|
Log-Analyse und Auswertung: Auf jeder Website überall WerbungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
15.07.2013, 07:09 | #1 |
| Auf jeder Website überall Werbung Hallo,ich bin sehr froh,dass ich mich an euch hier wenden kann! Ich habe seit einigen Tagen massenweise Werbung auf den Internetseiten(auch Google ect.). Dadurch hat sich mein Laptop auch sehr verlangsamt-was kann ich tun? Schöne Grüße PaulinaK |
15.07.2013, 07:10 | #2 |
/// the machine /// TB-Ausbilder | Auf jeder Website überall Werbung hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
15.07.2013, 07:13 | #3 |
| Auf jeder Website überall Werbung Hier FRST:
__________________Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-07-2013 Ran by Paulina (administrator) on 15-07-2013 07:56:14 Running from C:\Users\Paulina\Downloads Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Comodo Security Solutions Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\windows\system32\atiesrxx.exe (AMD) C:\windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\windows\system32\atibtmon.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe () C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (Microsoft Corporation) C:\windows\system32\schtasks.exe () C:\Program Files\Comodo\Dragon\dragon_updater.exe (Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe () C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (CyberLink Corp.) C:\Program Files\Lenovo\YouCam\YouCamTray.exe (Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe (Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe (Iminent) C:\Program Files\Iminent\IMBooster\IMBooster.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Bandoo Media Inc) C:\Program Files\Search Results Toolbar\Datamngr\datamngrUI.exe (Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (COMODO) C:\Program Files\Comodo\COMODO Internet Security\CisTray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit_manager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\windows\System32\IgrsSvcs.exe (COMODO) C:\Program Files\Comodo\COMODO Internet Security\cis.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe (OldTimer Tools) C:\Users\Paulina\Downloads\OTL.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe Hier addition: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-07-2013 Ran by Paulina at 2013-07-15 07:58:13 Running from C:\Users\Paulina\Downloads Boot Mode: Normal ========================================================== Adobe AIR (Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader 9.0.1 (Version: 9.0.1) AMD USB Filter Driver (Version: 1.0.15.94) Ask Toolbar (Version: 1.15.4.0) Ask Toolbar Updater (HKCU Version: 1.2.2.23821) ATI Catalyst Install Manager (Version: 3.0.765.0) Audacity 1.3.13 (Unicode) Avira Free Antivirus (Version: 13.0.0.3737) Bing Bar (Version: 7.1.391.0) Broadcom 802.11 Wireless Driver (Version: 1.0.0.0) BrowserDefender Catalyst Control Center Core Implementation (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Full Existing (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Full New (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Light (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Previews Common (Version: 2010.0302.2233.40412) Catalyst Control Center InstallProxy (Version: 2010.0302.2233.40412) Catalyst Control Center Localization All (Version: 2010.0302.2233.40412) CCC Help Chinese Standard (Version: 2010.0302.2232.40412) CCC Help Chinese Traditional (Version: 2010.0302.2232.40412) CCC Help Czech (Version: 2010.0302.2232.40412) CCC Help Danish (Version: 2010.0302.2232.40412) CCC Help Dutch (Version: 2010.0302.2232.40412) CCC Help English (Version: 2010.0302.2232.40412) CCC Help Finnish (Version: 2010.0302.2232.40412) CCC Help French (Version: 2010.0302.2232.40412) CCC Help German (Version: 2010.0302.2232.40412) CCC Help Greek (Version: 2010.0302.2232.40412) CCC Help Hungarian (Version: 2010.0302.2232.40412) CCC Help Italian (Version: 2010.0302.2232.40412) CCC Help Japanese (Version: 2010.0302.2232.40412) CCC Help Korean (Version: 2010.0302.2232.40412) CCC Help Norwegian (Version: 2010.0302.2232.40412) CCC Help Polish (Version: 2010.0302.2232.40412) CCC Help Portuguese (Version: 2010.0302.2232.40412) CCC Help Russian (Version: 2010.0302.2232.40412) CCC Help Spanish (Version: 2010.0302.2232.40412) CCC Help Swedish (Version: 2010.0302.2232.40412) CCC Help Thai (Version: 2010.0302.2232.40412) CCC Help Turkish (Version: 2010.0302.2232.40412) ccc-core-static (Version: 2010.0302.2233.40412) ccc-utility (Version: 2010.0302.2233.40412) CCleaner (Version: 3.02) Comodo Dragon (Version: 27.0.4.0) COMODO Internet Security Premium (Version: 6.2.20728.2847) Conexant HD Audio (Version: 4.111.0.62) CyberLink YouCam (Version: 3.0.2421a) DC-Bass Source 1.3.0 DealPly (remove only) (Version: 4.8.6.1) so,danke! |
15.07.2013, 08:14 | #4 |
/// the machine /// TB-Ausbilder | Auf jeder Website überall Werbung Logs sind nicht komplett, und bitte in Codetags posten. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.07.2013, 08:38 | #5 |
| Auf jeder Website überall Werbung Ok hier der nächste Versuch: FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-07-2013 Ran by Paulina (administrator) on 15-07-2013 09:32:33 Running from C:\Users\Paulina\Downloads Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Comodo Security Solutions Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\windows\system32\atiesrxx.exe (AMD) C:\windows\system32\atieclxx.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe () C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe () C:\Program Files\Comodo\Dragon\dragon_updater.exe (Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe () C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe (CyberLink Corp.) C:\Program Files\Lenovo\YouCam\YouCamTray.exe (Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe (Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe (Iminent) C:\Program Files\Iminent\IMBooster\IMBooster.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Ask) C:\Program Files\Ask.com\Updater\Updater.exe (Bandoo Media Inc) C:\Program Files\Search Results Toolbar\Datamngr\datamngrUI.exe (Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe (COMODO) C:\Program Files\Comodo\COMODO Internet Security\cistray.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit_manager.exe (Comodo Security Solutions, Inc.) C:\Program Files\Comodo\GeekBuddy\unit.exe (COMODO) C:\Program Files\Comodo\COMODO Internet Security\cis.exe (Microsoft Corporation) C:\windows\System32\IgrsSvcs.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Farbar) C:\Users\Paulina\Downloads\FRST (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [496184 2010-03-10] (Conexant Systems, Inc.) HKLM\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35184 2008-12-03] (Adobe Systems Incorporated) HKLM\...\Run: [VeriFaceManager] - C:\Program Files\Lenovo\VeriFace\PManage.exe [x] HKLM\...\Run: [UCam_Menu] - "C:\Program Files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" [222504 2009-05-20] (CyberLink Corp.) HKLM\...\Run: [YouCam Mirror Tray icon] - "C:\Program Files\Lenovo\YouCam\YouCamTray.exe" /s [167008 2009-12-22] (CyberLink Corp.) HKLM\...\Run: [UpdateP2GShortCut] - "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" [218408 2008-12-04] (CyberLink Corp.) HKLM\...\Run: [EnergyUtility] - C:\Program Files\Lenovo\Energy Management\utility.exe [4114368 2009-12-17] (Lenovo(beijing) Limited) HKLM\...\Run: [Energy Management] - C:\Program Files\Lenovo\Energy Management\Energy Management.exe [6223808 2009-12-17] (Lenovo (Beijing) Limited) HKLM\...\Run: [IMBooster] - C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup [1324008 2011-03-30] (Iminent) HKLM\...\Run: [NPSStartup] - [x] HKLM\...\Run: [avgnt] - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-07-01] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.) HKLM\...\Run: [] - [x] HKLM\...\Run: [ApnUpdater] - "C:\Program Files\Ask.com\Updater\Updater.exe" [1564872 2012-06-06] (Ask) HKLM\...\Run: [DATAMNGR] - C:\PROGRA~1\SEARCH~1\Datamngr\DATAMN~1.EXE [1681472 2012-11-15] (Bandoo Media Inc) HKLM\...\Run: [DivXMediaServer] - C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [x] HKLM\...\Run: [gbrspcontrol] - "C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave [1851088 2013-04-17] (Comodo Security Solutions, Inc.) HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1464536 2013-07-08] (COMODO) HKCU\...\Run: [Google Update] - "C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe" /c [116648 2012-10-30] (Google Inc.) HKCU\...\Run: [GoogleChromeAutoLaunch_9EE49418645B8CE65A6F7F02D3D23CBF] - "C:\Users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window [846288 2013-07-12] (Google Inc.) MountPoints2: {c202b000-e4ac-11e2-a4d3-88ae1d35ec03} - E:\Startme.exe MountPoints2: {c340d18c-cbe1-11e0-adfe-88ae1d35ec03} - E:\NokiaPCIA_Autorun.exe HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [ 2009-07-14] (Microsoft Corporation) HKU\Gast\...