen noch: * Teilweise has Sophos beim Runterladen der Scanner auf den Desktop zunächst den Zugriff auf die Seite verweigert - dort sei Spyware. Die Meldung war: "Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe"" * Mittendrin, als ich so weit ich weiss auf keinen anderen Seiten als Trojanerbord online war, schlug Sophos Alarm und packte ein "NirCmd" in Quarantäne. Deklariert es als Adware oder PUA * Ebenso meldete Sophos (ich glaube ich las Nachrichten online) "Virus/spyware 'Mal/ExpJS-BE' has been detected at "ccgpqtrnqhjoid.servebbs.net/acjcjlgky" Kann es sein, dass Sophos etwas überreagiert? Wie sollte ich nach der Reinigung meinen PC am Besten warten? Vielen Dank schon mal im Voraus, beste Grüße, Piristibulus |
03.07.2013, 20:52 | #8 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Ja das sind alles Fehlmeldungen über unsere Tools. Die müssen ähnlich wie Malware arbeiten um sie entfernen zu können, daher die Erkennung Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 21:31 | #9 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Hallo Schrauber, vielen Dank. Das hat alles wunderbar gefunzt. Hier nur vorsorglich noch einmal das log von DelFix: Code:
ATTFilter # DelFix v10.3 - Logfile created 04/07/2013 at 18:28:59 # Updated 08/06/2013 by Xplode # Username : Daniel - SOFERMAHIR # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) ~ Activating UAC ... OK ~ Removing disinfection tools ... Deleted : C:\Qoobox Deleted : C:\JRT Deleted : C:\Combofix Deleted : C:\FRST Deleted : C:\AdwCleaner[R1].txt Deleted : C:\AdwCleaner[R2].txt Deleted : C:\AdwCleaner[R3].txt Deleted : C:\AdwCleaner[S1].txt Deleted : C:\AdwCleaner[S2].txt Deleted : C:\AdwCleaner[S3].txt Deleted : C:\ComboFix.txt Deleted : C:\Users\Daniel\Desktop\adwcleaner.exe Deleted : C:\Users\Daniel\Desktop\ComboFix.txt Deleted : C:\Users\Daniel\Desktop\Defogger.exe Deleted : C:\Users\Daniel\Desktop\defogger_disable.log Deleted : C:\Users\Daniel\Desktop\defogger_enable.log Deleted : C:\Users\Daniel\Desktop\esetsmartinstaller_enu.exe Deleted : C:\Users\Daniel\Desktop\FRST.txt Deleted : C:\Users\Daniel\Desktop\FRST64.exe Deleted : C:\Users\Daniel\Desktop\JRT.txt Deleted : C:\Users\Daniel\Desktop\SecurityCheck.exe Deleted : C:\Users\Daniel\Desktop\TFC.exe Deleted : HKLM\SOFTWARE\OldTimer Tools Deleted : HKLM\SOFTWARE\AdwCleaner Deleted : HKLM\SOFTWARE\Swearware ~ Creating registry backup ... OK ~ Cleaning system restore ... New restore point created ! ~ Resetting system settings ... OK ########## - EOF - ########## Ich habe jetzt nur noch ein paar Fragen: * Ist Sophos ein gutes Antivir-programm oder soll ich mich lieber nach einem anderen Virenscanner umsehen? * Firewall: Genügt die von Windows? *Windows Defender - laufen lassen oder abschalten? * Ich habe auch SpyBot Search & Destroy - soll ich das entfernen oder funktioniert das gut mit Malwarebytes zusammen? * Ich verwende ccleaner - soll ich es behalten oder durch TFC ersetzen? * TFC verwende ich als reguläres Programm genauso wie oben beschrieben? Vielen lieben Dank und beste Grüße, Pristibulus |
05.07.2013, 07:44 | #10 | ||
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im MemoryZitat:
Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 07:34 | #11 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Lieber Schrauber, vielen Dank. Ich war leider das Wochenende über mit einem Workshop beschäftigt und bin erst gestern dazu gekommen, die Ratschläge zu implementieren. Allerdings - und da hatte ich nur Thunderbird und einige Uniwebseiten sowie das Trojanerbord offen - meinte der PC auf einmal er müsse wegen eines Fehlers neustarten. Ich habe danach sofort Sophos laufen lassen, der hat nichts gefunden. Aber der Windows Action Center erzählte mir auf einmal er habe den "Win32/Small.CA" gefunden. Gesehen hab ich die Message erst am Nachmittag, nochmal Sophos laufen lassen. Kann es sein, dass das einfach ein Fehlalarm ist? Vielen Dank und liebe Grüße, Piristibulus |
09.07.2013, 08:18 | #12 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Zeig mal bitte das Log bzw die komplette Meldung.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 08:37 | #13 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Hallo, vielen Dank für die Hilfe. Die Meldung ist nur noch im Archiv des Action-Centers zugänglich: Code:
ATTFilter Remove the Win32/Small.CA virus from your PC This problem was caused by Win32/Small.CA, a known computer virus. Piristibulus |
09.07.2013, 08:38 | #14 |
/// the machine /// TB-Ausbilder | Sophosmeldung: Troj/ZbotMem-B im Memory Sehr aussagekräftig Lass Dein AV mal nen Vollscan machen, poste das Logfile.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 09:26 | #15 |
| Sophosmeldung: Troj/ZbotMem-B im Memory Alles klar. Hier ist das log von Sophos. Ich fürchte, evtl. auch nicht sehr aussagekräftig. Gefunden hat er wohl nichts: Code:
ATTFilter ****************** Sophos Anti-Virus Log - 09/07/2013 08:24:28 ************** 20130701 044536 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130701 044537 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197478 items. 20130701 044537 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130701 054528 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130701 054529 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197488 items. 20130701 054529 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130701 110323 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130701 110324 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197502 items. 20130701 110324 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130701 111337 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" belongs to virus/spyware 'Troj/EncProc-K'. 