|
Plagegeister aller Art und deren Bekämpfung: Problem: Internet Explorer Meldung getwindowinfoWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.07.2013, 10:22 | #16 |
| Problem: Internet Explorer Meldung getwindowinfo FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-07-2013 02 Ran by Judith at 2013-07-20 11:20:45 Running from C:\Users\Judith\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= AAVUpdateManager (Version: 18.00.0000) Acronis*True*Image*Home (Version: 10.0.4942) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) Agama Web Buttons Apple Application Support (Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (Version: 2.1.3.127) Ashampoo Burning Studio 2013 v.11.0.5 (Version: 11.0.5) Audacity 1.2.6 Audacity 1.3.6 (Unicode) Audials (Version: 10.1.509.900) Audiograbber 1.83 SE (Version: 1.83 SE) Avidemux 2.5 (Version: 2.5.1.5249) Avira Free Antivirus (Version: 13.0.0.3737) AVS Screen Capture version 2.0.2 AVS Update Manager 1.0 AVS Video Editor 6 AVS Video Recorder 2.5 AVS4YOU Software Navigator 1.4 Bonjour (Version: 3.0.0.10) capella 7 (Version: 7.1.6) CCleaner (Version: 3.25) CD- und DVD-Sharing (Version: 1.0.1.4) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) COMPUTERBILD-Cloud D3DX10 (Version: 15.4.2368.0902) Dell Resource CD (Version: 1.00.0000) DivxToDVD 0.5.2b (Version: 0.5.2b) Dropbox (HKCU Version: 2.2.8) DSL-Manager EclipseCrossword (Version: 1.2.57) ESET Online Scanner v3 FileZilla Client 3.6.0.2 (Version: 3.6.0.2) FormatFactory 2.50 (Version: 2.50) Forte Free 2.0 Free Audio CD Burner version 1.4.7 Free Studio version 2013 (Version: 6.1.3.622) Free Video to iPod Converter version 4.2.16.305 Free Video to JPG Converter version 1.5 Free Video to MP3 Converter version 3.2 Free YouTube Download 2.9 Free YouTube Download Manager (Version: 1.0.2.40) Free YouTube to iPod Converter version 3.2 Free YouTube to MP3 Converter version 3.11.34.1015 (Version: 3.11.34.1015) FreeMind (Version: 0.8.1) GIMP 2.6.12 (Version: 2.6.12) GOM Player (Version: 2.1.40.5106) Google Chrome (HKCU Version: 28.0.1500.72) Google Earth (Version: 6.2.0.5905) Google Talk Plugin (Version: 4.2.1.14031) Google Update Helper (Version: 1.3.21.153) Hervorhebe-Funktion (Windows Live Toolbar) (Version: 03.01.0146) HotPotatoes v 6.3.0.3 IcoFX 1.6.4 ICQ 8.0 (build 6014) (HKCU Version: 8.0.6014.0) ICQ Sparberater (Version: 1.4.9) IsoBuster 2.3 (Version: 2.3) iTunes (Version: 11.0.0.163) Japanese Fonts Support For Adobe Reader 9 (Version: 9.0.0) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Junk Mail filter update (Version: 15.4.3502.0922) MAGIX Foto Manager 10 (Version: 8.0.1.136) MAGIX Online Druck Service (Version: 3.4.3.0) MAGIX Screenshare (Version: 4.3.6.1987) MAGIX Xtreme Foto & Grafik Designer 5 (Silver) (Version: 5.1.2.15876) MediaDirect (Version: 4.7) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0) Microsoft Search Enhancement Pack (Version: 3.0.133.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Windows Media Video 9 VCM Microsoft XML Parser (Version: 8.0.7820.0) MindManager Smart (Version: 2.1.3) Mozilla Firefox 21.0 (x86 de) (Version: 21.0) Mozilla Maintenance Service (Version: 21.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) neroxml (Version: 1.0.0) No23 Recorder (Version: 2.1.0.3) Notepad++ (Version: 6.2.3) NVIDIA Drivers Octava SD4 (Version: 5.01) OpenOffice.org 3.1 (Version: 3.1.9399) OutlookAddinSetup (Version: 1.0.0) Paragon Partition Manager 2007 PDF24 Creator 5.2.0 PDFCreator (Version: 1.2.3) Pfadfinder 2.0 (Version: 1.0.7) Phase 5 HTML-Editor (Version: 5.6.2.3) Phoenix Backup Professional (Version: 3.5.000) PixiePack Codec Pack (Version: 1.1.400.0) Plus-HD-2.3 (Version: 1.27.153.8) QuickTime (Version: 7.72.80.56) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealPlayer (Version: 15.0.4) RealUpgrade 1.1 (Version: 1.1.0) River Past Video Cleaner Pro (Version: 7.7.7) Roxio Creator Audio (Version: 3.3.0) Roxio Creator Copy (Version: 3.3.0) Roxio Creator Data (Version: 3.3.0) Roxio Creator DE (Version: 3.3.0) Roxio Creator Tools (Version: 3.3.0) Roxio Drag-to-Disc (Version: 9.0) Roxio Express Labeler (Version: 2.1.0) Roxio MyDVD DE (Version: 9.0.117) Roxio Update Manager (Version: 3.0.0) Rund um (2.0) ... Erlebnis Biologie 1 RS (Version: 1.00.0000) Rund um (2.0) ... Erlebnis Chemie RP HE NI (Version: 1.00.0000) Rund um (2.0) ... Erlebnis Naturwissenschaften 5 RP (Version: 1.00.0000) Rund um ... Biologie heute entdecken 1 (Version: 1.00.0000) Rund um ... Biologie heute entdecken 2 (Teil 1) (Version: 1.00.0000) Rund um ... Biologie heute entdecken 2 (Teil 2) (Version: 1.00.0000) Segoe UI (Version: 15.4.2271.0615) Sicherheitsupdate für Windows Media Player (KB2845142) SigmaTel Audio (Version: 5.10.5210.0) Skype™ 6.5 (Version: 6.5.158) Smart Menus (Windows Live Toolbar) (Version: 03.01.0146) Sonic Activation Module (Version: 1.0) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0) Steuer-Spar-Erklärung 2011 (Version: 16.17) Steuer-Spar-Erklärung 2012 (Version: 17.02) Streambox Vcr Suite 2 SugarSync (Version: 2.0.27.114357) Sweet Home 3D version 3.7 Text-To-Speech-Runtime (Version: 1.0.0.0) Toxic Biohazard TubeBox (Version: 4.1.1.0) Ulead GIF Animator Lite Edition 1.0 Uninstall 1.0.0.1 Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) VirtualDJ Home FREE (Version: 7.0.5) VLC media player 2.0.7 (Version: 2.0.7) VoiceOver Kit (Version: 1.30.128.0) White Christmas 3D Screensaver and Animated Wallpaper 1.0 (Version: 1.0) WIDCOMM Bluetooth Software 6.0.1.3100 (Version: 6.0.1.3100) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Toolbar-Erweiterung (Windows Live Toolbar) (Version: 03.01.0146) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0) Windows Utils WinRAR archiver Wuala (HKCU Version: 1.0.428.0) Wuala CBFS (Version: 3.2.107.0) Wuala OverlayIcons (Version: 1.0.0.2) XMedia Recode 3.0.8.5 (Version: 3.0.8.5) ==================== Restore Points ========================= 09-07-2013 01:00:34 Windows Update 10-07-2013 19:33:20 Gerätetreiber-Paketinstallation: SugarSync 10-07-2013 19:43:57 Installed Java 7 Update 25 11-07-2013 12:13:12 Geplanter Prüfpunkt 13-07-2013 01:00:57 Windows Update 14-07-2013 19:50:22 Geplanter Prüfpunkt 15-07-2013 11:45:56 Geplanter Prüfpunkt 16-07-2013 09:23:01 Geplanter Prüfpunkt 16-07-2013 20:02:16 Windows Update 16-07-2013 21:05:28 Free YouTube Download Manager 17-07-2013 09:50:36 JavaFX 2.1.1 wird entfernt 17-07-2013 09:52:26 Removed LibreOffice 3.6 17-07-2013 22:00:04 Geplanter Prüfpunkt 19-07-2013 08:47:18 ComboFix created restore point 19-07-2013 08:49:20 ComboFix created restore point ==================== Hosts content: ========================== 2010-11-10 18:16 - 2013-07-19 11:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {07EFF3F8-57E9-4060-AC8B-63C03D320C8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0DF7E8C6-4CF7-4DE8-8BAA-516D9BB205F9} - System32\Tasks\EPUpdater => C:\Users\Judith\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File Task: {18BF61D8-8C4D-46C1-A397-EB7A6DC96E58} - System32\Tasks\{658EA475-F343-45E9-AF82-B67E5CDA0A49} => c:\program files\mozilla firefox\firefox.exe [2013-06-24] (Mozilla Corporation) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2461E8E9-EE40-4DBD-A19C-B63B76A58539} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {2DB895D9-D2FC-42EA-B3EF-22E6FC0EE2F5} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {36D7A5B8-4472-4F24-A887-D37F62033E77} - System32\Tasks\{1CCCC0B6-CFDB-4CC2-A42A-85FEE189240A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3C6D8EF0-298B-4F31-80A7-9F3D060DE516} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3758001449-3176424044-3867666295-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {3D5CB9AB-CBA4-4773-8496-A0BB1355C097} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {4692C054-BD6B-44FE-AC34-6E8EF7BED887} - System32\Tasks\Hoolapp