\RunOnce: [FlashPlayerUpdate] - C:\windows\system32\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex [x] Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Start Menu\Programs\Startup\Start GeekBuddy.lnk ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\Comodo\GeekBuddy\launcher.exe (Comodo Security Solutions Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com?fr=fp-comodo HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) URLSearchHook: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVD0.dll (Conduit Ltd.) HKLM SearchScopes: DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=394&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=4423383531334391&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=394&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=4423383531334391&q={searchTerms} SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 HKCU SearchScopes: DefaultScope {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=2E6A88AE1D35EC03&affID=119357&tt=110713_91114&tsp=4941 SearchScopes: HKCU - {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=394&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=4423383531334391&q={searchTerms} SearchScopes: HKCU - {A92C7E1E-FA1D-4804-AD52-E5A5FA5F85A6} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=OSJ000YYDE&apn_uid=B5E1685F-9820-4B49-8DB5-42D07B39FED7&apn_sauid=B202C7E1-7D53-496E-A43B-6554219CFC1E SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 BHO: DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVD0.dll (Conduit Ltd.) BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO: Plus-HD-2.3 - {11111111-1111-1111-1111-110311341126} - C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-bho.dll (Plus HD) BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) BHO: DataMngr - {C1ED9DA0-AFD0-4b90-AC6A-D3874F591014} - C:\PROGRA~1\SEARCH~1\Datamngr\BROWSE~1.DLL (Bandoo Media Inc) BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: DealPly - {EF7BD87A-8024-11E2-F316-F3E56188709B} - C:\Program Files\DealPly\DealPlyIE.dll No File BHO: Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (APN LLC) Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll" No File Toolbar: HKLM - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVD0.dll (Conduit Ltd.) Toolbar: HKLM - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM - Search-Results Toolbar - {f34c9277-6577-4dff-b2d7-7d58092f272f} - C:\PROGRA~1\SEARCH~1\Datamngr\SRTOOL~1\searchresultsDx.dll (APN LLC) Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -DVDVideoSoftTB DE Toolbar - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - C:\Program Files\DVDVideoSoftTB_DE\prxtbDVD0.dll (Conduit Ltd.) Toolbar: HKCU -Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask) DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR HomePage: hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=2E6A88AE1D35EC03&affID=119357&tt=110713_91114&tsp=4941 CHR RestoreOnStartup: "hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=2E6A88AE1D35EC03&affID=119357&tt=110713_91114&tsp=4941" CHR DefaultSearchURL: (Yahoo! Search) - hxxp://de.search.yahoo.com/search?fr=chrc-comodo&type=GC&p={searchTerms} CHR DefaultSuggestURL: (Yahoo! Search) - "suggest_url": "" CHR Plugin: (Shockwave Flash) - C:\Users\Paulina\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Paulina\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Paulina\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.370.6) - C:\windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.) CHR Plugin: (Google Update) - C:\Users\Paulina\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File CHR Extension: (DVDVideoSoftTB DE) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm\10.16.4.512_0 CHR Extension: (YouTube) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Delta Toolbar) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.4_0 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0 CHR Extension: (Plus-HD-2.3) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoidjpeklpjhlhabhcomekbkclkbec\1.23.17_0 CHR Extension: (Gmail) - C:\Users\Paulina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-01] (Avira Operations GmbH & Co. KG) R2 BrowserDefendert; C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2827728 2013-05-23] () R2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70344 2013-04-17] (Comodo Security Solutions Inc.) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4801304 2013-07-08] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [127192 2013-06-18] (COMODO) R2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2094216 2013-05-29] () R2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [1851088 2013-04-17] (Comodo Security Solutions, Inc.) S3 IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited) S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited) S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S3 PS_MDP; C:\Program Files\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited) R2 ReadyComm.DirectRouter; C:\Program Files\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited) ==================== Drivers (Whitelisted) ==================== R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [21256 2009-09-03] (Lenovo Corporation) R3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5340160 2010-03-03] (ATI Technologies Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-03-31] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-03-31] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-31] (Avira Operations GmbH & Co. KG) S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [63240 2009-07-28] (Lenovo) R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [35064 2013-05-07] (Windows (R) Win 7 DDK provider) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2013-06-18] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [582936 2013-07-08] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [43728 2013-06-18] (COMODO) S3 FsUsbExDisk; C:\windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] () R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [85464 2013-06-18] (COMODO) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2009-09-19] (MCCI) S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2009-09-19] (MCCI Corporation) S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2009-09-19] (MCCI Corporation) R3 usbsmi; C:\Windows\System32\DRIVERS\SMIksdrv.sys [171776 2009-10-16] (SMI) R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider) S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [x] U3 BcmSqlStartupSvc; U2 IAStorDataMgrSvc; U2 IviRegMgr; U2 RichVideo; U3 SQLWriter; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-15 09:26 - 2013-07-15 09:26 - 00001790 _____ C:\Users\Paulina\Downloads\redist.txt 2013-07-15 09:25 - 2013-07-15 09:25 - 01218214 _____ (Farbar) C:\Users\Paulina\Downloads\FRST (1).exe 2013-07-15 09:02 - 2013-07-15 09:02 - 00726464 _____ (Enigma Software Group USA, LLC.) C:\Users\Paulina\Downloads\SpyHunter-Installer (1).exe 2013-07-15 09:01 - 2013-07-15 09:01 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-15 08:59 - 2013-07-15 09:00 - 00726464 _____ (Enigma Software Group USA, LLC.) C:\Users\Paulina\Downloads\SpyHunter-Installer.exe 2013-07-15 08:33 - 2013-07-15 09:14 - 00000168 _____ C:\windows\setupact.log 2013-07-15 08:33 - 2013-07-15 08:33 - 00000000 _____ C:\windows\setuperr.log 2013-07-15 08:08 - 2013-07-15 08:08 - 00062322 _____ C:\Users\Paulina\Downloads\Extras.Txt 2013-07-15 08:04 - 2013-07-15 08:04 - 00101662 _____ C:\Users\Paulina\Downloads\OTL.Txt 2013-07-15 07:58 - 2013-07-15 08:00 - 00026457 _____ C:\Users\Paulina\Downloads\Addition.txt 2013-07-15 07:56 - 2013-07-15 07:56 - 00000000 ____D C:\FRST 2013-07-15 07:55 - 2013-07-15 07:55 - 01218214 _____ (Farbar) C:\Users\Paulina\Downloads\FRST.exe 2013-07-15 07:42 - 2013-07-15 07:42 - 00602112 _____ (OldTimer Tools) C:\Users\Paulina\Downloads\OTL.exe 2013-07-14 21:34 - 2013-07-15 09:24 - 00496641 _____ C:\windows\system32\Drivers\sfi.dat 2013-07-14 21:34 - 2013-07-15 08:31 - 00001985 _____ C:\Users\Public\Desktop\COMODO Internet Security.lnk 2013-07-14 21:34 - 2013-07-14 21:34 - 00001857 _____ C:\Users\Public\Desktop\Virtual Comodo Dragon.lnk 2013-07-14 21:34 - 2013-07-14 21:34 - 00000593 _____ C:\Users\Public\Desktop\Gemeinsamer Bereich.lnk 2013-07-14 21:32 - 2013-07-14 21:34 - 00000000 ___SD C:\ProgramData\Shared Space 2013-07-14 21:31 - 2013-07-14 21:34 - 00000000 ____D C:\ProgramData\COMODO 2013-07-14 21:31 - 2013-07-14 21:31 - 00002017 _____ C:\Users\Public\Desktop\AntiError.lnk 2013-07-14 21:31 - 2013-07-14 21:31 - 00002013 _____ C:\Users\Public\Desktop\GeekBuddy.lnk 2013-07-14 21:31 - 2013-07-14 21:31 - 00000000 ____D C:\Program Files\Common Files\COMODO 2013-07-14 21:30 - 2013-07-14 21:32 - 00000000 ____D C:\Program Files\Comodo 2013-07-14 21:30 - 2013-07-14 21:30 - 00047368 _____ (COMODO CA Limited) C:\windows\system32\certsentry.dll 2013-07-14 21:30 - 2013-07-14 21:30 - 00001078 _____ C:\Users\Public\Desktop\Comodo Dragon.lnk 2013-07-14 21:30 - 2013-07-14 21:30 - 00000000 ____D C:\Users\Paulina\AppData\Local\Comodo 2013-07-14 21:30 - 2013-07-14 21:30 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-14 21:25 - 2013-07-14 21:27 - 149029376 _____ (COMODO) C:\Users\Paulina\Downloads\cispremium_installer_6.2.exe 2013-07-12 18:13 - 2013-07-14 11:52 - 00000005 _____ C:\Users\Paulina\AppData\Roaming\WBPU-TTL.DAT 2013-07-12 17:17 - 2013-07-12 17:17 - 00000000 ____D C:\Users\Paulina\Qtrax 2013-07-12 17:16 - 2013-07-13 08:35 - 00000000 ____D C:\Program Files\DivX 2013-07-12 17:16 - 2013-07-12 17:16 - 00000000 ____D C:\Program Files\Xvid 2013-07-12 17:16 - 2013-07-12 17:16 - 00000000 ____D C:\Program Files\ffdshow 2013-07-12 17:16 - 2012-02-26 16:47 - 00079360 _____ C:\windows\system32\ff_vfw.dll 2013-07-12 17:16 - 2011-05-30 15:42 - 00240640 _____ C:\windows\system32\xvidvfw.dll 2013-07-12 17:16 - 2011-05-23 11:52 - 00153088 _____ C:\windows\system32\xvid.ax 2013-07-12 17:16 - 2011-05-23 09:46 - 00645632 _____ C:\windows\system32\xvidcore.dll 2013-07-12 17:15 - 2013-07-15 09:16 - 00001186 _____ C:\windows\Tasks\Plus-HD-2.3-updater.job 2013-07-12 17:15 - 2013-07-13 08:35 - 00000000 ____D C:\ProgramData\DivX 2013-07-12 17:15 - 2013-07-12 17:15 - 00715038 _____ C:\windows\unins000.exe 2013-07-12 17:15 - 2013-07-12 17:15 - 00001788 _____ C:\windows\unins000.dat 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\LavFilters 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\CDXReader 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\OpenSource Flash Video Splitter 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\Lame For Audacity 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\Haali 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\DSP-worx 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\DirectVobSub 2013-07-12 17:15 - 2012-01-09 20:45 - 00178688 _____ C:\windows\system32\unrar.dll 2013-07-12 17:15 - 2011-12-07 19:32 - 00216064 _____ ( ) C:\windows\system32\lagarith.dll 2013-07-12 17:14 - 2013-07-15 09:16 - 00001190 _____ C:\windows\Tasks\Plus-HD-2.3-codedownloader.job 2013-07-12 17:14 - 2013-07-15 09:16 - 00001090 _____ C:\windows\Tasks\Plus-HD-2.3-enabler.job 2013-07-12 17:14 - 2013-07-12 17:14 - 00000000 ____D C:\windows\system32\searchplugins 2013-07-12 17:14 - 2013-07-12 17:14 - 00000000 ____D C:\windows\system32\Extensions 2013-07-12 17:14 - 2013-07-12 17:14 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender 2013-07-12 17:13 - 2013-07-15 09:16 - 00001886 _____ C:\windows\Tasks\Plus-HD-2.3-chromeinstaller.job 2013-07-12 17:13 - 2013-07-15 09:13 - 00000294 _____ C:\windows\Tasks\DSite.job 2013-07-12 17:13 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\Plus-HD-2.3 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\DSite 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Delta 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\DealPly 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Babylon 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\BabSolution 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\ProgramData\BrowserDefender 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\ProgramData\Babylon 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Program Files\Delta 2013-07-09 21:11 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-07-09 21:11 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-07-09 21:11 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-07-09 21:11 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-07-09 21:11 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-07-09 21:11 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-07-09 21:11 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-07-09 21:11 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-07-09 21:11 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-07-09 21:11 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-07-09 21:11 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-07-09 21:11 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-07-09 21:11 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-07-09 21:11 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-07-09 21:11 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-07-09 21:11 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-07-09 20:37 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-07-09 20:37 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2013-07-09 20:37 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2013-07-09 20:37 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2013-07-03 17:39 - 2013-07-03 17:39 - 00000000 ____D C:\Users\Paulina\Desktop\KEVIN 2013-07-01 10:44 - 2013-07-01 10:49 - 119585424 _____ C:\Users\Paulina\Downloads\Fler - Hinter Blauen Augen (Premium Edition).zip 2013-06-21 16:05 - 2013-06-21 16:05 - 01441280 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-06-21 16:05 - 2013-06-21 16:05 - 01400416 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-06-21 16:05 - 2013-06-21 16:05 - 00745472 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00719360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00629248 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00523264 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00361984 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-06-21 16:05 - 2013-06-21 16:05 - 00357888 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00242200 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00232960 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00204800 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00158720 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00138752 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00137216 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00125440 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00117248 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00073728 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-06-21 16:05 - 2013-06-21 16:05 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-06-18 16:16 - 2013-07-08 22:59 - 00582936 _____ (COMODO) C:\windows\system32\Drivers\cmdguard.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00085464 _____ (COMODO) C:\windows\system32\Drivers\inspect.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00043728 _____ (COMODO) C:\windows\system32\Drivers\cmdhlp.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00020072 _____ (COMODO) C:\windows\system32\Drivers\cmderd.sys 2013-06-18 16:15 - 2013-06-18 16:15 - 00348584 _____ (COMODO) C:\windows\system32\guard32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00278232 _____ (COMODO) C:\windows\system32\cmdvrt32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00040664 _____ (COMODO) C:\windows\system32\cmdkbd32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00035488 _____ (COMODO) C:\windows\system32\cmdcsr.dll ==================== One Month Modified Files and Folders ======= 2013-07-15 09:27 - 2012-10-30 22:56 - 00001128 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001UA.job 2013-07-15 09:27 - 2012-10-30 22:56 - 00001076 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001Core.job 2013-07-15 09:26 - 2013-07-15 09:26 - 00001790 _____ C:\Users\Paulina\Downloads\redist.txt 2013-07-15 09:25 - 2013-07-15 09:25 - 01218214 _____ (Farbar) C:\Users\Paulina\Downloads\FRST (1).exe 2013-07-15 09:24 - 2013-07-14 21:34 - 00496641 _____ C:\windows\system32\Drivers\sfi.dat 2013-07-15 09:23 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-15 09:23 - 2009-07-14 06:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-15 09:21 - 2010-06-26 01:32 - 01608924 _____ C:\windows\WindowsUpdate.log 2013-07-15 09:16 - 2013-07-12 17:15 - 00001186 _____ C:\windows\Tasks\Plus-HD-2.3-updater.job 2013-07-15 09:16 - 2013-07-12 17:14 - 00001190 _____ C:\windows\Tasks\Plus-HD-2.3-codedownloader.job 2013-07-15 09:16 - 2013-07-12 17:14 - 00001090 _____ C:\windows\Tasks\Plus-HD-2.3-enabler.job 2013-07-15 09:16 - 2013-07-12 17:13 - 00001886 _____ C:\windows\Tasks\Plus-HD-2.3-chromeinstaller.job 2013-07-15 09:14 - 2013-07-15 08:33 - 00000168 _____ C:\windows\setupact.log 2013-07-15 09:14 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-07-15 09:13 - 2013-07-12 17:13 - 00000294 _____ C:\windows\Tasks\DSite.job 2013-07-15 09:02 - 2013-07-15 09:02 - 00726464 _____ (Enigma Software Group USA, LLC.) C:\Users\Paulina\Downloads\SpyHunter-Installer (1).exe 2013-07-15 09:01 - 2013-07-15 09:01 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-15 09:00 - 2013-07-15 08:59 - 00726464 _____ (Enigma Software Group USA, LLC.) C:\Users\Paulina\Downloads\SpyHunter-Installer.exe 2013-07-15 08:50 - 2012-04-29 11:07 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-07-15 08:33 - 2013-07-15 08:33 - 00000000 _____ C:\windows\setuperr.log 2013-07-15 08:31 - 2013-07-14 21:34 - 00001985 _____ C:\Users\Public\Desktop\COMODO Internet Security.lnk 2013-07-15 08:08 - 2013-07-15 08:08 - 00062322 _____ C:\Users\Paulina\Downloads\Extras.Txt 2013-07-15 08:04 - 2013-07-15 08:04 - 00101662 _____ C:\Users\Paulina\Downloads\OTL.Txt 2013-07-15 08:00 - 2013-07-15 07:58 - 00026457 _____ C:\Users\Paulina\Downloads\Addition.txt 2013-07-15 07:56 - 2013-07-15 07:56 - 00000000 ____D C:\FRST 2013-07-15 07:55 - 2013-07-15 07:55 - 01218214 _____ (Farbar) C:\Users\Paulina\Downloads\FRST.exe 2013-07-15 07:42 - 2013-07-15 07:42 - 00602112 _____ (OldTimer Tools) C:\Users\Paulina\Downloads\OTL.exe 2013-07-14 21:34 - 2013-07-14 21:34 - 00001857 _____ C:\Users\Public\Desktop\Virtual Comodo Dragon.lnk 2013-07-14 21:34 - 2013-07-14 21:34 - 00000593 _____ C:\Users\Public\Desktop\Gemeinsamer Bereich.lnk 2013-07-14 21:34 - 2013-07-14 21:32 - 00000000 ___SD C:\ProgramData\Shared Space 2013-07-14 21:34 - 2013-07-14 21:31 - 00000000 ____D C:\ProgramData\COMODO 2013-07-14 21:34 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-14 21:34 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\DriverStore 2013-07-14 21:32 - 2013-07-14 21:30 - 00000000 ____D C:\Program Files\Comodo 2013-07-14 21:31 - 2013-07-14 21:31 - 00002017 _____ C:\Users\Public\Desktop\AntiError.lnk 2013-07-14 21:31 - 2013-07-14 21:31 - 00002013 _____ C:\Users\Public\Desktop\GeekBuddy.lnk 2013-07-14 21:31 - 2013-07-14 21:31 - 00000000 ____D C:\Program Files\Common Files\COMODO 2013-07-14 21:30 - 2013-07-14 21:30 - 00047368 _____ (COMODO CA Limited) C:\windows\system32\certsentry.dll 2013-07-14 21:30 - 2013-07-14 21:30 - 00001078 _____ C:\Users\Public\Desktop\Comodo Dragon.lnk 2013-07-14 21:30 - 2013-07-14 21:30 - 00000000 ____D C:\Users\Paulina\AppData\Local\Comodo 2013-07-14 21:30 - 2013-07-14 21:30 - 00000000 ____D C:\ProgramData\Comodo Downloader 2013-07-14 21:27 - 2013-07-14 21:25 - 149029376 _____ (COMODO) C:\Users\Paulina\Downloads\cispremium_installer_6.2.exe 2013-07-14 21:14 - 2011-06-11 17:50 - 00000000 ____D C:\Users\Paulina\AppData\Local\CrashDumps 2013-07-14 11:52 - 2013-07-12 18:13 - 00000005 _____ C:\Users\Paulina\AppData\Roaming\WBPU-TTL.DAT 2013-07-14 10:16 - 2010-12-24 21:12 - 00000000 ____D C:\Users\Paulina\Documents\Youcam 2013-07-13 09:14 - 2012-12-22 21:00 - 00000000 ____D C:\Users\Paulina\Desktop\Videos zum Selbermachen,Ideen für mein Zimmer,Dreadlocks ect 2013-07-13 08:39 - 2010-10-07 17:34 - 00000000 ___RD C:\Users\Paulina\Desktop 2013-07-13 08:35 - 2013-07-12 17:16 - 00000000 ____D C:\Program Files\DivX 2013-07-13 08:35 - 2013-07-12 17:15 - 00000000 ____D C:\ProgramData\DivX 2013-07-13 08:33 - 2010-12-24 21:12 - 00109280 _____ C:\Users\Paulina\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-13 08:32 - 2009-07-14 06:33 - 00419992 _____ C:\windows\system32\FNTCACHE.DAT 2013-07-12 17:17 - 2013-07-12 17:17 - 00000000 ____D C:\Users\Paulina\Qtrax 2013-07-12 17:17 - 2010-10-07 17:34 - 00000000 ____D C:\Users\Paulina 2013-07-12 17:16 - 2013-07-12 17:16 - 00000000 ____D C:\Program Files\Xvid 2013-07-12 17:16 - 2013-07-12 17:16 - 00000000 ____D C:\Program