FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-07-2013
Ran by User (administrator) on 21-07-2013 17:14:50
Running from C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(AVM Berlin) C:\Programme\avmwlanstick\wlangui.exe
(Sun Microsystems, Inc.) C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Programme\Microsoft ActiveSync\Wcescomm.exe
(AVM Berlin) C:\Programme\avmwlanstick\WlanNetService.exe
() C:\Programme\ICQ6Toolbar\ICQ Service.exe
(Sun Microsystems, Inc.) C:\Programme\Java\jre6\bin\jqs.exe
(Microsoft Corporation) C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
(Nero AG) C:\Programme\Nero\Update\NASvc.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\PROGRA~1\MI3AA1~1\rapimgr.exe
(Softwareentwicklung Remus) C:\Programme\ArchiCrypt Stealth 4\IJStealth4Svc.exe
() C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
(Skype Technologies S.A.) C:\Programme\Skype\Phone\Skype.exe
(McAfee, Inc.) C:\Programme\McAfee Security Scan\3.0.318\SSScheduler.exe
(Microsoft Corporation) C:\Programme\Windows Desktop Search\WindowsSearch.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Programme\OpenOffice.org 3\program\soffice.bin
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Sun Microsystems, Inc.) C:\Programme\Gemeinsame Dateien\Java\Java Update\jucheck.exe
(Opera Software) C:\Programme\Opera\opera.exe
(Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe
==================== Registry (Whitelisted) ==================
sdaten\Google\Update\GoogleUpdate.exe [136176 2011-09-28] (Google Inc.)
HKCU\...\Run: [KiesHelper] - C:\Programme\Samsung\Kies\KiesHelper.exe [935312 2011-11-29] (Samsung)
HKCU\...\Run: [KiesPDLR] - C:\Programme\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2011-11-29] ()
HKCU\...\Run: [MSMSGS] - C:\Programme\Messenger\msmsgs.exe [1695232 2008-04-14] (Microsoft Corporation)
HKCU\...\Run: [Skype] - C:\Programme\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKCU\...\Run: [Pando Media Booster] - C:\Programme\Pando Networks\Media Booster\PMB.exe [4284976 2013-05-08] ()
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Programme\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Programme\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
Startup: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Startmenü\Programme\Autostart\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dsl-start.computerbild.de/
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
URLSearchHook: (No Name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programme\MyWebSearch\bar\2.bin\MWSSRCAS.DLL No File
URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
URLSearchHook: (No Name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File
SearchScopes: HKLM - DefaultScope {56256A51-B582-467e-B8D4-7786EDA79AE0} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKCU - DefaultScope {7AE9CEBA-FF1A-4AEB-9A6B-B33CDE12E4EC} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
SearchScopes: HKCU - {342E97D3-7BFF-4E4F-9D04-7E66D2D3A353} URL = hxxp://websearch.search-results.com/redirect?client=ie&tb=STC-SRS&o=41648033&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=96&apn_dtid=YYYYYYYYDE&apn_uid=C2E53CF7-93DF-428C-BD0F-5FE827EBC2BB&apn_sauid=3BDCAC75-8F2C-45D6-9FA0-4DAD0377E6A4&
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
SearchScopes: HKCU - {7AE9CEBA-FF1A-4AEB-9A6B-B33CDE12E4EC} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1561552
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Programme\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
BHO: CescrtHlpr Object - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Programme\facemoods.com\facemoods\1.4.17.8\bh\facemoods.dll (facemoods.com BHO)
BHO: No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Programme\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent)
BHO: Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: ICQ Sparberater - {FE163F11-1919-4257-A280-FF5AF8DAEECB} - C:\Programme\icq\Internet Explorer\icq.dll (solute gmbh)
Toolbar: HKLM - SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programme\MyWebSearch\bar\2.bin\MWSBAR.DLL No File
Toolbar: HKLM - No Name - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File
Toolbar: HKLM - Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Programme\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
Toolbar: HKLM - Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
Toolbar: HKLM - facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoodsTlbr.dll (facemoods.com)
Toolbar: HKLM - ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
Toolbar: HKCU -Search-Results Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
Toolbar: HKCU -SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: ipp - No CLSID Value -
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler: msdaipp - No CLSID Value -
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default
FF SelectedSearchEngine: Google