Init => C:\Users\Judith\AppData\Roaming\HOOLAP~1\Hoolapp.exe No File Task: {521E92D9-3347-43B0-8FD9-81111C6875F5} - System32\Tasks\icqSWU => C:\Windows\System32\cscript.exe [2009-04-11] (Microsoft Corporation) Task: {5392E7AF-501E-42B5-9C13-F4F38D0AB0FA} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {54427084-6145-4C10-A6BE-3852819D9086} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-11-24] (Piriform Ltd) Task: {5EA3018C-5A19-4672-A5D9-1E6798A5DDB6} - System32\Tasks\Microsoft\Windows\RestartManager\{5A2F064A-6F7D-43b3-A3E7-66C404102C38} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {61858FB2-F17C-4365-A209-A1C513102D64} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation) Task: {6319641D-EF8F-47AB-8F8B-8686C8D0EF51} - System32\Tasks\Hoolapp For Android => C:\Users\Judith\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE No File Task: {6C51054D-758B-4BAD-86DD-53F1A46E3A90} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3758001449-3176424044-3867666295-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {8B3D2A13-BD5E-409A-B91D-4112FC8C84DF} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {937DE204-BC75-40F1-9F78-99C92C20A7F9} - System32\Tasks\{9FB8FE6B-80F2-4C6A-AF86-BBF69CEFAF15} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {9B411A20-1FFE-430A-9A15-1FEEBA8C6738} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-04] (Google Inc.) Task: {9CEB093B-75B3-4E5C-82E3-0F00F56EEF97} - System32\Tasks\Microsoft\Windows\RestartManager\{413EBFE5-7F85-4328-8E7F-EE0B67E7758A} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {9EBD668F-185F-49E8-A084-D7A3454DC025} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-04] (Google Inc.) Task: {A4B2B7F7-AD7A-4B6D-8012-7A293D2774E7} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Judith => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {A860C6A5-C081-4512-A41B-3CDA091A9F23} - System32\Tasks\User_Feed_Synchronization-{FFEC623E-F341-4E38-8943-ABB2B7D24138} => C:\Windows\system32\msfeedssync.exe [2013-05-29] (Microsoft Corporation) Task: {B15FE2B6-56A5-467A-83AD-9A5C39F49798} - \BrowserDefendert No Task File Task: {CA11AF58-3534-4B3A-B808-9E78362DCECC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-24] (Google Inc.) Task: {D0645CD6-D80F-4895-89A2-31762C52DF3B} - System32\Tasks\DSite => C:\Users\Judith\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File Task: {D36A0565-494E-4C1B-A28D-24EBCC2C4439} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DB14B352-D4C4-4BEA-81ED-DC36F12E827B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-24] (Google Inc.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core.job => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA.job => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{FFEC623E-F341-4E38-8943-ABB2B7D24138}.job => C:\Windows\system32\msfeedssync.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter #6 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Bluetooth Peripheral Device Description: Bluetooth Peripheral Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth Peripheral Device Description: Bluetooth Peripheral Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/19/2013 02:47:06 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2028 Error: (07/19/2013 02:47:06 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2028 Error: (07/19/2013 02:47:06 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/19/2013 02:47:05 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1029 Error: (07/19/2013 02:47:05 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1029 Error: (07/19/2013 02:47:05 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/19/2013 01:51:05 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6240 Error: (07/19/2013 01:51:05 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6240 Error: (07/19/2013 01:51:05 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/19/2013 01:51:04 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5195 System errors: ============= Error: (07/20/2013 10:58:25 AM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (07/20/2013 00:33:28 AM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (07/20/2013 00:30:25 AM) (Source: DCOM) (User: ) Description: {6295DF2D-35EE-11D1-8707-00C04FD93327} Error: (07/19/2013 05:33:20 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/19/2013 03:20:45 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/19/2013 02:19:47 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/19/2013 02:10:25 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Microsoft Office Sessions: ========================= Error: (07/19/2013 02:47:06 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2028 Error: (07/19/2013 02:47:06 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2028 Error: (07/19/2013 02:47:06 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/19/2013 02:47:05 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1029 Error: (07/19/2013 02:47:05 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1029 Error: (07/19/2013 02:47:05 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/19/2013 01:51:05 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6240 Error: (07/19/2013 01:51:05 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6240 Error: (07/19/2013 01:51:05 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (07/19/2013 01:51:04 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5195 CodeIntegrity Errors: =================================== Date: 2013-07-17 15:37:59.555 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:59.226 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.844 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.504 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.177 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:57.840 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-30 16:54:35.531 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-04 17:06:43.935 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-04 17:06:43.628 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-04 17:06:43.232 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 74% Total physical RAM: 2045.31 MB Available physical RAM: 518.38 MB Total Pagefile: 4327.88 MB Available Pagefile: 2835.47 MB Total Virtual: 2047.88 MB Available Virtual: 1886.77 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:99.88 GB) (Free:29.04 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive j: (Samsung Festplatte neu) (Fixed) (Total:931.51 GB) (Free:617.61 GB) NTFS Drive m: (Daten) (Fixed) (Total:130.95 GB) (Free:4.26 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 00000080) Partition 1: (Not Active) - (Size=47 MB) - (Type=DE) Partition 2: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=133 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 54349CA3) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Das Problem ist leider immer noch vorhanden. |
20.07.2013, 10:51 | #17 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Adobe, Firefox und Windows inkl. IE updaten.
__________________Kannst mir nen Screenshot davon zeigen?
__________________ |
20.07.2013, 11:52 | #18 |
| Problem: Internet Explorer Meldung getwindowinfo Von was magst du bitte einen screenshot?