20130701 111337 On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" for user SoferMahir\Daniel 20130701 111348 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" belongs to virus/spyware 'Troj/EncProc-K'. 20130701 111353 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-1dfd901e-temp" has been cleaned up. 20130701 111353 Virus/spyware 'Troj/EncProc-K' has been removed. 20130701 120311 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130701 120312 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197518 items. 20130701 120312 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130701 204258 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130701 204259 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197533 items. 20130701 204259 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130702 043908 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130702 043909 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197556 items. 20130702 043909 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130702 084347 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130702 084348 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items. 20130702 084348 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130702 114717 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items. 20130702 114717 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130702 134021 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items. 20130702 134021 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130702 135745 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197562 items. 20130702 135746 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130702 141320 Scan 'Scan my computer' started. 20130702 141410 Virus/spyware 'Troj/ZbotMem-B' has been detected in "User Memory". 20130702 141410 'Troj/ZbotMem-B' must be cleaned up before scan can continue. 20130702 141410 Scan 'Scan my computer' aborted. 20130702 141410 Summary of results for scan 'Scan my computer': Items scanned: 2 Errors: 1 Items quarantined: 1 Items dealt with: 0 20130702 150319 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130702 150320 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197568 items. 20130702 150320 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130702 151532 Scan 'Scan my computer' started. 20130702 151624 Virus/spyware 'Troj/ZbotMem-B' has been detected in "User Memory". 20130702 151624 'Troj/ZbotMem-B' must be cleaned up before scan can continue. 20130702 151624 Scan 'Scan my computer' aborted. 20130702 151624 Summary of results for scan 'Scan my computer': Items scanned: 2 Errors: 1 Items quarantined: 1 Items dealt with: 0 20130702 154246 Blocked web request to "www.newzipopenerfun.com/gb/sag" (linked from "filepony.de/download-frst64/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 143200617. 20130702 154315 Blocked web request to "www.newzipopenerfun.com/gb/sab" (linked from "filepony.de/download-frst64/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 143200617. 20130702 170307 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130702 170307 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197600 items. 20130702 170307 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130702 173545 The automatic sending of file data for Sophos Live Protection is disabled. 20130702 173619 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130702 175417 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130702 175445 The automatic sending of file data for Sophos Live Protection is enabled. 20130702 192311 File "C:\Windows\NIRCMD.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130702 192311 On-access scanner has denied access to location "C:\Windows\NIRCMD.exe" for user NT AUTHORITY\SYSTEM 20130702 200306 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130702 200306 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197613 items. 20130702 200306 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130703 034945 Access to location "ccgpqtrnqhjoid.servebbs.net/acjcjlgky" was blocked for user SoferMahir\Daniel 20130703 034945 Virus/spyware 'Mal/ExpJS-BE' has been detected at "ccgpqtrnqhjoid.servebbs.net/acjcjlgky" 20130703 075650 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130703 075651 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197634 items. 20130703 075651 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130703 080653 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130703 080722 The automatic sending of file data for Sophos Live Protection is disabled. 20130703 084151 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130703 084216 The automatic sending of file data for Sophos Live Protection is enabled. 20130703 084400 Blocked web request to "general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner" (linked from "filepony.de/download-adwcleaner/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/Generic-L' has been found at this website, reference ID 112325898. 20130703 084616 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130703 084629 The automatic sending of file data for Sophos Live Protection is disabled. 20130703 085038 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197634 items. 20130703 085039 User (NT AUTHORITY\LOCAL SERVICE) has stopped on-access scanning for this machine. 20130703 085747 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130703 085804 The automatic sending of file data for Sophos Live Protection is enabled. 