FF Homepage: user_pref("browser.startup.homepage", "");
FF Keyword.URL: hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNxpt158YYDE&ptnrS=ZNxpt158YYDE&si=216118&ptb=guIloz1OBjPIzKGO8EmpSg&ind=2010121709&n=77d005ed&psa=&st=kwd&searchfor=
FF NetworkProxy: "no_proxies_on", "localhost, 127.0.0.1, stealthy.co"
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Programme\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @bittorrent.com/BitTorrentDNA - C:\Programme\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Programme\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Programme\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Programme\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @mywebsearch.com/Plugin - C:\Programme\MyWebSearch\bar\2.bin\NPMyWebS.dll (MyWebSearch.com)
FF Plugin: @Nero.com/KM - C:\PROGRA~1\GEMEIN~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Programme\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Programme\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin-1.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin-2.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin-3.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin-4.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin-5.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin-6.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\icqplugin.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\mywebsearch.xml
FF SearchPlugin: C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\searchplugins\searchplugins-backup
FF Extension: No Name - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Microsoft .NET Framework Assistant - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: No Name - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\Extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: Hotspot Shield - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\Extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}
FF Extension: stealthyextension - C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Mozilla\Firefox\Profiles\9d29ab5w.default\Extensions\stealthyextension@gmail.com.xpi
FF Extension: Default - C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [m3ffxtbr@mywebsearch.com] C:\Programme\MyWebSearch\bar\2.bin
FF Extension: My Web Search - C:\Programme\MyWebSearch\bar\2.bin
FF HKLM\...\Firefox\Extensions: [jqs@sun.com] C:\Programme\Java\jre6\lib\deploy\jqs\ff
FF Extension: Java Quick Starter - C:\Programme\Java\jre6\lib\deploy\jqs\ff
FF StartMenuInternet: FIREFOX.EXE - F:\Programme\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR HKLM\...\Chrome\Extension: [ihflimipbcaljfnojhhknppphnnciiif] - C:\Programme\facemoods.com\facemoods\1.4.17.8\facemoods.crx
CHR StartMenuInternet: Google Chrome - "C:\Dokumente und Einstellungen\TEMP\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\chrome.exe"
========================== Services (Whitelisted) =================
R2 AVM WLAN Connection Service; C:\Programme\avmwlanstick\WlanNetService.exe [364544 2007-12-20] (AVM Berlin)
S2 gupdate; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
S3 gupdatem; C:\Programme\Google\Update\GoogleUpdate.exe [136176 2011-01-02] (Google Inc.)
R2 ICQ Service; C:\Programme\ICQ6Toolbar\ICQ Service.exe [247608 2010-11-21] ()
S3 iPod Service; C:\Programme\iPod\bin\iPodService.exe [820008 2010-11-17] (Apple Inc.)
S3 McComponentHostService; C:\Programme\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 MDM; C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE [322120 2006-06-01] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [115608 2013-04-10] (Mozilla Foundation)
S2 MyWebSearchService; C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe [28762 2011-03-25] (MyWebSearch.com)
R2 NAUpdate; C:\Programme\Nero\Update\NASvc.exe [690472 2011-07-22] (Nero AG)
S3 npggsvc; C:\WINDOWS\system32\GameMon.des [4023760 2010-12-01] (INCA Internet Co., Ltd.)
S3 ose; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [89136 2006-06-01] (Microsoft Corporation)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [161384 2013-02-28] (Skype Technologies)
R2 StealthInjectorService; C:\Programme\ArchiCrypt Stealth 4\IJStealth4Svc.exe [145920 2006-08-01] (Softwareentwicklung Remus)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-10-24] (Microsoft Corporation)
S3 AppMgmt; %SystemRoot%\System32\appmgmts.dll [x]
R2 JavaQuickStarterService; "C:\Programme\Java\jre6\bin\jqs.exe" -service -config "C:\Programme\Java\jre6\lib\deploy\jqs\jqs.conf" [x]
==================== Drivers (Whitelisted) ====================
S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-12-20] (AVM Berlin)
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-12-20] (AVM GmbH)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider)
R3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [18688 2001-08-17] (Microsoft Corporation)
R3 KMWDFILTER; C:\Windows\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