__________________Problem ist, ich hatte irgendwann mal den IE deinstalliert und kann ihn jetzt nicht mehr installieren. Bei den anderen Sachen versuche ich mal ein update. Danke für deine Hilfe ! Was meinst du mit Windows updaten? Sollte ich das System ganz neu aufspielen? IE kann ich nicht installieren |
20.07.2013, 12:07 | #19 |
| Problem: Internet Explorer Meldung getwindowinfo Hier ein Screenshot, ich hoffe du hast das gemeint |
20.07.2013, 15:09 | #20 |
| Problem: Internet Explorer Meldung getwindowinfo Hier noch ein Ergebnis: |
20.07.2013, 15:10 | #21 |
| Problem: Internet Explorer Meldung getwindowinfo Wie soll ich diese entfernen? Einfach löschen? |
20.07.2013, 17:42 | #22 |
| Problem: Internet Explorer Meldung getwindowinfo Jetzt geht gar nichts mehr :-( Ich fahre den PC hoch er lädt alle Programme und fährt dann automatisch wieder runter. Was mache ich denn jetzt? |
20.07.2013, 20:11 | #23 | |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Was genau treibst Du da? Immer nur das machen was ich sage. Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.07.2013, 17:01 | #24 |
| Problem: Internet Explorer Meldung getwindowinfo Okay ich halte mich in Zukunft daran. Ich war deprimiert, dass es einfach nicht gehen will. Der abgesicherte Modus geht ja. Was soll ich machen? |
21.07.2013, 21:06 | #25 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Ein FRST Log aus dem abgesicherten Modus bitte
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2013, 09:12 | #26 |
| Problem: Internet Explorer Meldung getwindowinfoFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2013 02 Ran by Judith (administrator) on 22-07-2013 09:54:24 Running from C:\Users\Judith\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Safe Mode (minimal) ==================== Processes (Whitelisted) =================== (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== Lsa: [Authentication Packages] msv1_0 relog_ap ed) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [49664 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [ICQ] - C:\Users\Judith\AppData\Roaming\ICQM\icq.exe [27598184 2013-04-10] (ICQ) HKCU\...\Run: [COMPUTERBILD-Cloud] - C:\Program Files\COMPUTERBILD-Cloud\CGCClient.exe [1781840 2012-08-08] () HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.) HKCU\...\Run: [SugarSync] - C:\Program Files\SugarSync\SugarSync.exe [12419424 2013-06-26] (SugarSync, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\T-Online\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\T-Online\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Judith\AppData\Local\Windows\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Judith\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Judith\AppData\Local\Windows\net.lnk ShortcutTarget: net.lnk -> C:\Users\Judith\AppData\Roaming\Windows Net Data\net.exe (Windows Net) SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {752A9793-46C2-4927-9DCE-8FD9351F6B79} URL = hxxp://www.google.de/search?q={searchTerms} BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: ICQ Sparberater - {E2B5568A-B3BC-49D6-9BEA-4A549AA1E01E} - C:\Program Files\icq\Internet Explorer\icq.dll () Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File Toolbar: HKCU -No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File Toolbar: HKCU -No Name - {00000000-0000-0000-0000-000000000000} - No File Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Judith\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Judith\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-13.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-14.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-15.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-16.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\foxsearch.src FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com FF Extension: ICQ Sparberater - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\ciuvo-extension@icq.de FF Extension: ReminderFox - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} FF Extension: NoiaFoxoption - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKCU\...\Firefox\Extensions: [{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46}] C:\Users\Judith\AppData\Local\{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46} FF Extension: XULRunner - C:\Users\Judith\AppData\Local\{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46} Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (Google Talk Plugin) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.16) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0 ========================== Services (Whitelisted) ================= S2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [411168 2007-02-16] (Acronis) S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-20] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-20] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-06-20] (Avira Operations GmbH & Co. KG) S2 DokanMounter; C:\Program Files\COMPUTERBILD-Cloud\Data\Tools\mounter.exe [14848 2012-02-15] () S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 TDslMgrService; C:\Program Files\T-Online\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) S3 UPnPService; C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) ==================== Drivers (Whitelisted) ==================== S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26080 2012-10-08] (Wondershare) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-06-20] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-06-20] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) S1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [299024 2012-04-09] (EldoS Corporation) S2 Dokan; C:\Windows\system32\drivers\dokan.sys [95744 2012-02-15] (Windows (R) Win 7 DDK provider) S1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R0 hotcore3; C:\Windows\System32\drivers\hotcore3.sys [39472 2007-08-21] (Paragon Software Group) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-07-20] (Malwarebytes Corporation) S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2012-12-12] (RapidSolution Software AG) S3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2012-12-12] (RapidSolution Software AG) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-01-10] (Duplex Secure Ltd.) S3 SSCBFS3; C:\Windows\System32\DRIVERS\sscbfs3.sys [295936 2013-01-30] (EldoS Corporation) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [31360 2012-07-20] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) S3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [39048 2012-12-12] (RapidSolution Software AG) S2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [32768 2008-12-13] (Acronis) S3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) S2 {2E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}; C:\Program Files\Dell\MediaDirect\000.fcl [13560 2007-04-02] (Cyberlink Corp.) S3 ActivHidSerMini; system32\DRIVERS\activhidsermini.sys [x] S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S4 IpInIp; system32\DRIVERS\ipinip.sys [x] S4 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S4 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 prmvmouse; system32\DRIVERS\activmouse.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-22 09:42 - 2013-07-22 09:42 - 00143624 _____ C:\Windows\Minidump\Mini072213-01.dmp 2013-07-20 20:20 - 2013-07-20 20:21 - 00143624 _____ C:\Windows\Minidump\Mini072013-11.dmp 2013-07-20 20:13 - 2013-07-20 20:13 - 00143624 _____ C:\Windows\Minidump\Mini072013-10.dmp 2013-07-20 20:07 - 2013-07-20 20:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-09.dmp 2013-07-20 19:15 - 2013-07-20 19:15 - 00143624 _____ C:\Windows\Minidump\Mini072013-08.dmp 2013-07-20 19:07 - 2013-07-20 19:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-07.dmp 2013-07-20 19:00 - 2013-07-20 19:00 - 00143624 _____ C:\Windows\Minidump\Mini072013-06.dmp 2013-07-20 18:26 - 2013-07-20 18:27 - 00143624 _____ C:\Windows\Minidump\Mini072013-05.dmp 2013-07-20 18:20 - 2013-07-20 18:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-04.dmp 2013-07-20 18:14 - 2013-07-20 18:14 - 00143624 _____ C:\Windows\Minidump\Mini072013-03.dmp 2013-07-20 18:04 - 2013-07-20 18:06 - 00001885 _____ C:\AdwCleaner[S3].txt 2013-07-20 17:50 - 2013-07-20 17:51 - 00143624 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 17:44 - 2013-07-20 17:44 - 00143624 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 17:43 - 2013-07-22 09:41 - 219110943 _____ C:\Windows\MEMORY.DMP 2013-07-20 13:13 - 2013-07-20 13:13 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-20 13:10 - 2013-07-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Judith\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-20 13:09 - 2013-07-20 13:09 - 00602112 _____ (OldTimer