20130703 090233 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130703 090246 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130703 090425 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090425 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090439 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090439 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090505 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090505 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090517 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090517 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090551 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090551 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090616 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090616 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090631 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090631 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090657 Access to location "thisisudax.org/downloads/JRT.exe" was blocked for user SoferMahir\Daniel 20130703 090657 Virus/spyware 'Mal/Generic-S' has been detected at "thisisudax.org/downloads/JRT.exe" 20130703 090837 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130703 091024 The automatic sending of file data for Sophos Live Protection is disabled. 20130703 092305 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130703 092741 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197634 items. 20130703 092741 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130703 092935 The automatic sending of file data for Sophos Live Protection is enabled. 20130703 093403 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130703 093403 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197644 items. 20130703 093403 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130703 093626 The automatic sending of file data for Sophos Live Protection is disabled. 20130703 093656 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130703 124007 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197662 items. 20130703 164008 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197672 items. 20130703 190147 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130703 190210 The automatic sending of file data for Sophos Live Protection is enabled. 20130703 191027 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130703 191044 The automatic sending of file data for Sophos Live Protection is disabled. 20130703 192100 The automatic sending of file data for Sophos Live Protection is enabled. 20130703 192112 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130703 194014 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130703 194015 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197685 items. 20130703 194015 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130704 013705 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130704 013705 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197697 items. 20130704 013705 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130704 014419 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 014431 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 014445 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 014509 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 014518 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 015257 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 015316 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 015510 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 015527 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 044431 File "C:\Windows\NIRCMD.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 044431 On-access scanner has denied access to location "C:\Windows\NIRCMD.exe" for user NT AUTHORITY\SYSTEM 20130704 045753 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197697 items. 20130704 045754 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 070650 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197697 items. 20130704 070650 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 071245 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130704 071246 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items. 20130704 071246 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130704 084659 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items. 20130704 084659 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 101707 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items. 20130704 101708 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 120010 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197703 items. 20130704 120011 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 120604 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130704 120605 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197714 items. 20130704 120605 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130704 123314 File "C:\Users\Daniel\Desktop\JRT.exe" belongs to virus/spyware 'Mal/Generic-S'. 20130704 123314 On-access scanner has denied access to location "C:\Users\Daniel\Desktop\JRT.exe" for user SoferMahir\Daniel 20130704 123323 File "C:\Users\Daniel\Desktop\JRT.exe" belongs to virus/spyware 'Mal/Generic-S'. 20130704 123323 Registry value "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoRestartShell" belongs to virus/spyware 'Mal/Generic-S'. 20130704 123323 Registry value "HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoRestartShell" has been cleaned up. 20130704 123325 File "C:\Users\Daniel\Desktop\JRT.exe" has been cleaned up. 20130704 123325 Virus/spyware 'Mal/Generic-S' has been removed. 20130704 140822 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 140857 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 140944 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 140958 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 141047 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130704 141054 Blocked web request to "oldtimer.geekstogo.com/TFC.exe" (linked from "filepony.de/download-tfc/get-mirror-server.html") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 56206009. 