Files\ffdshow 2013-07-12 17:15 - 2013-07-12 17:15 - 00715038 _____ C:\windows\unins000.exe 2013-07-12 17:15 - 2013-07-12 17:15 - 00001788 _____ C:\windows\unins000.dat 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\LavFilters 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\CDXReader 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\OpenSource Flash Video Splitter 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\Lame For Audacity 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\Haali 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\DSP-worx 2013-07-12 17:15 - 2013-07-12 17:15 - 00000000 ____D C:\Program Files\DirectVobSub 2013-07-12 17:15 - 2013-07-12 17:13 - 00000000 ____D C:\Program Files\Plus-HD-2.3 2013-07-12 17:14 - 2013-07-12 17:14 - 00000000 ____D C:\windows\system32\searchplugins 2013-07-12 17:14 - 2013-07-12 17:14 - 00000000 ____D C:\windows\system32\Extensions 2013-07-12 17:14 - 2013-07-12 17:14 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\DSite 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Delta 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\DealPly 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Babylon 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\BabSolution 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\ProgramData\BrowserDefender 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\ProgramData\Babylon 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-12 17:13 - 2013-07-12 17:13 - 00000000 ____D C:\Program Files\Delta 2013-07-10 22:33 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-07-10 15:58 - 2010-10-07 17:34 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-10 15:58 - 2009-07-29 12:50 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 15:58 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-09 21:16 - 2010-06-26 01:40 - 00343064 _____ C:\windows\system32\PerfStringBackup.INI 2013-07-09 21:13 - 2010-10-07 17:51 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-09 21:06 - 2010-12-31 10:35 - 75699896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2013-07-08 22:59 - 2013-06-18 16:16 - 00582936 _____ (COMODO) C:\windows\system32\Drivers\cmdguard.sys 2013-07-03 17:39 - 2013-07-03 17:39 - 00000000 ____D C:\Users\Paulina\Desktop\KEVIN 2013-07-01 10:49 - 2013-07-01 10:44 - 119585424 _____ C:\Users\Paulina\Downloads\Fler - Hinter Blauen Augen (Premium Edition).zip 2013-07-01 10:25 - 2013-05-07 15:20 - 00067168 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys 2013-06-29 23:37 - 2010-12-24 22:05 - 00000000 ____D C:\Users\Paulina\AppData\Roaming\Skype 2013-06-27 20:48 - 2009-07-14 06:53 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT 2013-06-21 21:02 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE 2013-06-21 16:05 - 2013-06-21 16:05 - 01441280 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-06-21 16:05 - 2013-06-21 16:05 - 01400416 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-06-21 16:05 - 2013-06-21 16:05 - 00745472 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00719360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00629248 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00523264 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00361984 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-06-21 16:05 - 2013-06-21 16:05 - 00357888 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00242200 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00232960 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00204800 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00158720 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00138752 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00137216 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00125440 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00117248 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00073728 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-06-21 16:05 - 2013-06-21 16:05 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00023040 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-06-21 16:05 - 2013-06-21 16:05 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-06-21 16:05 - 2013-06-21 16:05 - 00011776 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-06-18 16:16 - 2013-06-18 16:16 - 00085464 _____ (COMODO) C:\windows\system32\Drivers\inspect.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00043728 _____ (COMODO) C:\windows\system32\Drivers\cmdhlp.sys 2013-06-18 16:16 - 2013-06-18 16:16 - 00020072 _____ (COMODO) C:\windows\system32\Drivers\cmderd.sys 2013-06-18 16:15 - 2013-06-18 16:15 - 00348584 _____ (COMODO) C:\windows\system32\guard32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00278232 _____ (COMODO) C:\windows\system32\cmdvrt32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00040664 _____ (COMODO) C:\windows\system32\cmdkbd32.dll 2013-06-18 16:15 - 2013-06-18 16:15 - 00035488 _____ (COMODO) C:\windows\system32\cmdcsr.dll Files to move or delete: ==================== C:\Users\Gast\AppData\Roaming\i.ini ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-09 11:04 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 14-07-2013 Ran by Paulina at 2013-07-15 09:33:42 Running from C:\Users\Paulina\Downloads Boot Mode: Normal ========================================================== Adobe AIR (Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader 9.0.1 (Version: 9.0.1) AMD USB Filter Driver (Version: 1.0.15.94) Ask Toolbar (Version: 1.15.4.0) Ask Toolbar Updater (HKCU Version: 1.2.2.23821) ATI Catalyst Install Manager (Version: 3.0.765.0) Audacity 1.3.13 (Unicode) Avira Free Antivirus (Version: 13.0.0.3737) Bing Bar (Version: 7.1.391.0) Broadcom 802.11 Wireless Driver (Version: 1.0.0.0) BrowserDefender Catalyst Control Center Core Implementation (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Full Existing (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Full New (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Light (Version: 2010.0302.2233.40412) Catalyst Control Center Graphics Previews Common (Version: 2010.0302.2233.40412) Catalyst Control Center InstallProxy (Version: 2010.0302.2233.40412) Catalyst Control Center Localization All (Version: 2010.0302.2233.40412) CCC Help Chinese Standard (Version: 2010.0302.2232.40412) CCC Help Chinese Traditional (Version: 2010.0302.2232.40412) CCC Help Czech (Version: 2010.0302.2232.40412) CCC Help Danish (Version: 2010.0302.2232.40412) CCC Help Dutch (Version: 2010.0302.2232.40412) CCC Help English (Version: 2010.0302.2232.40412) CCC Help Finnish (Version: 2010.0302.2232.40412) CCC Help French (Version: 2010.0302.2232.40412) CCC Help German (Version: 2010.0302.2232.40412) CCC Help Greek (Version: 2010.0302.2232.40412) CCC Help Hungarian (Version: 2010.0302.2232.40412) CCC Help Italian (Version: 2010.0302.2232.40412) CCC Help Japanese (Version: 2010.0302.2232.40412) CCC Help Korean (Version: 2010.0302.2232.40412) CCC Help Norwegian (Version: 2010.0302.2232.40412) CCC Help Polish (Version: 2010.0302.2232.40412) CCC Help Portuguese (Version: 2010.0302.2232.40412) CCC Help Russian (Version: 2010.0302.2232.40412) CCC Help Spanish (Version: 2010.0302.2232.40412) CCC Help Swedish (Version: 2010.0302.2232.40412) CCC Help Thai (Version: 2010.0302.2232.40412) CCC Help Turkish (Version: 2010.0302.2232.40412) ccc-core-static (Version: 2010.0302.2233.40412) ccc-utility (Version: 2010.0302.2233.40412) CCleaner (Version: 3.02) Comodo Dragon (Version: 27.0.4.0) COMODO Internet Security Premium (Version: 6.2.20728.2847) Conexant HD Audio (Version: 4.111.0.62) CyberLink YouCam (Version: 3.0.2421a) DC-Bass Source 1.3.0 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Delta Chrome Toolbar Delta toolbar (Version: 1.8.21.5) DirectVobSub 2.40.4209 (Version: 2.40.4209) DivX-Setup (Version: 2.6.1.8) DVDVideoSoftTB DE Toolbar (Version: 6.9.0.16) Energy Management (Version: 5.3.0.8) ffdshow v1.1.4399 [2012-03-22] (Version: 1.1.4399.0) Free YouTube to MP3 Converter version 3.11.37.1212 (Version: 3.11.37.1212) GeekBuddy (Version: 4.7.55) Google Chrome (HKCU Version: 28.0.1500.72) Haali Media Splitter iLivid (Version: 4.0.0.2208) Iminent (Version: 4.10.0.0) ImTranslator for IE Java Auto Updater (Version: 2.0.7.1) Java(TM) 6 Update 35 (Version: 6.0.350) Lagarith Lossless Codec (1.3.27) LAME v3.99.3 (for Windows) Lenovo DirectShare (Version: 1.0.1.38) Lenovo EasyCamera (Version: 5.8.0.12) Lenovo ReadyComm 5 (Version: 5.1.1.22) Lenovo ReadyComm 5.0 Service (Version: 5.0.0.1) McAfee Security Scan Plus (Version: 3.0.318.