Tools) C:\Users\Judith\Downloads\OTL.exe 2013-07-20 12:48 - 2013-07-20 12:52 - 00004974 _____ C:\Windows\ie8_main.log 2013-07-20 12:48 - 2013-07-20 12:48 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-20 12:45 - 2013-07-20 12:46 - 14938992 _____ (Microsoft Corporation) C:\Users\Judith\Downloads\IE8-WindowsVista-x86-DEU.exe 2013-07-20 12:45 - 2013-07-20 12:45 - 21703480 _____ (Mozilla) C:\Users\Judith\Downloads\Firefox_Setup_22.0.exe 2013-07-19 17:45 - 2013-07-19 17:45 - 00000000 ____D C:\Program Files\ESET 2013-07-19 17:45 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Desktop\SecurityCheck.exe 2013-07-19 17:34 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Downloads\SecurityCheck.exe 2013-07-19 17:33 - 2013-07-19 17:33 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu (1).exe 2013-07-19 15:22 - 2013-07-19 15:22 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu.exe 2013-07-19 13:26 - 2013-07-20 11:21 - 00026743 _____ C:\Users\Judith\Downloads\Addition.txt 2013-07-19 13:23 - 2013-07-19 13:23 - 00003328 _____ C:\Users\Judith\Desktop\JRT.txt 2013-07-19 12:03 - 2013-07-19 12:03 - 00000000 ____D C:\Windows\ERUNT 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Downloads\JRT.exe 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Desktop\JRT.exe 2013-07-19 11:50 - 2013-07-19 11:52 - 00011518 _____ C:\AdwCleaner[S2].txt 2013-07-19 11:50 - 2013-07-19 11:52 - 00000098 _____ C:\Windows\DeleteOnReboot.bat 2013-07-19 11:50 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Desktop\adwcleaner2305.exe 2013-07-19 11:18 - 2013-07-19 11:18 - 00030260 _____ C:\ComboFix.txt 2013-07-19 10:47 - 2013-07-19 10:45 - 05091168 ____R (Swearware) C:\Users\Judith\Desktop\ComboFix.exe 2013-07-19 10:47 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-19 10:47 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-19 10:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-19 10:46 - 2013-07-19 11:18 - 00000000 ____D C:\Qoobox 2013-07-19 10:45 - 2013-07-19 11:15 - 00000000 ____D C:\Windows\erdnt 2013-07-19 10:44 - 2013-07-19 10:45 - 05091168 ____R (Swearware) C:\Users\Judith\Downloads\ComboFix.exe 2013-07-18 19:58 - 2013-07-18 19:58 - 00000000 ____D C:\FRST 2013-07-18 19:56 - 2013-07-18 19:56 - 01218860 _____ (Farbar) C:\Users\Judith\Downloads\FRST.exe 2013-07-18 19:53 - 2013-07-18 19:53 - 00000000 ____D C:\Users\Judith\Qtrax 2013-07-18 19:48 - 2013-07-18 19:48 - 00793536 _____ C:\Users\Judith\Downloads\ZipOpenerSetup.exe 2013-07-18 17:13 - 2013-07-18 17:14 - 00033686 _____ C:\AdwCleaner[S1].txt 2013-07-18 17:12 - 2013-07-18 17:12 - 00033720 _____ C:\AdwCleaner[R1].txt 2013-07-18 17:11 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Downloads\adwcleaner2305.exe 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setuperr.log 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setupact.log 2013-07-17 12:22 - 2013-07-20 17:38 - 00006232 _____ C:\Windows\PFRO.log 2013-07-16 23:17 - 2013-07-18 16:41 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-07-16 23:16 - 2013-07-17 12:29 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Windows Net Data 2013-07-16 23:15 - 2013-06-27 07:14 - 00031816 _____ C:\Windows\Launcher.exe 2013-07-16 23:04 - 2013-07-16 23:04 - 00000000 ____D C:\Users\Judith\AppData\Local\Software Updater 2013-07-16 22:03 - 2013-07-16 22:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-16 20:10 - 2013-07-16 20:10 - 00283168 _____ C:\Users\Judith\Downloads\Setup (1).exe 2013-07-16 14:35 - 2013-07-16 14:35 - 00895488 _____ M:\Dokumente\Visitenkarten.doc 2013-07-13 03:25 - 2013-07-13 03:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2845142_WM64$ 2013-07-13 03:25 - 2007-07-27 10:41 - 00016760 ____N (Microsoft Corporation) C:\Windows\system32\spmsg.dll 2013-07-12 16:40 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-12 16:39 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-12 16:39 - 2013-05-29 13:30 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 16:39 - 2013-05-29 13:30 - 00916480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 16:39 - 2013-05-29 13:30 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-12 16:39 - 2013-05-29 13:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 06016000 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-12 16:39 - 2013-05-29 13:24 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-12 16:39 - 2013-05-29 11:47 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-12 16:39 - 2013-05-29 10:07 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-12 16:39 - 2013-05-29 10:06 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-12 16:39 - 2013-05-29 10:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-12 16:39 - 2013-05-29 10:04 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 16:39 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-12 16:39 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-12 16:39 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-12 16:39 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-12 16:39 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-12 16:39 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-12 16:38 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 21:53 - 2013-07-10 21:53 - 00024064 _____ M:\Dokumente\Windows Phone Store.doc 2013-07-10 21:51 - 2013-07-10 21:51 - 00000840 _____ C:\Users\Judith\Desktop\Wuala.lnk 2013-07-10 21:48 - 2013-07-21 10:43 - 00000000 ___RD C:\Users\Judith\Dropbox 2013-07-10 21:48 - 2013-07-10 21:48 - 00000992 _____ C:\Users\Judith\Desktop\Dropbox.lnk 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala OverlayIcons 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala CBFS 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-10 21:47 - 2013-07-10 21:45 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-10 21:47 - 2012-04-09 16:27 - 00299024 _____ (EldoS Corporation) C:\Windows\system32\Drivers\cbfs3.sys 2013-07-10 21:47 - 2012-04-09 16:27 - 00223760 _____ (EldoS Corporation) C:\Windows\system32\CbFsNetRdr3.dll 2013-07-10 21:47 - 2012-04-09 16:27 - 00158224 _____ (EldoS Corporation) C:\Windows\system32\CbFsMntNtf3.dll 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-10 21:44 - 2013-07-10 21:44 - 00000000 ____D C:\Program Files\Dropbox 2013-07-10 21:43 - 2013-07-10 21:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-10 21:40 - 2013-07-21 10:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Dropbox 2013-07-10 21:39 - 2013-07-10 21:40 - 33578320 _____ (Dropbox, Inc.) C:\Users\Judith\Downloads\Dropbox 2.2.8.exe 2013-07-10 21:38 - 2013-07-10 21:38 - 00000000 ____D M:\Dokumente\Mein SugarSync 2013-07-10 21:36 - 2013-07-10 21:38 - 00000000 ____D C:\Users\Judith\AppData\Local\SugarSync 2013-07-10 21:35 - 2013-07-10 21:35 - 00001692 _____ C:\Users\Public\Desktop\SugarSync.lnk 2013-07-10 21:35 - 2013-01-30 13:12 - 00225024 _____ (EldoS Corporation) C:\Windows\system32\SSCbFsNetRdr3.dll 2013-07-10 21:35 - 2013-01-30 13:12 - 00159488 _____ (EldoS Corporation) C:\Windows\system32\SSCbFsMntNtf3.dll 2013-07-10 21:33 - 2013-07-10 21:42 - 00000828 _____ C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wuala.lnk 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Wuala 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Local\Wuala 2013-07-10 21:33 - 2013-01-30 13:11 - 00295936 _____ (EldoS Corporation) C:\Windows\system32\Drivers\sscbfs3.sys 2013-07-10 21:32 - 2013-07-10 21:35 - 00000000 ____D C:\Program Files\SugarSync 2013-07-10 21:29 - 2013-07-10 21:29 - 22964952 _____ C:\Users\Judith\Downloads\WualaSetup_04_13.exe 2013-07-10 21:27 - 2013-07-10 21:28 - 20911672 _____ (SugarSync, Inc.) C:\Users\Judith\Downloads\SugarSyncSetup_2.0.27.exe 2013-07-07 21:25 - 2013-07-07 21:25 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00001853 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\ProgramData\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\Program Files\Avira 2013-07-07 21:21 - 2013-06-20 14:48 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-07 21:21 - 2013-03-06 16:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-07 21:21 - 2012-08-27 15:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-07 21:04 - 2013-07-07 21:06 - 104943936 _____ C:\Users\Judith\Downloads\avira3737_free_antivirus_de.exe 2013-07-01 18:20 - 2013-07-01 18:20 - 00005384 _____ C:\Users\Judith\Downloads\Mundharmonika+Noten.htm (7).html 2013-06-28 11:52 - 2013-06-28 11:52 - 00000865 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-06-28 11:50 - 2013-06-28 11:51 - 22937227 _____ C:\Users\Judith\Downloads\vlc-2.0.7-win32.exe 2013-06-24 18:21 - 2013-06-24 18:21 - 00024064 _____ M:\Dokumente\Schreib-ab homepage.doc 2013-06-24 17:53 - 2013-07-20 12:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-06-24 17:25 - 2013-06-24 17:25 - 00001038 