20130704 141107 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130704 141311 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197714 items. 20130704 141311 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 141342 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" belongs to virus/spyware 'Troj/Java-ON'. 20130704 141342 On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" for user SoferMahir\Daniel 20130704 141350 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" belongs to virus/spyware 'Troj/Java-ON'. 20130704 141350 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" belongs to virus/spyware 'Mal/ExpJS-N'. 20130704 141350 On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" for user SoferMahir\Daniel 20130704 141352 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\766de788-401bb4c0" has been cleaned up. 20130704 141352 Virus/spyware 'Troj/Java-ON' has been removed. 20130704 141352 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" belongs to virus/spyware 'Mal/ExpJS-N'. 20130704 141352 On-access scanner has denied access to location "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" for user SoferMahir\Daniel 20130704 141355 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" belongs to virus/spyware 'Mal/ExpJS-N'. 20130704 141357 File "C:\Users\Daniel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\38db0252-6a676761" has been cleaned up. 20130704 141357 Virus/spyware 'Mal/ExpJS-N' has been removed. 20130704 141404 Process "C:\Users\Daniel\Desktop\TFC.exe" exhibiting suspicious behavior pattern 'HIPS/RegMod-009'. No action taken. If you are unsure whether the application can be authorized, please send a sample to Sophos. 20130704 141404 Process "C:\Users\Daniel\Desktop\TFC.exe" exhibiting suspicious behavior pattern 'HIPS/RegMod-009'. No action taken. If you are unsure whether the application can be authorized, please send a sample to Sophos. 20130704 162058 File "C:\32788R22FWJFW\NirCmd.3XE" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162059 File "C:\32788R22FWJFW\NirCmdC.3XE" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162100 File "C:\32788R22FWJFW\firefox.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162101 File "C:\32788R22FWJFW\iexplore.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162101 File "C:\32788R22FWJFW\nir.pif" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162116 File "C:\32788R22FWJFW\iexplore.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162116 On-access scanner has denied access to location "C:\32788R22FWJFW\iexplore.exe" for user SoferMahir\Daniel 20130704 162259 User (SoferMahir\Daniel) has stopped on-access scanning for this machine. 20130704 162306 The automatic sending of file data for Sophos Live Protection is disabled. 20130704 162535 User (SoferMahir\Daniel) has started on-access scanning for this machine. 20130704 162547 The automatic sending of file data for Sophos Live Protection is enabled. 20130704 162901 File "C:\ComboFix\NircmdB.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 162901 On-access scanner has denied access to location "C:\ComboFix\NircmdB.exe" for user SoferMahir\Daniel 20130704 162926 Process "C:\Users\Daniel\Desktop\delfix.exe" exhibiting suspicious behavior pattern 'HIPS/RegMod-009'. No action taken. If you are unsure whether the application can be authorized, please send a sample to Sophos. 20130704 163647 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197714 items. 20130704 163647 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 164244 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130704 164245 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197754 items. 20130704 164245 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130704 164347 Scan 'Scan my computer' started. 20130704 165153 File "C:\ComboFix\NircmdB.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 172431 Adware or PUA 'NirCmd' has been detected. 20130704 172431 Scan 'Scan my computer' completed. 20130704 172431 Summary of results for scan 'Scan my computer': Items scanned: 155652 Errors: 0 Items quarantined: 1 Items dealt with: 0 20130704 174841 File "C:\ComboFix\NircmdB.exe" belongs to adware or PUA 'NirCmd' (of type 5). 20130704 174841 Scanning "C:\Windows\NIRCMD.exe" returned SAV Interface error 0xa0040210: The file could not be accessed. 20130704 174841 Scanning "C:\32788R22FWJFW\firefox.exe" returned SAV Interface error 0xa0040210: The file could not be accessed. 20130704 174841 Scanning "C:\32788R22FWJFW\iexplore.exe" returned SAV Interface error 0xa0040210: The file could not be accessed. 20130704 174841 Scanning "C:\32788R22FWJFW\nir.pif" returned SAV Interface error 0xa0040210: The file could not be accessed. 20130704 174841 File "C:\ComboFix\NircmdB.exe" has been cleaned up. 20130704 174841 Adware or PUA 'NirCmd' has been removed. 20130704 174954 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197754 items. 20130704 174954 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 194627 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197754 items. 20130704 194627 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 195236 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130704 195237 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items. 20130704 195237 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130704 201623 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items. 20130704 201623 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 210029 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items. 