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Choice Guard (Version: 2.0.48.0) Microsoft Office 2010 (Version: 14.0.4763.1000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Nokia Connectivity Cable Driver (Version: 7.1.29.0) Nokia PC-Internetzugang (Version: 2.0.1.6) OpenSource Flash Video Splitter 1.0.0.5 (Version: 1.0.0.5) Opera 12.01 (Version: 12.01.1532) PC Connectivity Solution Lite (Version: 5.8.33.6) Picasa 3 (Version: 3.9) Plus-HD-2.3 (Version: 1.27.153.8) Power2Go (Version: 5.6.0.4809d4) Realtek USB 2.0 Card Reader (Version: 6.1.7600.30117) SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Drive Software SAMSUNG Mobile USB Modem 1.0 Software Samsung New PC Studio USB Driver Installer (Version: 1.00.0000) Search-Results Toolbar (Version: 1.0.0.12) Skype Click to Call (Version: 5.9.9216) Skype™ 6.0 (Version: 6.0.126) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Ultimate Codec VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0) VLC media player 1.1.7 (Version: 1.1.7) Windows Live Anmelde-Assistent (Version: 5.000.818.5) Windows Live Essentials (Version: 14.0.8089.0726) Windows Live Essentials (Version: 14.0.8089.726) Windows Live-Uploadtool (Version: 14.0.8014.1029) Windows-Treiberpaket - Nokia pccsmcfd (08/22/2008 7.0.0.0) (Version: 08/22/2008 7.0.0.0) WinRAR 4.20 (32-Bit) (Version: 4.20.0) XMedia Recode 3.0.9.0 (Version: 3.0.9.0) Xvid Video Codec (Version: 1.3.2) ==================== Restore Points ========================= 28-05-2013 17:15:26 Geplanter Prüfpunkt 09-06-2013 09:10:53 Geplanter Prüfpunkt 13-06-2013 16:55:23 Windows Update 21-06-2013 14:02:58 Windows Update 09-07-2013 19:00:30 Windows Update 14-07-2013 19:33:24 Gerätetreiber-Paketinstallation: COMODO Netzwerkdienst ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {093290F1-EF40-4747-BC98-96B2092F1005} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe [2012-06-06] () Task: {16FBC770-F0B7-41BD-A06B-357E0251685C} - System32\Tasks\Plus-HD-2.3-codedownloader => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-codedownloader.exe [2013-07-12] (Plus HD) Task: {176B69F5-B4FB-432E-805B-CC33DC8AC328} - System32\Tasks\{20370E79-4265-49FF-9826-C14D5698101A} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {1A2F035A-D9FD-42F7-8ABC-B7170F7E1999} - System32\Tasks\{264E39A4-65CF-4F7A-92CD-22D2A2E97396} => C:\Program Files\Internet Explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {1BC6568D-06FA-4218-8C90-FA2997E6E5AD} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-07-08] (COMODO) Task: {23CB3456-224A-4634-A387-C63C9B148E3A} - System32\Tasks\BrowserDefendert => C:\windows\system32\sc.exe [2009-07-14] (Microsoft Corporation) Task: {255FE613-B71F-4E19-95FC-A7EFAD65772C} - System32\Tasks\{6856395F-8950-4F63-B9BA-3DDCD670641D} => C:\Program Files\Internet Explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {310C0320-EB98-4DCD-90A9-E50EC2CE92A3} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-07-08] (COMODO) Task: {46589F91-8321-431A-BE16-1FD620397D24} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {4CD10A40-E78C-47A8-A623-C885091FB8AF} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-07-08] (COMODO) Task: {5C3C94D2-B6F9-4C64-8525-14CCD9279471} - System32\Tasks\DealPly => C:\Users\Paulina\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE No File Task: {627BA19B-3781-433D-8758-0B410FF837F8} - System32\Tasks\{FD9E755D-0E8B-4CFB-AC85-B89CDFD814E2} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {678BC6B4-1F76-4B7B-8970-27AC715E5C70} - System32\Tasks\{18CE69E3-4E54-495F-A042-01D4897247FF} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {75E352CC-6D58-4F9C-B172-B8270588429D} - System32\Tasks\EPUpdater => C:\Users\Paulina\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [2013-06-06] () Task: {77ACD958-EFA1-4E9D-9E66-E0ECC6B16E4C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001UA => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-30] (Google Inc.) Task: {7A1E4277-D2ED-4AE4-963F-A53CD0065131} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-07-08] (COMODO) Task: {8B9765C0-A09C-4BC5-8F49-852F8126EA7E} - System32\Tasks\Plus-HD-2.3-chromeinstaller => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-chromeinstaller.exe [2013-07-12] (Plus HD) Task: {8DEA3BD7-1A30-4DC7-8EDE-C14D8B03218A} - System32\Tasks\{FC104110-06D1-42A5-8F27-330F49AD3D1F} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {915FB41F-1375-4E3B-ABE8-DB9E1F8BC0C3} - System32\Tasks\Plus-HD-2.3-enabler => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-enabler.exe [2013-07-12] (Plus HD) Task: {A5C164A0-F23A-49FF-B341-B93DC64166D0} - System32\Tasks\COMODO\COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [2013-07-08] (COMODO) Task: {A5D03ADE-9375-4F51-A2A3-FC165ECFE675} - System32\Tasks\{81DD89C5-F18A-4A8A-BC6F-3DE68B506527} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {C94A4779-BC70-4784-9C8B-2E41B27CF229} - System32\Tasks\{E79D8D93-E8F7-4350-B0F7-F9F2AA75A3CC} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {CF24913A-4740-479F-9F0A-A6C62FF7C9A4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001Core => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-30] (Google Inc.) Task: {D4919017-D671-46E3-A782-B37FC0D8AACA} - System32\Tasks\{AD7A2856-AFF3-4724-A08D-E030E50D1120} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {D4FAB41F-C5AD-4245-8522-468F104A8F9A} - System32\Tasks\{44D0BC17-4DB6-4705-B1BB-195F64CF796D} => C:\Program Files\Skype\\Phone\Skype.exe [2012-11-09] (Skype Technologies S.A.) Task: {D7358E00-3F04-40B5-999D-9EEBE1DF792E} - System32\Tasks\Plus-HD-2.3-updater => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-updater.exe [2013-07-12] (Plus HD) Task: {DD0C03D5-C43E-4114-BF9A-D6604AFE7A70} - System32\Tasks\{C2B10A17-DC74-4812-8CBE-CEE7F5B31B4D} => C:\Program Files\Internet Explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {E8AD37A5-2F6C-463C-BD9C-072E5DC11920} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {ECACD0A8-03B4-4205-94F8-D4E7E75266B6} - System32\Tasks\DSite => C:\Users\Paulina\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [2013-07-12] () Task: {EF7D69D9-93E4-42A3-AD65-16704E6BA66C} - System32\Tasks\{C3FAD734-D3BE-4694-A82B-F80B8524F7DF} => c:\program files\internet explorer\iexplore.exe [2013-06-12] (Microsoft Corporation) Task: {F629D806-F34E-4940-B52D-B0C7E3B660EA} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation) Task: {F8D5563E-0908-4F51-9667-BD2B3A830EDB} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-13] (Adobe Systems Incorporated) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\DSite.job => ? Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001Core.job => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001UA.job => C:\Users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\Plus-HD-2.3-chromeinstaller.job => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-chromeinstaller.exe Task: C:\windows\Tasks\Plus-HD-2.3-codedownloader.job => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-codedownloader.exe Task: C:\windows\Tasks\Plus-HD-2.3-enabler.job => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-enabler.exe Task: C:\windows\Tasks\Plus-HD-2.3-updater.job => C:\Program Files\Plus-HD-2.3\Plus-HD-2.3-updater.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/14/2013 09:14:36 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: div80D4.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Name des fehlerhaften Moduls: div80D4.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005724a ID des fehlerhaften Prozesses: 0x474 Startzeit der fehlerhaften Anwendung: 0xdiv80D4.tmp0 Pfad der fehlerhaften Anwendung: div80D4.tmp1 Pfad des fehlerhaften Moduls: div80D4.tmp2 Berichtskennung: div80D4.tmp3 Error: (07/13/2013 09:32:22 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: div27AE.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Name des fehlerhaften Moduls: div27AE.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005724a ID des fehlerhaften Prozesses: 0x3ec Startzeit der fehlerhaften Anwendung: 0xdiv27AE.tmp0 Pfad der fehlerhaften Anwendung: div27AE.tmp1 Pfad des fehlerhaften Moduls: div27AE.tmp2 Berichtskennung: div27AE.tmp3 Error: (07/13/2013 08:40:17 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: div6A95.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Name des fehlerhaften Moduls: div6A95.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005724a ID des fehlerhaften Prozesses: 0xf74 Startzeit der fehlerhaften Anwendung: 0xdiv6A95.tmp0 Pfad der fehlerhaften Anwendung: div6A95.tmp1 Pfad des fehlerhaften Moduls: div6A95.tmp2 Berichtskennung: div6A95.tmp3 Error: (07/13/2013 08:39:42 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: divD1DF.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Name des fehlerhaften Moduls: divD1DF.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005724a ID des fehlerhaften Prozesses: 0xce4 Startzeit der fehlerhaften Anwendung: 0xdivD1DF.tmp0 Pfad der fehlerhaften Anwendung: divD1DF.tmp1 Pfad des fehlerhaften Moduls: divD1DF.tmp2 Berichtskennung: divD1DF.tmp3 Error: (07/09/2013 09:15:54 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (07/09/2013 09:15:54 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (07/09/2013 09:02:46 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (07/09/2013 09:02:45 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (07/03/2013 04:56:41 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (07/03/2013 11:54:40 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. System errors: ============= Error: (07/15/2013 08:46:26 AM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (07/15/2013 08:46:12 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/15/2013 08:46:12 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (07/15/2013 08:42:44 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 15.07.2013 um 08:40:53 unerwartet heruntergefahren. Error: (07/15/2013 08:38:14 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/15/2013 08:38:14 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Media Player-Netzwerkfreigabedienst erreicht. Error: (07/15/2013 08:35:25 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/15/2013 08:35:24 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (07/15/2013 08:35:25 AM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (07/14/2013 09:46:56 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "KITA-NB", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{2A33FDB8-30AA-4265-AC19-FB836F0DCF-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Microsoft Office Sessions: ========================= Error: (07/14/2013 09:14:36 PM) (Source: Application Error)(User: ) Description: div80D4.tmp2.6.1.84f3db06cdiv80D4.tmp2.6.1.84f3db06cc00000050005724a47401ce80c65fa5b6a4C:\Users\Paulina\AppData\Local\Temp\div80C4.tmp\div80D4.tmpC:\Users\Paulina\AppData\Local\Temp\div80C4.tmp\div80D4.tmp9edf388d-ecb9-11e2-aa39-88ae1d35ec03 Error: (07/13/2013 09:32:22 PM) (Source: Application Error)(User: ) Description: div27AE.tmp2.6.1.84f3db06cdiv27AE.tmp2.6.1.84f3db06cc00000050005724a3ec01ce7fffaeeb62dfC:\Users\Paulina\AppData\Local\Temp\div2740.tmp\div27AE.tmpC:\Users\Paulina\AppData\Local\Temp\div2740.tmp\div27AE.tmpf02a0b2b-ebf2-11e2-9cf0-88ae1d35ec03 Error: (07/13/2013 08:40:17 AM) (Source: Application Error)(User: ) Description: div6A95.tmp2.6.1.84f3db06cdiv6A95.tmp2.6.1.84f3db06cc00000050005724af7401ce7f93d5afbfbdC:\Users\Paulina\AppData\Local\Temp\div6A46.tmp\div6A95.tmpC:\Users\Paulina\AppData\Local\Temp\div6A46.tmp\div6A95.tmp13fe2830-eb87-11e2-81f9-88ae1d35ec03 Error: (07/13/2013 08:39:42 AM) (Source: Application Error)(User: ) Description: divD1DF.tmp2.6.1.84f3db06cdivD1DF.tmp2.6.1.84f3db06cc00000050005724ace401ce7f93be628753C:\Users\Paulina\AppData\Local\Temp\divD1BF.tmp\divD1DF.tmpC:\Users\Paulina\AppData\Local\Temp\divD1BF.tmp\divD1DF.tmpff6cc456-eb86-11e2-81f9-88ae1d35ec03 Error: (07/09/2013 09:15:54 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (07/09/2013 09:15:54 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (07/09/2013 09:02:46 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (07/09/2013 09:02:45 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (07/03/2013 04:56:41 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 Error: (07/03/2013 11:54:40 AM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT) Description: Performance1637070000000000000000000009030000 ==================== Memory info =========================== Percentage of memory in use: 37% Total physical RAM: 2812.2 MB Available physical RAM: 1748 MB Total Pagefile: 5622.7 MB Available Pagefile: 4064.9 MB Total Virtual: 2047.88 MB Available Virtual: 1927.04 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:254.14 GB) (Free:193.03 GB) NTFS Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:28.19 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 8FFA782E) Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=254 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=15 GB) - (Type=12) ==================== End Of Log ============================ |
15.07.2013, 09:25 | #6 | |
/// the machine /// TB-Ausbilder | Auf jeder Website überall WerbungCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ --> Auf jeder Website überall Werbung |
15.07.2013, 11:49 | #7 |
| Auf jeder Website überall Werbung Also ich weiß nicht aber irgendwie bekomme ich das mit Combofix nicht richtig hin,gibt´s vielleicht auch noch eine andere Möglichkeit-die Werbung ist fast ausschließlich von InstantSaving (app)? Paulina |
15.07.2013, 12:48 | #8 |
/// the machine /// TB-Ausbilder | Auf jeder Website überall Werbung Geht das genauer? Was klappt nicht? Das Laden von dem Tool auf den Desktop? Oder den doppelklick drauf machen? Mehr isses nämlich nit
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.07.2013, 14:33 | #9 |
| Auf jeder Website überall Werbung Naja,ich würde mal sagen das Laden von DM-Tool auf den Desktop. Also ich hatte es einmal ausprobiert,da hats dann auf dem Desktop nur noch das Combofix und zB. 1,2,3 fertiggestellt und bei Lösche xxx ist es dann ewig stehen geblieben ? Und jetzt wollte ich es mir nochmal runterladen,aber das geht irgendwie nichtmehr. Was soll ich jetzt machen? Paulina |
15.07.2013, 18:58 | #10 |
/// the machine /// TB-Ausbilder | Auf jeder Website überall Werbung Das geht irgendwie nicht mehr? Was heisst irgendwie? Lösche die Combofix.exe, lade sie neu, lass sie laufen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.07.2013, 19:17 | #11 |
| Auf jeder Website überall Werbung Hier ist die Combofix.txt-hoffe das ist das richtige: Code:
ATTFilter ComboFix 13-07-14.01 - Paulina 16.07.2013 19:59:06.2.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2812.2026 [GMT 2:00] ausgeführt von:: c:\users\Paulina\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Windows Live\Messenger\msacm32.dll c:\users\Paulina\20120407180455854.bmp.jpg c:\users\Paulina\20120407180515955.bmp.jpg c:\users\Paulina\20120407180524851.bmp.jpg c:\users\Paulina\20120407180529497.bmp.jpg c:\users\Paulina\20120508180528817.bmp.jpg c:\users\Paulina\20120508180536382.bmp.jpg c:\users\Paulina\20120508180821491.bmp.jpg c:\users\Paulina\20120508180851359.bmp.jpg c:\users\Paulina\20120508181011360.bmp.jpg c:\users\Paulina\20120508181132647.bmp.jpg c:\users\Paulina\20120508181143179.bmp.jpg c:\users\Paulina\20120508181152464.bmp.jpg c:\users\Paulina\20120508181201990.bmp.jpg . . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-06-06 1519304] "{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}"= "c:\program files\DVDVideoSoftTB_DE\prxtbDVD0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_CLASSES_ROOT\clsid\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] 2011-05-09 09:49 176936 ----a-w- c:\program files\DVDVideoSoftTB_DE\prxtbDVD0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}"= "c:\program files\DVDVideoSoftTB_DE\prxtbDVD0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}"= "c:\program files\DVDVideoSoftTB_DE\prxtbDVD0.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe" [2012-10-30 116648] "GoogleChromeAutoLaunch_9EE49418645B8CE65A6F7F02D3D23CBF"="c:\users\Paulina\AppData\Local\Google\Chrome\Application\chrome.exe" [2013-07-12 846288] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe" [2010-03-10 496184] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184] "UCam_Menu"="c:\program files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504] "YouCam Mirror Tray icon"="c:\program files\Lenovo\YouCam\YouCamTray.exe" [2009-12-22 167008] "UpdateP2GShortCut"="c:\program files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408] "EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2009-12-17 4114368] "Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2009-12-17 6223808] "IMBooster"="c:\program files\Iminent\IMBooster\imbooster.exe" [2011-03-30 1324008] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-07-01 345144] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-06-06 1564872] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\BROWSE~1\261339~1.144\{C16C1~1\BrowserDefender.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 MMCSS;Multimediaklassenplaner;c:\windows\system32\svchost.exe [2009-07-14 20992] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-11-09 160944] R2 sppsvc;Software Protection;c:\windows\system32\sppsvc.exe [2010-11-20 3179520] R2 WinDefend;Windows Defender;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 1394ohci;OHCI-konformer 1394-Hostcontroller;c:\windows\system32\drivers\1394ohci.sys [2010-11-20 164864] R3 AcpiPmi;ACPI-Energieanzeigetreiber;c:\windows\system32\drivers\acpipmi.sys [2010-11-20 10240] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-13 256904] R3 adp94xx;adp94xx;c:\windows\system32\DRIVERS\adp94xx.sys [2009-07-14 422976] R3 adpahci;adpahci;c:\windows\system32\DRIVERS\adpahci.sys [2009-07-14 297552] R3 amdsata;amdsata;c:\windows\system32\drivers\amdsata.sys [2011-03-11 80256] R3 amdsbs;amdsbs;c:\windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312] R3 ApfiltrService;Alps Pointing-device Filter Driver;c:\windows\system32\DRIVERS\Apfiltr.sys [x] R3 AppID;Anwendungs-ID-Treiber;c:\windows\system32\drivers\appid.sys [2010-11-20 50176] R3 AppIDSvc;Anwendungsidentität;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 arcsas;arcsas;c:\windows\system32\DRIVERS\arcsas.sys [2009-07-14 86608] R3 b06bdrv;Broadcom NetXtreme II VBD;c:\windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888] R3 BDESVC;BitLocker-Laufwerkverschlüsselungsdienst;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;c:\windows\system32\DRIVERS\BrFiltLo.sys [2009-07-13 13568] R3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;c:\windows\system32\DRIVERS\BrFiltUp.sys [2009-07-13 5248] R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240] R3 Brserid;Brother MFC Serial Port Interface Driver (WDM);c:\windows\System32\Drivers\Brserid.sys [2009-07-14 272128] R3 BrSerWdm;Brother WDM Serial driver;c:\windows\System32\Drivers\BrSerWdm.sys [2009-07-13 62336] R3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\System32\Drivers\BrUsbMdm.sys [2009-07-13 12160] R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\System32\Drivers\BrUsbSer.sys [2009-07-13 11904] R3 BthEnum;Bluetooth-Anforderungsblocktreiber;c:\windows\system32\drivers\BthEnum.sys [2009-07-13 34816] R3 BthPan;Bluetooth-Gerät (PAN);c:\windows\system32\DRIVERS\bthpan.sys [2009-07-13 93696] R3 BTHPORT;Bluetooth-Porttreiber;c:\windows\System32\Drivers\BTHport.sys [2012-07-06 393728] R3 bthserv;Bluetooth-Unterstützungsdienst;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 BTHUSB;USB-Treiber für Bluetooth-Funkgerät;c:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416] R3 CertPropSvc;Zertifikatverteilung;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 circlass;Consumer IR Devices;c:\windows\system32\DRIVERS\circlass.sys [2009-07-13 37888] R3 defragsvc;Defragmentierung;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 ebdrv;Broadcom NetXtreme II 10 GigE VBD;c:\windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160] R3 EFS;Verschlüsselndes Dateisystem (EFS);c:\windows\System32\lsass.exe [2011-11-17 22528] R3 ehRecvr;Windows Media Center-Empfängerdienst;c:\windows\ehome\ehRecvr.exe [2010-11-20 556544] R3 ehSched;Windows Media Center-Planerdienst;c:\windows\ehome\ehsched.exe [2009-07-14 94720] R3 elxstor;elxstor;c:\windows\system32\DRIVERS\elxstor.sys [2009-07-14 453712] R3 ErrDev;Microsoft-Hardwarefehler-Gerätetreiber;c:\windows\system32\drivers\errdev.sys [2009-07-13 7168] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [2011-05-06 13904] R3 Fax;Fax;c:\windows\system32\fxssvc.exe [2010-11-20 523264] R3 fdPHost;Funktionssuchanbieter-Host;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 Filetrace;Filetrace;c:\windows\system32\drivers\filetrace.sys [2009-07-13 28160] R3 FsDepends;File System Dependency Minifilter;c:\windows\system32\drivers\FsDepends.sys [2009-07-14 46160] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-31 36608] R3 gagp30kx;Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms;c:\windows\system32\DRIVERS\gagp30kx.sys [2009-07-14 57936] R3 hcw85cir;Hauppauge Consumer Infrared Receiver;c:\windows\system32\drivers\hcw85cir.sys [2009-07-13 26624] R3 HdAudAddService;Microsoft 1.1 UAA-Funktionstreiber für High Definition Audio-Dienst;c:\windows\system32\drivers\HdAudio.sys [2010-11-20 