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-06-24 12:29 - 2013-06-24 12:29 - 00017196 _____ C:\Users\Judith\.recently-used.xbel ==================== One Month Modified Files and Folders ======= 2013-07-22 09:42 - 2013-07-22 09:42 - 00143624 _____ C:\Windows\Minidump\Mini072213-01.dmp 2013-07-22 09:42 - 2012-02-13 21:18 - 00000000 ____D C:\Windows\Minidump 2013-07-22 09:42 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-22 09:42 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-22 09:42 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-22 09:41 - 2013-07-20 17:43 - 219110943 _____ C:\Windows\MEMORY.DMP 2013-07-21 10:43 - 2013-07-10 21:48 - 00000000 ___RD C:\Users\Judith\Dropbox 2013-07-21 10:43 - 2013-07-10 21:40 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Dropbox 2013-07-21 10:40 - 2012-03-04 13:19 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 20:21 - 2013-07-20 20:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-11.dmp 2013-07-20 20:19 - 2012-11-28 17:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-20 20:13 - 2013-07-20 20:13 - 00143624 _____ C:\Windows\Minidump\Mini072013-10.dmp 2013-07-20 20:11 - 2012-03-04 13:20 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 20:09 - 2012-11-24 15:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA.job 2013-07-20 20:07 - 2013-07-20 20:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-09.dmp 2013-07-20 19:15 - 2013-07-20 19:15 - 00143624 _____ C:\Windows\Minidump\Mini072013-08.dmp 2013-07-20 19:07 - 2013-07-20 19:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-07.dmp 2013-07-20 19:00 - 2013-07-20 19:00 - 00143624 _____ C:\Windows\Minidump\Mini072013-06.dmp 2013-07-20 18:52 - 2008-12-13 16:15 - 00000000 ____D M:\Dokumente\Programme 2013-07-20 18:27 - 2013-07-20 18:26 - 00143624 _____ C:\Windows\Minidump\Mini072013-05.dmp 2013-07-20 18:20 - 2013-07-20 18:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-04.dmp 2013-07-20 18:14 - 2013-07-20 18:14 - 00143624 _____ C:\Windows\Minidump\Mini072013-03.dmp 2013-07-20 18:12 - 2012-12-10 21:35 - 00000000 ____D C:\Users\Judith\AppData\Roaming\COMPUTERBILD Cloud 2013-07-20 18:07 - 2010-05-25 18:16 - 00008524 _____ C:\Windows\bthservsdp.dat 2013-07-20 18:07 - 2006-11-02 15:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-20 18:07 - 2006-11-02 14:52 - 01287636 _____ C:\Windows\WindowsUpdate.log 2013-07-20 18:06 - 2013-07-20 18:04 - 00001885 _____ C:\AdwCleaner[S3].txt 2013-07-20 17:59 - 2009-10-26 21:40 - 00000000 ____D C:\Users\Judith\Downloads\USB Stick grau 1 2013-07-20 17:51 - 2013-07-20 17:50 - 00143624 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 17:44 - 2013-07-20 17:44 - 00143624 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 17:38 - 2013-07-17 12:22 - 00006232 _____ C:\Windows\PFRO.log 2013-07-20 17:38 - 2012-04-27 17:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-20 17:34 - 2011-07-22 18:56 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Skype 2013-07-20 13:16 - 2010-10-13 15:12 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-07-20 13:13 - 2013-07-20 13:13 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-20 13:13 - 2010-10-13 15:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-20 13:13 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-20 13:10 - 2013-07-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Judith\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-20 13:09 - 2013-07-20 13:09 - 00602112 _____ (OldTimer Tools) C:\Users\Judith\Downloads\OTL.exe 2013-07-20 12:52 - 2013-07-20 12:48 - 00004974 _____ C:\Windows\ie8_main.log 2013-07-20 12:50 - 2008-12-13 11:46 - 00000000 ____D C:\Users\Judith\AppData\Local\Adobe 2013-07-20 12:48 - 2013-07-20 12:48 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-20 12:48 - 2013-06-24 17:53 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 12:46 - 2013-07-20 12:45 - 14938992 _____ (Microsoft Corporation) C:\Users\Judith\Downloads\IE8-WindowsVista-x86-DEU.exe 2013-07-20 12:45 - 2013-07-20 12:45 - 21703480 _____ (Mozilla) C:\Users\Judith\Downloads\Firefox_Setup_22.0.exe 2013-07-20 11:48 - 2006-11-02 12:33 - 01560022 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-20 11:47 - 2012-12-10 21:36 - 00000000 __SHD C:\Users\Judith\wc 2013-07-20 11:45 - 2008-12-10 20:46 - 00183296 _____ C:\Users\Judith\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-20 11:43 - 2006-11-02 14:47 - 00530840 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-20 11:39 - 2008-12-10 20:45 - 00000000 ___RD C:\Users\Judith\Desktop 2013-07-20 11:34 - 2009-01-05 14:33 - 00027430 _____ C:\Users\Judith\AppData\Roaming\nvModes.001 2013-07-20 11:32 - 2013-02-17 16:41 - 00000000 ____D C:\Program Files\Freetec 2013-07-20 11:32 - 2013-02-17 16:39 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-20 11:31 - 2012-01-09 17:23 - 00000000 ____D M:\Dokumente\VirtualDJ 2013-07-20 11:30 - 2009-01-10 19:23 - 00000000 ____D C:\Program Files\OpenOffice.org 3 2013-07-20 11:21 - 2013-07-19 13:26 - 00026743 _____ C:\Users\Judith\Downloads\Addition.txt 2013-07-19 17:45 - 2013-07-19 17:45 - 00000000 ____D C:\Program Files\ESET 2013-07-19 17:34 - 2013-07-19 17:45 - 00891062 _____ C:\Users\Judith\Desktop\SecurityCheck.exe 2013-07-19 17:34 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Downloads\SecurityCheck.exe 2013-07-19 17:33 - 2013-07-19 17:33 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu (1).exe 2013-07-19 15:22 - 2013-07-19 15:22 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu.exe 2013-07-19 13:23 - 2013-07-19 13:23 - 00003328 _____ C:\Users\Judith\Desktop\JRT.txt 2013-07-19 12:03 - 2013-07-19 12:03 - 00000000 ____D C:\Windows\ERUNT 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Downloads\JRT.exe 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Desktop\JRT.exe 2013-07-19 11:52 - 2013-07-19 11:50 - 00011518 _____ C:\AdwCleaner[S2].txt 2013-07-19 11:52 - 2013-07-19 11:50 - 00000098 _____ C:\Windows\DeleteOnReboot.bat 2013-07-19 11:18 - 2013-07-19 11:18 - 00030260 _____ C:\ComboFix.txt 2013-07-19 11:18 - 2013-07-19 10:46 - 00000000 ____D C:\Qoobox 2013-07-19 11:18 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-07-19 11:18 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-19 11:15 - 2013-07-19 10:45 - 00000000 ____D C:\Windows\erdnt 2013-07-19 11:09 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-07-19 11:07 - 2006-11-02 12:22 - 59244544 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 45350912 _____ C:\Windows\system32\config\COMPON~2.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 24903680 _____ C:\Windows\system32\config\SYSTEM.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00786432 _____ C:\Windows\system32\config\DEFAULT.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-07-19 11:04 - 2008-12-10 20:45 - 00000000 ____D C:\Users\Judith 2013-07-19 10:45 - 2013-07-19 10:47 - 05091168 ____R (Swearware) C:\Users\Judith\Desktop\ComboFix.exe 2013-07-19 10:45 - 2013-07-19 10:44 - 05091168 ____R (Swearware) C:\Users\Judith\Downloads\ComboFix.exe 2013-07-18 19:58 - 2013-07-18 19:58 - 00000000 ____D C:\FRST 2013-07-18 19:56 - 2013-07-18 19:56 - 01218860 _____ (Farbar) C:\Users\Judith\Downloads\FRST.exe 2013-07-18 19:53 - 2013-07-18 19:53 - 00000000 ____D C:\Users\Judith\Qtrax 2013-07-18 19:48 - 2013-07-18 19:48 - 00793536 _____ C:\Users\Judith\Downloads\ZipOpenerSetup.exe 2013-07-18 17:14 - 2013-07-18 17:13 - 00033686 _____ C:\AdwCleaner[S1].txt 2013-07-18 17:13 - 2008-12-13 19:22 - 00000000 ____D C:\ProgramData\ICQ 2013-07-18 17:13 - 2008-12-13 13:43 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-18 17:12 - 2013-07-18 17:12 - 00033720 _____ C:\AdwCleaner[R1].txt 2013-07-18 17:11 - 2013-07-19 11:50 - 00662345 _____ C:\Users\Judith\Desktop\adwcleaner2305.exe 2013-07-18 17:11 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Downloads\adwcleaner2305.exe 2013-07-18 16:41 - 2013-07-16 23:17 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-07-18 14:38 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setuperr.log 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setupact.log 2013-07-18 03:09 - 2012-11-24 15:33 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core.job 2013-07-17 14:02 - 2008-12-13 19:48 - 00000000 ____D M:\Dokumente\Sicherung 2013-07-17 12:29 - 2013-07-16 23:16 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Windows Net Data 2013-07-17 12:06 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\ShellNew 2013-07-17 11:49 - 2011-11-22 19:00 - 00000000 ____D C:\Program Files\DsNET Corp 2013-07-16 23:16 - 2010-12-19 20:32 - 00000000 ___HD C:\Users\Judith\AppData\Local\Windows 2013-07-16 23:04 - 2013-07-16 23:04 - 00000000 ____D C:\Users\Judith\AppData\Local\Software Updater 2013-07-16 22:06 - 2013-07-16 22:03 - 00000000 ____D