S3 NPPTNT2; C:\WINDOWS\system32\npptNT2.sys [4682 2004-12-30] (INCA Internet Co., Ltd.)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 RTLE8023xp; C:\Windows\System32\DRIVERS\Rtenicxp.sys [101504 2007-09-19] (Realtek Semiconductor Corporation )
R0 sfdrv01a; C:\Windows\System32\drivers\sfdrv01a.sys [63352 2006-07-05] (Protection Technology (StarForce))
R0 sfsync03; C:\Windows\System32\drivers\sfsync03.sys [35328 2005-12-06] (Protection Technology)
R0 sfsync04; C:\Windows\System32\drivers\sfsync04.sys [59776 2006-08-11] (Protection Technology (StarForce))
S3 taphss; C:\Windows\System32\DRIVERS\taphss.sys [33512 2012-11-08] (AnchorFree Inc)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
S3 cpuz134; \??\C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Temp\cpuz134\cpuz134_x32.sys [x]
S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [x]
S3 EagleXNt; \??\C:\WINDOWS\system32\drivers\EagleXNt.sys [x]
S4 IntelIde; No ImagePath
S3 USBAAPL; System32\Drivers\usbaapl.sys [x]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-21 17:14 - 2013-07-21 17:14 - 01219758 _____ (Farbar) C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\FRST.exe
2013-07-21 17:14 - 2013-07-21 17:14 - 01219758 _____ (Farbar) C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\FRST.exe
2013-07-20 18:46 - 2013-07-20 19:19 - 00000582 _____ C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-20 18:46 - 2013-07-20 18:46 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Malwarebytes
2013-07-20 18:45 - 2013-07-20 19:19 - 00000000 ____D C:\Programme\mb
2013-07-20 18:45 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-07-17 10:26 - 2013-07-17 11:38 - 00000000 ____D C:\FRST
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-16 23:57 - 2013-07-20 20:28 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-16 23:57 - 2013-07-17 08:54 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___RD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Startmenü
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Netzwerkumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ___HD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Druckumgebung
2013-07-16 23:57 - 2008-12-19 11:16 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\Desktop
2013-07-16 23:54 - 2013-07-16 23:54 - 00163060 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\2433f433
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:31 - 2013-07-11 03:32 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 01:44 - 2013-07-11 03:35 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 01:44 - 2013-07-11 03:34 - 00015045 _____ C:\WINDOWS\KB2845187.log
==================== One Month Modified Files and Folders =======
2013-07-21 17:14 - 2013-07-21 17:14 - 01219758 _____ (Farbar) C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\FRST.exe
2013-07-21 17:14 - 2013-07-21 17:14 - 01219758 _____ (Farbar) C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\FRST.exe
2013-07-21 17:14 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop
2013-07-21 17:14 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop
2013-07-21 17:11 - 2012-09-18 20:14 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Skype
2013-07-21 17:10 - 2011-09-22 19:41 - 00000416 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{2D336ACC-32A6-4A94-B047-3074AA51D08C}.job
2013-07-21 17:01 - 2011-08-28 03:23 - 00000224 _____ C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
2013-07-21 16:47 - 2013-06-11 21:47 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-21 16:36 - 2011-09-15 19:58 - 00001238 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004UA.job
2013-07-21 16:23 - 2011-01-02 21:04 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-21 15:55 - 2008-12-19 11:28 - 00032462 _____ C:\WINDOWS\SchedLgU.Txt
2013-07-21 15:07 - 2008-12-19 11:19 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-07-21 15:07 - 2008-12-19 11:19 - 00000050 _____ C:\WINDOWS\wiaservc.log
2013-07-21 15:06 - 2011-01-02 21:04 - 00001082 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-21 15:06 - 2008-12-19 12:46 - 00208477 _____ C:\WINDOWS\system32\nvapps.xml
2013-07-21 15:06 - 2008-12-19 11:28 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-21 04:08 - 2011-09-15 21:33 - 00000190 ___SH C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\ntuser.ini
2013-07-21 04:08 - 2011-09-15 21:33 - 00000190 ___SH C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\ntuser.ini
2013-07-21 04:08 - 2008-12-19 11:24 - 01673382 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-20 20:28 - 2013-07-16 23:57 - 00000190 ___SH C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\ntuser.ini
2013-07-20 19:19 - 2013-07-20 18:46 - 00000582 _____ C:\Dokumente und Einstellungen\All Users\Desktop\ Malwarebytes Anti-Malware .lnk
2013-07-20 19:19 - 2013-07-20 18:45 - 00000000 ____D C:\Programme\mb
2013-07-20 19:19 - 2008-12-24 02:02 - 00000000 ____D C:\Dokumente und Einstellungen\All Users\Desktop