20130704 210029 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 211326 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items. 20130704 211326 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 212137 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197764 items. 20130704 212137 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130704 222747 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130704 222747 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197767 items. 20130704 222747 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130705 085837 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130705 085838 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197774 items. 20130705 085838 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130705 094559 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197774 items. 20130705 094600 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130705 095248 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130705 095250 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197788 items. 20130705 095250 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 102043 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130705 104244 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197788 items. 20130705 104244 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130705 175331 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130705 175332 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197819 items. 20130705 175332 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130706 124553 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130706 124554 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197849 items. 20130706 124554 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130706 193613 Blocked web request to "wikimannia.org/Michael_Blume" (linked from "www.google.de/url") for user SoferMahir\Daniel. 'Mal/HTMLGen-A' has been found at this website, reference ID 32839688. 20130706 203533 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130706 203534 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197860 items. 20130706 203534 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130707 073302 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130707 073309 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197873 items. 20130707 073309 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130707 075252 Scanning "hxxp://aihdownload.adobe.com/bin/live/install_reader11_uk_mssd_aaa_aih.exe" returned SAV Interface error 0xa0040212: The file is encrypted. 20130708 082421 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197873 items. 20130708 082421 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130708 083042 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130708 083043 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197914 items. 20130708 083043 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130708 101902 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197914 items. 20130708 101902 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130708 102208 Scan 'Scan my computer' started. 20130708 111607 Scan 'Scan my computer' completed. 20130708 111607 Summary of results for scan 'Scan my computer': Items scanned: 166507 Errors: 0 Items quarantined: 0 Items dealt with: 0 20130708 112451 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130708 112452 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197922 items. 20130708 112452 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130708 141318 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197922 items. 20130708 141318 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130708 141748 Scan 'Scan my computer' started. 20130708 151435 Scan 'Scan my computer' completed. 20130708 151435 Summary of results for scan 'Scan my computer': Items scanned: 167777 Errors: 0 Items quarantined: 0 Items dealt with: 0 20130708 172340 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197922 items. 20130708 172340 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130708 173020 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130708 173020 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197943 items. 20130708 173021 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130708 201846 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130708 201846 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197960 items. 20130708 201846 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130709 042614 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130709 042614 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197980 items. 20130709 042614 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130709 062410 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197980 items. 20130709 062410 User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine. 20130709 063035 User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine. 20130709 063036 Using detection data version 4.90G (detection engine 3.43.0). This version can detect 5197992 items. 20130709 063036 User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine. 20130709 074008 Scan 'Scan my computer' started. 20130709 082128 Scan 'Scan my computer' completed. 20130709 082128 Summary of results for scan 'Scan my computer': Items scanned: 162010 Errors: 0 Items quarantined: 0 Items dealt with: 0 (460 items) Piristibulus |
Themen zu Sophosmeldung: Troj/ZbotMem-B im Memory |
administrator, anleitung, anzeige, anzeigen, befall, beste grüße, bestimmte, cmd, defogger, desktop, detected, doppelt, entfernen, firefox, guten, log, meldung, problem, programme, scan, seite, sophos, strg, suche, troj/zbotmem-b, webseite, win, zeichen |