C:\Windows\system32\MRT 2013-07-16 20:10 - 2013-07-16 20:10 - 00283168 _____ C:\Users\Judith\Downloads\Setup (1).exe 2013-07-16 14:35 - 2013-07-16 14:35 - 00895488 _____ M:\Dokumente\Visitenkarten.doc 2013-07-16 12:14 - 2008-12-13 12:30 - 00002637 _____ C:\Users\Judith\Desktop\Microsoft Office Word 2003.lnk 2013-07-14 20:33 - 2012-01-20 19:03 - 00000000 ____D M:\Dokumente\Handys N97 Galaxy Ace 2013-07-13 04:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-13 03:48 - 2008-12-13 12:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-13 03:47 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-13 03:25 - 2013-07-13 03:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2845142_WM64$ 2013-07-13 03:02 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 09:31 - 2008-12-13 12:53 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Mozilla 2013-07-10 21:53 - 2013-07-10 21:53 - 00024064 _____ M:\Dokumente\Windows Phone Store.doc 2013-07-10 21:51 - 2013-07-10 21:51 - 00000840 _____ C:\Users\Judith\Desktop\Wuala.lnk 2013-07-10 21:48 - 2013-07-10 21:48 - 00000992 _____ C:\Users\Judith\Desktop\Dropbox.lnk 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala OverlayIcons 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala CBFS 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-10 21:45 - 2013-07-10 21:47 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-10 21:45 - 2012-06-30 12:00 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-10 21:45 - 2011-12-22 15:59 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-10 21:44 - 2013-07-10 21:44 - 00000000 ____D C:\Program Files\Dropbox 2013-07-10 21:43 - 2013-07-10 21:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-10 21:42 - 2013-07-10 21:33 - 00000828 _____ C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wuala.lnk 2013-07-10 21:40 - 2013-07-10 21:39 - 33578320 _____ (Dropbox, Inc.) C:\Users\Judith\Downloads\Dropbox 2.2.8.exe 2013-07-10 21:40 - 2010-02-17 17:02 - 00039424 _____ M:\Dokumente\mailaccounts community Free sms accounts.doc 2013-07-10 21:38 - 2013-07-10 21:38 - 00000000 ____D M:\Dokumente\Mein SugarSync 2013-07-10 21:38 - 2013-07-10 21:36 - 00000000 ____D C:\Users\Judith\AppData\Local\SugarSync 2013-07-10 21:35 - 2013-07-10 21:35 - 00001692 _____ C:\Users\Public\Desktop\SugarSync.lnk 2013-07-10 21:35 - 2013-07-10 21:32 - 00000000 ____D C:\Program Files\SugarSync 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Wuala 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Local\Wuala 2013-07-10 21:29 - 2013-07-10 21:29 - 22964952 _____ C:\Users\Judith\Downloads\WualaSetup_04_13.exe 2013-07-10 21:28 - 2013-07-10 21:27 - 20911672 _____ (SugarSync, Inc.) C:\Users\Judith\Downloads\SugarSyncSetup_2.0.27.exe 2013-07-07 21:25 - 2013-07-07 21:25 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00001853 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\ProgramData\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\Program Files\Avira 2013-07-07 21:06 - 2013-07-07 21:04 - 104943936 _____ C:\Users\Judith\Downloads\avira3737_free_antivirus_de.exe 2013-07-06 17:47 - 2012-08-30 13:55 - 00000000 ____D C:\Users\Judith\AppData\Roaming\vlc 2013-07-06 15:41 - 2010-01-15 17:53 - 00000000 ____D C:\Users\Judith\AppData\Roaming\dvdcss 2013-07-01 19:15 - 2008-12-13 16:17 - 00000000 ____D M:\Dokumente\Allerlei 2013-07-01 18:20 - 2013-07-01 18:20 - 00005384 _____ C:\Users\Judith\Downloads\Mundharmonika+Noten.htm (7).html 2013-06-28 15:16 - 2008-12-13 18:22 - 00074752 _____ C:\Users\Judith\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-06-28 11:52 - 2013-06-28 11:52 - 00000865 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-06-28 11:51 - 2013-06-28 11:50 - 22937227 _____ C:\Users\Judith\Downloads\vlc-2.0.7-win32.exe 2013-06-27 14:47 - 2013-04-01 16:03 - 00000000 ____D M:\Dokumente\Flug USA Herbst 2013 2013-06-27 07:14 - 2013-07-16 23:15 - 00031816 _____ C:\Windows\Launcher.exe 2013-06-24 18:23 - 2011-03-28 18:58 - 00000000 ____D C:\Users\Judith\AppData\Roaming\DVDVideoSoft 2013-06-24 18:21 - 2013-06-24 18:21 - 00024064 _____ M:\Dokumente\Schreib-ab homepage.doc 2013-06-24 17:26 - 2008-12-13 13:43 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-06-24 17:25 - 2013-06-24 17:25 - 00001038 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-06-24 17:14 - 2012-10-13 13:42 - 70431848 _____ (DVDVideoSoft Ltd. ) C:\Users\Judith\Downloads\FreeStudio.exe 2013-06-24 12:30 - 2010-08-09 12:10 - 00000000 ____D C:\Users\Judith\.gimp-2.6 2013-06-24 12:29 - 2013-06-24 12:29 - 00017196 _____ C:\Users\Judith\.recently-used.xbel 2013-06-24 00:37 - 2006-11-02 12:24 - 75733144 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-20 19:20 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-07-2013 02 Ran by Judith at 2013-07-22 09:56:10 Running from C:\Users\Judith\Downloads Boot Mode: Safe Mode (minimal) ========================================================== ==================== Installed Programs ======================= AAVUpdateManager (Version: 18.00.0000) Acronis*True*Image*Home (Version: 10.0.4942) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) Apple Application Support (Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (Version: 2.1.3.127) Ashampoo Burning Studio 2013 v.11.0.5 (Version: 11.0.5) Audacity 1.2.6 Audacity 1.3.6 (Unicode) Audials (Version: 10.1.509.900) Audiograbber 1.83 SE (Version: 1.83 SE) Avidemux 2.5 (Version: 2.5.1.5249) Avira Free Antivirus (Version: 13.0.0.3737) AVS Screen Capture version 2.0.2 AVS Update Manager 1.0 AVS Video Editor 6 AVS Video Recorder 2.5 AVS4YOU Software Navigator 1.4 Bonjour (Version: 3.0.0.10) capella 7 (Version: 7.1.6) CCleaner (Version: 3.25) CD- und DVD-Sharing (Version: 1.0.1.4) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) COMPUTERBILD-Cloud D3DX10 (Version: 15.4.2368.0902) Dell Resource CD (Version: 1.00.0000) DivxToDVD 0.5.2b (Version: 0.5.2b) Dropbox (HKCU Version: 2.2.8) DSL-Manager EclipseCrossword (Version: 1.2.57) ESET Online Scanner v3 FileZilla Client 3.6.0.2 (Version: 3.6.0.2) FormatFactory 2.50 (Version: 2.50) Forte Free 2.0 Free Audio CD Burner version 1.4.7 Free Studio version 2013 (Version: 6.1.3.622) Free Video to iPod Converter version 4.2.16.305 Free Video to JPG Converter version 1.5 Free Video to MP3 Converter version 3.2 Free YouTube Download 2.9 Free YouTube to iPod Converter version 3.2 Free YouTube to MP3 Converter version 3.11.34.1015 (Version: 3.11.34.1015) FreeMind (Version: 0.8.1) GIMP 2.6.12 (Version: 2.6.12) GOM Player (Version: 2.1.40.5106) Google Chrome (HKCU Version: 28.0.1500.72) Google Earth (Version: 6.2.0.5905) Google Talk Plugin (Version: 4.2.1.14031) Google Update Helper (Version: 1.3.21.153) Hervorhebe-Funktion (Windows Live Toolbar) (Version: 03.01.0146) HotPotatoes v 6.3.0.3 ICQ 8.0 (build 6014) (HKCU Version: 8.0.6014.0) ICQ Sparberater (Version: 1.4.9) IsoBuster 2.3 (Version: 2.3) iTunes (Version: 11.0.0.163) Japanese Fonts Support For Adobe Reader 9 (Version: 9.0.0) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Junk Mail filter update (Version: 15.4.3502.0922) MAGIX Foto Manager 10 (Version: 8.0.1.136) MAGIX Online Druck Service (Version: 3.4.3.0) MAGIX Screenshare (Version: 4.3.6.1987) MAGIX Xtreme Foto & Grafik Designer 5 (Silver) (Version: 5.1.2.15876) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) MediaDirect (Version: 4.7) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0) Microsoft Search Enhancement Pack (Version: 3.0.133.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Windows Media Video 9 VCM Microsoft XML Parser (Version: 8.0.7820.0) MindManager Smart (Version: 2.1.3) Mozilla Firefox 22.0 (x86 de) (Version: 22.0) Mozilla Maintenance Service (Version: 22.