304128] R3 HidBth;Microsoft Bluetooth HID Miniport;c:\windows\system32\DRIVERS\hidbth.sys [2009-07-13 91136] R3 HidIr;Microsoft Infrared HID Driver;c:\windows\system32\DRIVERS\hidir.sys [2009-07-13 37888] R3 HomeGroupListener;Heimnetzgruppen-Listener;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 HomeGroupProvider;Heimnetzgruppen-Anbieter;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 HpSAMD;HpSAMD;c:\windows\system32\drivers\HpSAMD.sys [2009-07-14 67152] R3 iaStorV;Intel RAID-Controller Windows 7;c:\windows\system32\drivers\iaStorV.sys [2011-03-11 332160] R3 igfx;igfx;c:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480] R3 IGRS;IGRS;c:\program files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-15 38152] R3 IPBusEnum;PnP-X-IP-Busenumerator;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 IPMIDRV;IPMIDRV;c:\windows\system32\drivers\IPMIDrv.sys [2010-11-20 65536] R3 iScsiPrt;iScsiPort-Treiber;c:\windows\system32\drivers\msiscsi.sys [2010-11-20 233344] R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888] R3 KtmRm;KtmRm für Distributed Transaction Coordinator;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192] R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-11-17 575304] R3 lltdsvc;Verbindungsschicht-Topologieerkennungs-Zuordnungsprogramm;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 LSI_FC;LSI_FC;c:\windows\system32\DRIVERS\lsi_fc.sys [2009-07-14 95824] R3 LSI_SAS;LSI_SAS;c:\windows\system32\DRIVERS\lsi_sas.sys [2009-07-14 89168] R3 LSI_SAS2;LSI_SAS2;c:\windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864] R3 LSI_SCSI;LSI_SCSI;c:\windows\system32\DRIVERS\lsi_scsi.sys [2009-07-14 96848] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216] R3 megasas;megasas;c:\windows\system32\DRIVERS\megasas.sys [2009-07-14 30800] R3 MegaSR;MegaSR;c:\windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584] R3 mpio;Microsoft Multipfad-Bustreiber;c:\windows\system32\drivers\mpio.sys [2010-11-20 130432] R3 msdsm;Microsoft Multipfadgeräte-spezifisches Modul;c:\windows\system32\drivers\msdsm.sys [2010-11-20 116096] R3 mshidkmdf;Pass-through HID to KMDF Filter Driver;c:\windows\System32\drivers\mshidkmdf.sys [2009-07-13 4096] R3 MSiSCSI;Microsoft iSCSI-Initiator-Dienst;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 MsRPC;MsRPC; [x] R3 MTConfig;Microsoft Input Configuration Driver;c:\windows\system32\DRIVERS\MTConfig.sys [2009-07-13 12288] R3 NdisCap;NDIS Capture LightWeight Filter;c:\windows\system32\DRIVERS\ndiscap.sys [2009-07-13 27136] R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] R3 nfrd960;nfrd960;c:\windows\system32\DRIVERS\nfrd960.sys [2009-07-14 44624] R3 nmwcd;Nokia USB Phone Parent Driver;c:\windows\system32\drivers\ccdcmb.sys [2011-08-17 18176] R3 nmwcdc;Nokia USB Communication Driver;c:\windows\system32\drivers\ccdcmbo.sys [2011-08-17 23168] R3 nvstor;nvstor;c:\windows\system32\drivers\nvstor.sys [2011-03-11 143744] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] R3 p2pimsvc;Peernetzwerkidentitäts-Manager;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 p2psvc;Peernetzwerk-Gruppenzuordnung;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 pccsmcfd;PCCS Mode Change Filter Driver;c:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816] R3 pla;Leistungsprotokolle und -warnungen;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 PNRPAutoReg;PNRP-Computernamenveröffentlichungs-Dienst;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 PNRPsvc;Peer Name Resolution-Protokoll;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992] R3 ql2300;ql2300;c:\windows\system32\DRIVERS\ql2300.sys [2009-07-14 1383488] R3 ql40xx;ql40xx;c:\windows\system32\DRIVERS\ql40xx.sys [2009-07-14 106064] R3 QWAVE;Verbessertes Windows-Audio/Video-Streaming;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 QWAVEdrv;QWAVE-Treiber;c:\windows\system32\drivers\qwavedrv.sys [2009-07-13 31744] R3 rdpbus;Remote Desktop Device Redirector Bus Driver;c:\windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944] R3 RFCOMM;Bluetooth-Gerät (RFCOMM-Protokoll-TDI);c:\windows\system32\DRIVERS\rfcomm.sys [2009-07-13 129536] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-03-24 191008] R3 sbp2port;Bustreiber für SBP2-Transport/Protokoll;c:\windows\system32\drivers\sbp2port.sys [2010-11-20 85376] R3 scfilter;Filtertreiber für Smartcards der Plug & Play-Klasse;c:\windows\system32\DRIVERS\scfilter.sys [2010-11-20 26624] R3 SCPolicySvc;Richtlinie zum Entfernen der Scmartcard;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 SDRSVC;Windows-Sicherung;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 SensrSvc;Adaptive Helligkeit;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 sermouse;Serial Mouse Driver;c:\windows\system32\DRIVERS\sermouse.sys [2009-07-13 19968] R3 ServiceLayer;ServiceLayer;c:\program files\PC Connectivity Solution\ServiceLayer.exe [2008-09-23 575488] R3 SessionEnv;Konfiguration für Remotedesktops;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 sffdisk;SFF-Speicherklassentreiber;c:\windows\system32\drivers\sffdisk.sys [2009-07-13 11264] R3 sffp_mmc;SFF-Speicherprotokolltreiber für MMC;c:\windows\system32\drivers\sffp_mmc.sys [2009-07-13 12288] R3 sffp_sd;SFF-Speicherprotokolltreiber für SDBus;c:\windows\system32\drivers\sffp_sd.sys [2010-11-20 12800] R3 SiSRaid2;SiSRaid2;c:\windows\system32\DRIVERS\SiSRaid2.sys [2009-07-14 40016] R3 SiSRaid4;SiSRaid4;c:\windows\system32\DRIVERS\sisraid4.sys [2009-07-14 77888] R3 Smb;Nachrichtenorientiertes TCP/IP- und TCP/IPv6-Protokoll (SMB-Sitzung);c:\windows\system32\DRIVERS\smb.sys [2009-07-13 71168] R3 SNMPTRAP;SNMP-Trap;c:\windows\System32\snmptrap.exe [2009-07-14 12800] R3 sppuinotify;SPP-Benachrichtigungsdienst;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [2009-09-19 98432] R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [2009-09-19 14848] R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [2009-09-19 123648] R3 stexstor;stexstor;c:\windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072] R3 TabletInputService;Tablet PC-Eingabedienst;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 TBS;TPM-Basisdienste;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 TCPIP6;Microsoft IPv6 Protocol Driver;c:\windows\system32\DRIVERS\tcpip.sys [2013-05-08 1293672] R3 THREADORDER;Server für Threadsortierung;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 TrustedInstaller;Windows Modules Installer;c:\windows\servicing\TrustedInstaller.exe [2010-11-20 204800] R3 tssecsrv;Remote Desktop Services Security Filter Driver;c:\windows\system32\DRIVERS\tssecsrv.sys [2010-11-20 31232] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 uagp35;Microsoft AGPv3.5 Filter;c:\windows\system32\DRIVERS\uagp35.sys [2009-07-14 55888] R3 UI0Detect;Erkennung interaktiver Dienste;c:\windows\system32\UI0Detect.exe [2009-07-14 35840] R3 uliagpkx;Uli AGP-Bus-Filter;c:\windows\system32\drivers\uliagpkx.sys [2009-07-14 57424] R3 UmPass;Microsoft UMPass Driver;c:\windows\system32\DRIVERS\umpass.sys [2009-07-13 8192] R3 upperdev;upperdev;c:\windows\system32\DRIVERS\usbser_lowerflt.sys [2011-08-17 8192] R3 usbcir;eHome-Infrarotempfänger (USBCIR);c:\windows\system32\drivers\usbcir.sys [2009-07-13 86016] R3 usbser;USB Modem Driver;c:\windows\system32\drivers\usbser.sys [2010-11-20 27648] R3 UsbserFilt;UsbserFilt;c:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2011-08-17 8192] R3 usbvideo;USB-Videogerät (WDM);c:\windows\System32\Drivers\usbvideo.sys [2010-11-20 146432] R3 VaultSvc;Anmeldeinformationsverwaltung;c:\windows\system32\lsass.exe [2011-11-17 22528] R3 vhdmp;vhdmp;c:\windows\system32\drivers\vhdmp.sys [2010-11-20 160128] R3 ViaC7;VIA C7 Processor Driver;c:\windows\system32\DRIVERS\viac7.sys [2009-07-13 52736] R3 vsmraid;vsmraid;c:\windows\system32\DRIVERS\vsmraid.sys [2009-07-14 141904] R3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\DRIVERS\wacompen.sys [2009-07-13 21632] R3 wbengine;Blockebenen-Sicherungsmodul;c:\windows\system32\wbengine.exe [2010-11-20 1203200] R3 WbioSrvc;Windows-Biometriedienst;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 wcncsvc;Windows-Sofortverbindung - Konfigurationsregistrierungsstelle;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 WcsPlugInService;Windows-Farbsystem;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 Wd;Wd;c:\windows\system32\DRIVERS\wd.sys [2009-07-14 19024] R3 Wecsvc;Windows-Ereignissammlung;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 wercplsupport;Unterstützung in der Systemsteuerung unter Lösungen für Probleme;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 WerSvc;Windows-Fehlerberichterstattungsdienst;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 WIMMount;WIMMount;c:\windows\system32\drivers\wimmount.sys [2009-07-14 19008] R3 WinRM;Windows-Remoteverwaltung (WS-Verwaltung);c:\windows\System32\svchost.exe [2009-07-14 20992] R3 WinUsb;WinUsb;c:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968] R3 WmiAcpi;Microsoft Windows Management Interface for ACPI;c:\windows\system32\drivers\wmiacpi.sys [2009-07-13 11264] R3 WPCSvc;Parental Controls;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 WPDBusEnum;Enumeratordienst für tragbare Geräte;c:\windows\system32\svchost.exe [2009-07-14 20992] R3 WwanSvc;WWAN - automatische Konfiguration;c:\windows\system32\svchost.exe [2009-07-14 20992] R4 Mcx2Svc;Media Center Extender-Dienst;c:\windows\system32\svchost.exe [2009-07-14 20992] S0 amdxata;amdxata;c:\windows\system32\drivers\amdxata.sys [2011-03-11 22400] S0 AtiPcie;AMD PCI Express (3GIO) Filter;c:\windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 14392] S0 CLFS;Gemeinsames Protokoll (CLFS);c:\windows\System32\CLFS.sys [2009-07-14 249408] S0 CNG;CNG;c:\windows\System32\Drivers\cng.sys [2012-06-02 369336] S0 FileInfo;File Information FS MiniFilter;c:\windows\system32\drivers\fileinfo.sys [2009-07-14 58448] S0 fvevol;Filtertreiber der Bitlocker-Laufwerkverschlüsselung;c:\windows\System32\DRIVERS\fvevol.sys [2013-01-24 196328] S0 hwpolicy;Hardware Policy Driver;c:\windows\System32\drivers\hwpolicy.sys [2010-11-20 14208] S0 KSecPkg;KSecPkg;c:\windows\System32\Drivers\ksecpkg.sys [2012-06-02 134000] S0 msahci;msahci;c:\windows\system32\drivers\msahci.sys [2010-11-20 28032] S0 msisadrv;msisadrv;c:\windows\system32\drivers\msisadrv.sys [2009-07-14 13888] S0 pcw;Performance Counters for Windows Driver;c:\windows\System32\drivers\pcw.sys [2009-07-14 43088] S0 rdyboost;ReadyBoost;c:\windows\System32\drivers\rdyboost.sys [2010-11-20 173440] S0 spldr;Security Processor Loader Driver; [x] S0 vdrvroot;Enumerator-Treiber für Microsoft Virtual Drive;c:\windows\system32\drivers\vdrvroot.sys [2009-07-14 32832] S0 volmgr;Treiber für Volume-Manager;c:\windows\system32\drivers\volmgr.sys [2010-11-20 53120] S0 volmgrx;Dynamischer Volume-Manager;c:\windows\System32\drivers\volmgrx.sys [2009-07-14 297040] S0 Wdf01000;Kernelmodustreiber-Frameworkdienst;c:\windows\system32\drivers\Wdf01000.sys [2012-07-26 526952] S1 avipbb;avipbb;c:\windows\system32\DRIVERS\avipbb.sys [2013-03-31 135136] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2013-03-31 37352] S1 blbdrive;blbdrive;c:\windows\system32\DRIVERS\blbdrive.sys [2009-07-13 35328] S1 DfsC;DFS Namespace Client Driver;c:\windows\system32\Drivers\dfsc.sys [2010-11-20 78336] S1 discache;System Attribute Cache;c:\windows\system32\drivers\discache.sys [2009-07-13 32256] S1 nsiproxy;NSI proxy service driver.;c:\windows\system32\drivers\nsiproxy.sys [2009-07-13 16896] S1 RDPENCDD;RDP Encoder Mirror Driver;c:\windows\system32\drivers\rdpencdd.sys [2009-07-14 6656] S1 RDPREFMP;Reflector Display Driver used to gain access to graphics data;c:\windows\system32\drivers\rdprefmp.sys [2009-07-14 7168] S1 ssmdrv;ssmdrv;c:\windows\system32\DRIVERS\ssmdrv.sys [2012-08-27 28520] S1 tdx;NetIO-Legacy-TDI-Supporttreiber;c:\windows\system32\DRIVERS\tdx.sys [2010-11-20 74752] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S1 Wanarpv6;Remotezugriff-IPv6-ARP-Treiber;c:\windows\system32\DRIVERS\wanarp.sys [2010-11-20 63488] S1 WfpLwf;WFP Lightweight Filter;c:\windows\system32\DRIVERS\wfplwf.sys [2009-07-13 9728] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-03-03 172032] S2 AntiVirSchedulerService;Avira Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2013-07-01 84024] S2 AudioEndpointBuilder;Windows-Audio-Endpunkterstellung;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 193616] S2 BFE;Basisfiltermodul;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 DPS;Diagnoserichtliniendienst;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 FDResPub;Funktionssuche-Ressourcenveröffentlichung;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 FontCache;Windows-Dienst für Schriftartencache;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 gpsvc;Gruppenrichtlinienclient;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 IKEEXT;IKE- und AuthIP IPsec-Schlüsselerstellungsmodule;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 iphlpsvc;IP-Hilfsdienst;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 lltdio;Link-Layer Topology Discovery Mapper I/O Driver;c:\windows\system32\DRIVERS\lltdio.sys [2009-07-13 48128] S2 luafv;UAC-Dateivirtualisierung;c:\windows\system32\drivers\luafv.sys [2009-07-13 86528] S2 MpsSvc;Windows-Firewall;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 NlaSvc;NLA (Network Location Awareness);c:\windows\System32\svchost.exe [2009-07-14 20992] S2 nsi;Netzwerkspeicher-Schnittstellendienst;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 PEAUTH;PEAUTH;c:\windows\system32\drivers\peauth.sys [2009-07-14 586752] S2 Power;Stromversorgung;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 ProfSvc;Benutzerprofildienst;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992] S2 RpcEptMapper;RPC-Endpunktzuordnung;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 rspndr;Link-Layer Topology Discovery Responder;c:\windows\system32\DRIVERS\rspndr.sys [2009-07-13 60928] S2 SysMain;Superfetch;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 tcpipreg;TCP/IP Registry Compatibility;c:\windows\system32\drivers\tcpipreg.sys [2012-10-03 35328] S2 UxSms;Sitzungs-Manager für Desktopfenster-Manager;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 Wlansvc;Automatische WLAN-Konfiguration;c:\windows\system32\svchost.exe [2009-07-14 20992] S2 WSearch;Windows Search;c:\windows\system32\SearchIndexer.exe [2011-05-04 427520] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2009-09-03 21256] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 5340160] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 152064] S3 Appinfo;Anwendungsinformationen;c:\windows\system32\svchost.exe [2009-07-14 20992] S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 240208] S3 BCM43XX;Broadcom 802.11 Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwl6.sys [2010-02-02 2707448] S3 bowser;Browsersupporttreiber;c:\windows\system32\DRIVERS\bowser.sys [2011-02-23 69632] S3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDRT32.sys [2010-01-18 514104] S3 CompositeBus;Busenumeratortreiber für Verbundgeräte;c:\windows\system32\drivers\CompositeBus.sys [2010-11-20 31232] S3 DXGKrnl;LDDM Graphics Subsystem;c:\windows\System32\drivers\dxgkrnl.sys [2013-04-10 728424] S3 KeyIso;CNG-Schlüsselisolation;c:\windows\system32\lsass.exe [2011-11-17 22528] S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-13 50688] S3 monitor;Microsoft Monitor Class Function Driver Service;c:\windows\system32\DRIVERS\monitor.sys [2009-07-13 23552] S3 mpsdrv;Windows-Firewallautorisierungstreiber;c:\windows\system32\drivers\mpsdrv.sys [2009-07-13 60416] S3 mrxsmb10;SMB 1.x-Miniredirector;c:\windows\system32\DRIVERS\mrxsmb10.sys [2011-07-09 223744] S3 mrxsmb20;SMB 2.0-Miniredirector;c:\windows\system32\DRIVERS\mrxsmb20.sys [2011-04-27 96768] S3 NativeWifiP;NativeWiFi Filter;c:\windows\system32\DRIVERS\nwifi.sys [2009-07-13 267264] S3 netprofm;Netzwerklistendienst;c:\windows\System32\svchost.exe [2009-07-14 20992] S3 PcaSvc;Programmkompatibilitäts-Assistent-Dienst;c:\windows\system32\svchost.exe [2009-07-14 20992] S3 RasAgileVpn;WAN Miniport (IKEv2);c:\windows\system32\DRIVERS\AgileVpn.sys [2009-07-13 49152] S3 srv2;Server-SMB-Treiber 2.xxx;c:\windows\system32\DRIVERS\srv2.sys [2011-04-29 310272] S3 srvnet;srvnet;c:\windows\system32\DRIVERS\srvnet.sys [2011-04-29 114688] S3 tunnel;Microsoft-Tunnelminiport-Adaptertreiber;c:\windows\system32\DRIVERS\tunnel.sys [2010-11-20 108544] S3 umbus;UMBusenumerator-Treiber;c:\windows\system32\drivers\umbus.sys [2010-11-20 39936] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 30392] S3 usbsmi;Lenovo EasyCamera;c:\windows\system32\DRIVERS\SMIksdrv.sys [2009-10-16 171776] S3 vwifibus;Virtual WiFi Bus Driver;c:\windows\system32\DRIVERS\vwifibus.sys [2009-07-13 19968] S3 WdiServiceHost;Diagnosediensthost;c:\windows\System32\svchost.exe [2009-07-14 20992] S3 WdiSystemHost;Diagnosesystemhost;c:\windows\System32\svchost.exe [2009-07-14 20992] S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP <NO NAME> REG_SZ . Inhalt des "geplante Tasks" Ordners . 2013-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-29 16:50] . 2013-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001Core.job - c:\users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-30 20:56] . 2013-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1520893771-1691518371-2521108171-1001UA.job - c:\users\Paulina\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-30 20:56] . 2013-07-16 c:\windows\Tasks\Plus-HD-2.3-chromeinstaller.job - c:\program files\Plus-HD-2.3\Plus-HD-2.3-chromeinstaller.exe [2013-07-12 15:13] . 2013-07-16 c:\windows\Tasks\Plus-HD-2.3-codedownloader.job - c:\program files\Plus-HD-2.3\Plus-HD-2.3-codedownloader.exe [2013-07-12 15:14] . 2013-07-16 c:\windows\Tasks\Plus-HD-2.3-enabler.job - c:\program files\Plus-HD-2.3\Plus-HD-2.3-enabler.exe [2013-07-12 15:14] . 2013-07-16 c:\windows\Tasks\Plus-HD-2.3-updater.job - c:\program files\Plus-HD-2.3\Plus-HD-2.3-updater.exe [2013-07-12 15:15] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Free YouTube Download - c:\users\Paulina\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to MP3 Converter - c:\users\Paulina\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: ImTranslator - e:\progra~1\SMARTL~1\IMTRAN~1\startup.html IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-10 - (no file) HKLM-Run-VeriFaceManager - c:\program files\Lenovo\VeriFace\PManage.exe HKLM-Run-NPSStartup - (no file) HKLM-Run-<NO NAME> - (no file) HKLM-Run-DivXMediaServer - c:\program files\DivX\DivX Media Server\DivXMediaServer.exe SafeBoot-mcmscsvc SafeBoot-MCODS AddRemove-ImTranslator for IE - e:\progra~1\SMARTL~1\IMTRAN~1\UNWISE.EXE AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-07-16 20:11:42 ComboFix-quarantined-files.txt 2013-07-16 18:11 . Vor Suchlauf: 6 Verzeichnis(se), 207.664.496.640 Bytes frei Nach Suchlauf: 10 Verzeichnis(se), 207.089.885.184 Bytes frei . - - End Of File - - F75464627E3DE4B2816A066FAC152732 A36C5E4F47E84449FF07ED3517B43A31 |
17.07.2013, 08:06 | #12 |
/// the machine /// TB-Ausbilder | Auf jeder Website überall Werbung Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.07.2013, 12:47 | #13 |
| Auf jeder Website überall Werbung Also ich habe eine Systemwiederherstellung auf den 14.06 gemacht,avira neu installiert und google chrome neu installiert und jetzt geht erstmal alles. Kann ich das da jetzt nicht erstmal so lassen? Freundliche Grüße Paulina ) |
17.07.2013, 13:11 | #14 |
/// the machine /// TB-Ausbilder | Auf jeder Website überall Werbung Klar, nur ist das immer ne bescheidene Idee. Wenn der Rechner infiziert ist macht jede Infektion zuerst mal eines: Die Systemwiederherstellungspunkte infizieren.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Auf jeder Website überall Werbung |
google, inter, interne, internetseite, internetseiten, laptop, massenweise, seite, seiten, tagen, website, werbun, werbung, werbung auf jeder internetseite, überall |