2013-07-20 19:10 - 2008-12-19 11:17 - 00000000 ___RD C:\Programme
2013-07-20 18:46 - 2013-07-20 18:46 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\Malwarebytes
2013-07-19 13:20 - 2008-12-19 12:15 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-07-19 13:20 - 2008-12-19 12:15 - 00001024 ____H C:\WINDOWS\system32\config\userdiff.LOG
2013-07-19 13:19 - 2008-12-19 11:16 - 00001812 ____C C:\WINDOWS\regopt.log
2013-07-17 11:38 - 2013-07-17 10:26 - 00000000 ____D C:\FRST
2013-07-17 11:38 - 2011-09-15 21:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50
2013-07-17 09:05 - 2013-07-17 09:05 - 00000000 ____D C:\autostartsicherung
2013-07-17 08:54 - 2013-07-17 08:54 - 00000000 __SHD C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50\IETldCache
2013-07-17 08:54 - 2013-07-16 23:57 - 00000000 ____D C:\Dokumente und Einstellungen\Administrator.USER-A6BFC21F50
2013-07-16 23:55 - 2006-02-28 14:00 - 00013646 _____ C:\WINDOWS\system32\wpa.dbl
2013-07-16 23:54 - 2013-07-16 23:54 - 00163060 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\2433f433
2013-07-16 04:36 - 2011-09-15 19:58 - 00001186 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-2139871995-839522115-1004Core.job
2013-07-13 23:54 - 2011-09-16 18:32 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\ICQ
2013-07-13 04:40 - 2011-10-23 23:44 - 00002475 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\Google Chrome.lnk
2013-07-13 04:40 - 2011-10-23 23:44 - 00002475 _____ C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\Google Chrome.lnk
2013-07-12 18:43 - 2012-12-09 19:10 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\router_reconnect
2013-07-12 18:43 - 2012-12-09 19:10 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Desktop\router_reconnect
2013-07-11 22:57 - 2010-04-18 14:00 - 00000276 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2013-07-11 04:42 - 2011-09-15 21:32 - 00000000 __SHD C:\DOKUME~1\TEMP~1.USE\LOKALE~1\Verlauf
2013-07-11 04:41 - 2008-12-19 11:16 - 00294072 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-11 04:21 - 2009-10-05 17:06 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-07-11 03:35 - 2013-07-11 03:35 - 00010961 _____ C:\WINDOWS\KB2834886.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00010881 _____ C:\WINDOWS\KB2834904.log
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2850851$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834904_WM11$
2013-07-11 03:35 - 2013-07-11 03:35 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2834886$
2013-07-11 03:35 - 2013-07-11 01:44 - 00016274 _____ C:\WINDOWS\KB2850851.log
2013-07-11 03:35 - 2013-01-10 02:47 - 00194578 _____ C:\WINDOWS\setupapi.log
2013-07-11 03:35 - 2008-12-19 11:17 - 01921953 _____ C:\WINDOWS\FaxSetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00942003 _____ C:\WINDOWS\ocgen.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00741031 _____ C:\WINDOWS\tsoc.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00648976 _____ C:\WINDOWS\comsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00392944 _____ C:\WINDOWS\ntdtcsetup.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00304236 _____ C:\WINDOWS\iis6.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00106837 _____ C:\WINDOWS\ocmsn.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00096795 _____ C:\WINDOWS\msgsocm.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.log
2013-07-11 03:35 - 2008-12-19 11:17 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-07-11 03:34 - 2013-07-11 03:34 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2845187$
2013-07-11 03:34 - 2013-07-11 01:44 - 00015045 _____ C:\WINDOWS\KB2845187.log
2013-07-11 03:34 - 2008-12-19 11:17 - 00006516 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-11 03:32 - 2013-07-11 03:31 - 00013260 _____ C:\WINDOWS\KB2846071-IE8.log
2013-07-11 03:32 - 2008-12-19 16:02 - 00260975 _____ C:\WINDOWS\updspapi.log
2013-07-11 03:31 - 2009-08-15 21:58 - 00000000 ____D C:\WINDOWS\ie8updates
2013-07-11 03:01 - 2009-10-05 17:08 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2013-07-08 03:17 - 2012-10-08 20:38 - 00000000 ____D C:\Dokumente und Einstellungen\TEMP.USER-A6BFC21F50\Anwendungsdaten\TS3Client
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2006-02-28 14:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\Windows\System32\winlogon.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\Windows\System32\svchost.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\Windows\System32\services.exe
[2006-02-28 14:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\Windows\System32\User32.dll
[2006-02-28 14:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\Windows\System32\userinit.exe
[2006-02-28 14:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\Windows\System32\Drivers\volsnap.sys
[2006-02-28 14:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================
--- --- ---