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) neroxml (Version: 1.0.0) No23 Recorder (Version: 2.1.0.3) Notepad++ (Version: 6.2.3) NVIDIA Drivers Octava SD4 (Version: 5.01) OutlookAddinSetup (Version: 1.0.0) Paragon Partition Manager 2007 PDF24 Creator 5.2.0 PDFCreator (Version: 1.2.3) Pfadfinder 2.0 (Version: 1.0.7) Phase 5 HTML-Editor (Version: 5.6.2.3) Phoenix Backup Professional (Version: 3.5.000) PixiePack Codec Pack (Version: 1.1.400.0) Plus-HD-2.3 (Version: 1.27.153.8) QuickTime (Version: 7.72.80.56) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealPlayer (Version: 15.0.4) RealUpgrade 1.1 (Version: 1.1.0) River Past Video Cleaner Pro (Version: 7.7.7) Roxio Creator Audio (Version: 3.3.0) Roxio Creator Copy (Version: 3.3.0) Roxio Creator Data (Version: 3.3.0) Roxio Creator DE (Version: 3.3.0) Roxio Creator Tools (Version: 3.3.0) Roxio Drag-to-Disc (Version: 9.0) Roxio Express Labeler (Version: 2.1.0) Roxio MyDVD DE (Version: 9.0.117) Roxio Update Manager (Version: 3.0.0) Rund um (2.0) ... Erlebnis Biologie 1 RS (Version: 1.00.0000) Rund um (2.0) ... Erlebnis Chemie RP HE NI (Version: 1.00.0000) Rund um (2.0) ... Erlebnis Naturwissenschaften 5 RP (Version: 1.00.0000) Rund um ... Biologie heute entdecken 1 (Version: 1.00.0000) Rund um ... Biologie heute entdecken 2 (Teil 1) (Version: 1.00.0000) Rund um ... Biologie heute entdecken 2 (Teil 2) (Version: 1.00.0000) Segoe UI (Version: 15.4.2271.0615) Sicherheitsupdate für Windows Media Player (KB2845142) SigmaTel Audio (Version: 5.10.5210.0) Skype™ 6.5 (Version: 6.5.158) Smart Menus (Windows Live Toolbar) (Version: 03.01.0146) Sonic Activation Module (Version: 1.0) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0) Steuer-Spar-Erklärung 2011 (Version: 16.17) Steuer-Spar-Erklärung 2012 (Version: 17.02) Streambox Vcr Suite 2 SugarSync (Version: 2.0.27.114357) Text-To-Speech-Runtime (Version: 1.0.0.0) Toxic Biohazard TubeBox (Version: 4.1.1.0) Ulead GIF Animator Lite Edition 1.0 Uninstall 1.0.0.1 Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) VLC media player 2.0.7 (Version: 2.0.7) VoiceOver Kit (Version: 1.30.128.0) White Christmas 3D Screensaver and Animated Wallpaper 1.0 (Version: 1.0) WIDCOMM Bluetooth Software 6.0.1.3100 (Version: 6.0.1.3100) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Toolbar-Erweiterung (Windows Live Toolbar) (Version: 03.01.0146) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0) Windows Utils WinRAR archiver Wuala (HKCU Version: 1.0.428.0) Wuala CBFS (Version: 3.2.107.0) Wuala OverlayIcons (Version: 1.0.0.2) XMedia Recode 3.0.8.5 (Version: 3.0.8.5) ==================== Restore Points ========================= 10-07-2013 19:33:20 Gerätetreiber-Paketinstallation: SugarSync 10-07-2013 19:43:57 Installed Java 7 Update 25 11-07-2013 12:13:12 Geplanter Prüfpunkt 13-07-2013 01:00:57 Windows Update 14-07-2013 19:50:22 Geplanter Prüfpunkt 15-07-2013 11:45:56 Geplanter Prüfpunkt 16-07-2013 09:23:01 Geplanter Prüfpunkt 16-07-2013 20:02:16 Windows Update 16-07-2013 21:05:28 Free YouTube Download Manager 17-07-2013 09:50:36 JavaFX 2.1.1 wird entfernt 17-07-2013 09:52:26 Removed LibreOffice 3.6 17-07-2013 22:00:04 Geplanter Prüfpunkt 19-07-2013 08:47:18 ComboFix created restore point 19-07-2013 08:49:20 ComboFix created restore point 20-07-2013 09:25:52 OpenOffice.org 3.1 wird entfernt 20-07-2013 09:30:26 Removed VirtualDJ Home FREE 20-07-2013 09:31:37 Free YouTube Download Manager ==================== Hosts content: ========================== 2010-11-10 18:16 - 2013-07-19 11:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {07EFF3F8-57E9-4060-AC8B-63C03D320C8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0DF7E8C6-4CF7-4DE8-8BAA-516D9BB205F9} - System32\Tasks\EPUpdater => C:\Users\Judith\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File Task: {18BF61D8-8C4D-46C1-A397-EB7A6DC96E58} - System32\Tasks\{658EA475-F343-45E9-AF82-B67E5CDA0A49} => c:\program files\mozilla firefox\firefox.exe [2013-06-18] (Mozilla Corporation) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2461E8E9-EE40-4DBD-A19C-B63B76A58539} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {2DB895D9-D2FC-42EA-B3EF-22E6FC0EE2F5} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {36D7A5B8-4472-4F24-A887-D37F62033E77} - System32\Tasks\{1CCCC0B6-CFDB-4CC2-A42A-85FEE189240A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3C6D8EF0-298B-4F31-80A7-9F3D060DE516} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3758001449-3176424044-3867666295-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {3D5CB9AB-CBA4-4773-8496-A0BB1355C097} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {4692C054-BD6B-44FE-AC34-6E8EF7BED887} - System32\Tasks\Hoolapp Init => C:\Users\Judith\AppData\Roaming\HOOLAP~1\Hoolapp.exe No File Task: {521E92D9-3347-43B0-8FD9-81111C6875F5} - System32\Tasks\icqSWU => C:\Windows\System32\cscript.exe [2009-04-11] (Microsoft Corporation) Task: {5392E7AF-501E-42B5-9C13-F4F38D0AB0FA} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {54427084-6145-4C10-A6BE-3852819D9086} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-11-24] (Piriform Ltd) Task: {5450762C-E678-4C27-9F14-0DE6B0BA673B} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Judith => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {5EA3018C-5A19-4672-A5D9-1E6798A5DDB6} - System32\Tasks\Microsoft\Windows\RestartManager\{5A2F064A-6F7D-43b3-A3E7-66C404102C38} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {61858FB2-F17C-4365-A209-A1C513102D64} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation) Task: {6319641D-EF8F-47AB-8F8B-8686C8D0EF51} - System32\Tasks\Hoolapp For Android => C:\Users\Judith\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE No File Task: {6C51054D-758B-4BAD-86DD-53F1A46E3A90} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3758001449-3176424044-3867666295-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {8B3D2A13-BD5E-409A-B91D-4112FC8C84DF} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {937DE204-BC75-40F1-9F78-99C92C20A7F9} - System32\Tasks\{9FB8FE6B-80F2-4C6A-AF86-BBF69CEFAF15} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {9B411A20-1FFE-430A-9A15-1FEEBA8C6738} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-04] (Google Inc.) Task: {9CEB093B-75B3-4E5C-82E3-0F00F56EEF97} - System32\Tasks\Microsoft\Windows\RestartManager\{413EBFE5-7F85-4328-8E7F-EE0B67E7758A} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {9EBD668F-185F-49E8-A084-D7A3454DC025} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-04] (Google Inc.) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {A860C6A5-C081-4512-A41B-3CDA091A9F23} - System32\Tasks\User_Feed_Synchronization-{FFEC623E-F341-4E38-8943-ABB2B7D24138} => C:\Windows\system32\msfeedssync.exe [2013-05-29] (Microsoft Corporation) Task: {B15FE2B6-56A5-467A-83AD-9A5C39F49798} - \BrowserDefendert No Task File Task: {CA11AF58-3534-4B3A-B808-9E78362DCECC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-24] (Google Inc.) Task: {D0645CD6-D80F-4895-89A2-31762C52DF3B} - System32\Tasks\DSite => C:\Users\Judith\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File Task: {D36A0565-494E-4C1B-A28D-24EBCC2C4439} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DB14B352-D4C4-4BEA-81ED-DC36F12E827B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-24] (Google Inc.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core.job => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA.job => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{FFEC623E-F341-4E38-8943-ABB2B7D24138}.job => C:\Windows\system32\msfeedssync.exe ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/22/2013 09:53:19 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 09:44:24 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:48:02 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:45:30 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:27:54 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:58:18 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:55:56 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:51:56 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 04:11:59 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11919 Error: (07/20/2013 04:11:59 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11919 System errors: ============= Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: AFD avipbb avkmgr cbfs3 DfsC DslMNLwf NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr ssmdrv tdx Wanarpv6 ws2ifsl Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NetzwerklistendienstNLA (Network Location Awareness)%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NLA (Network Location Awareness)Netzwerkspeicher-Schnittstellendienst%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: NetzwerkverbindungenNetzwerkspeicher-Schnittstellendienst%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: IP-HilfsdienstNetzwerkspeicher-Schnittstellendienst%%1068 Error: (07/22/2013 09:54:07 AM) (Source: Service Control Manager) (User: ) Description: WebClientWebDav Client Redirector Driver%%1068 Microsoft Office Sessions: ========================= Error: (07/22/2013 09:53:19 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 09:44:24 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:48:02 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:45:30 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:27:54 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:58:18 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:55:56 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:51:56 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 04:11:59 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11919 Error: (07/20/2013 04:11:59 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11919 CodeIntegrity Errors: =================================== Date: 2013-07-20 14:48:55.523 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:55.222 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.945 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.665 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.385 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.085 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:59.555 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:59.226 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.844 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.504 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 27% Total physical RAM: 2045.31 MB Available physical RAM: 1484.13 MB Total Pagefile: 4325.88 MB Available Pagefile: 3962.51 MB Total Virtual: 2047.88 MB Available Virtual: 1934.76 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:99.88 GB) (Free:30.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive j: (Samsung Festplatte neu) (Fixed) (Total:931.51 GB) (Free:617.61 GB) NTFS Drive m: (Daten) (Fixed) (Total:130.95 GB) (Free:4.53 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 00000080) Partition 1: (Not Active) - (Size=47 MB) - (Type=DE) Partition 2: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=133 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 54349CA3) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
22.07.2013, 09:27 | #27 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\Judith\AppData\Local\Windows\net.lnk ShortcutTarget: net.lnk -> C:\Users\Judith\AppData\Roaming\Windows Net Data\net.exe (Windows Net) C:\Users\Judith\AppData\Local\Windows Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Geht normal booten?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2013, 11:14 | #28 |
| Problem: Internet Explorer Meldung getwindowinfo FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2013 02 Ran by Judith (administrator) on 22-07-2013 09:54:24 Running from C:\Users\Judith\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Safe Mode (minimal) ==================== Processes (Whitelisted) =================== (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== Lsa: [Authentication Packages] msv1_0 relog_ap ed) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [49664 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [ICQ] - C:\Users\Judith\AppData\Roaming\ICQM\icq.exe [27598184 2013-04-10] (ICQ) HKCU\...\Run: [COMPUTERBILD-Cloud] - C:\Program Files\COMPUTERBILD-Cloud\CGCClient.exe [1781840 2012-08-08] () HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.) HKCU\...\Run: [SugarSync] - C:\Program Files\SugarSync\SugarSync.exe [12419424 2013-06-26] (SugarSync, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\T-Online\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\T-Online\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Judith\AppData\Local\Windows\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Judith\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Judith\AppData\Local\Windows\net.lnk ShortcutTarget: net.lnk -> C:\Users\Judith\AppData\Roaming\Windows Net Data\net.exe (Windows Net) SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {752A9793-46C2-4927-9DCE-8FD9351F6B79} URL = hxxp://www.google.de/search?q={searchTerms} BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: ICQ Sparberater - {E2B5568A-B3BC-49D6-9BEA-4A549AA1E01E} - C:\Program Files\icq\Internet Explorer\icq.dll () Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File Toolbar: HKCU -No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File Toolbar: HKCU -No Name - {00000000-0000-0000-0000-000000000000} - No File Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Judith\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Judith\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-13.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-14.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-15.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-16.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\foxsearch.src FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com FF Extension: ICQ Sparberater - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\ciuvo-extension@icq.de FF Extension: ReminderFox - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} FF Extension: NoiaFoxoption - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKCU\...\Firefox\Extensions: [{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46}] C:\Users\Judith\AppData\Local\{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46} FF Extension: XULRunner - C:\Users\Judith\AppData\Local\{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46} Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (Google Talk Plugin) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.16) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0 ========================== Services (Whitelisted) ================= S2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [411168 2007-02-16] (Acronis) S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-20] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-20] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-06-20] (Avira Operations GmbH & Co. KG) S2 DokanMounter; C:\Program Files\COMPUTERBILD-Cloud\Data\Tools\mounter.exe [14848 2012-02-15] () S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 TDslMgrService; C:\Program Files\T-Online\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) S3 UPnPService; C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) ==================== Drivers (Whitelisted) ==================== S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26080 2012-10-08] (Wondershare) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-06-20] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-06-20] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) S1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [299024 2012-04-09] (EldoS Corporation) S2 Dokan; C:\Windows\system32\drivers\dokan.sys [95744 2012-02-15] (Windows (R) Win 7 DDK provider) S1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R0 hotcore3; C:\Windows\System32\drivers\hotcore3.sys [39472 2007-08-21] (Paragon Software Group) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-07-20] (Malwarebytes Corporation) S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2012-12-12] (RapidSolution Software AG) S3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2012-12-12] (RapidSolution Software AG) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-01-10] (Duplex Secure Ltd.) S3 SSCBFS3; C:\Windows\System32\DRIVERS\sscbfs3.sys [295936 2013-01-30] (EldoS Corporation) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [31360 2012-07-20] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) S3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [39048 2012-12-12] (RapidSolution Software AG) S2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [32768 2008-12-13] (Acronis) S3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) S2 {2E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}; C:\Program Files\Dell\MediaDirect\000.fcl [13560 2007-04-02] (Cyberlink Corp.) S3 ActivHidSerMini; system32\DRIVERS\activhidsermini.sys [x] S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S4 IpInIp; system32\DRIVERS\ipinip.sys [x] S4 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S4 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 prmvmouse; system32\DRIVERS\activmouse.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-22 09:42 - 2013-07-22 09:42 - 00143624 _____ C:\Windows\Minidump\Mini072213-01.dmp 2013-07-20 20:20 - 2013-07-20 20:21 - 00143624 _____ C:\Windows\Minidump\Mini072013-11.dmp 2013-07-20 20:13 - 2013-07-20 20:13 - 00143624 _____ C:\Windows\Minidump\Mini072013-10.dmp 2013-07-20 20:07 - 2013-07-20 20:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-09.dmp 2013-07-20 19:15 - 2013-07-20 19:15 - 00143624 _____ C:\Windows\Minidump\Mini072013-08.dmp 2013-07-20 19:07 - 2013-07-20 19:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-07.dmp 2013-07-20 19:00 - 2013-07-20 19:00 - 00143624 _____ C:\Windows\Minidump\Mini072013-06.dmp 2013-07-20 18:26 - 2013-07-20 18:27 - 00143624 _____ C:\Windows\Minidump\Mini072013-05.dmp 2013-07-20 18:20 - 2013-07-20 18:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-04.dmp 2013-07-20 18:14 - 2013-07-20 18:14 - 00143624 _____ C:\Windows\Minidump\Mini072013-03.dmp 2013-07-20 18:04 - 2013-07-20 18:06 - 00001885 _____ C:\AdwCleaner[S3].txt 2013-07-20 17:50 - 2013-07-20 17:51 - 00143624 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 17:44 - 2013-07-20 17:44 - 00143624 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 17:43 - 2013-07-22 09:41 - 219110943 _____ C:\Windows\MEMORY.DMP 2013-07-20 13:13 - 2013-07-20 13:13 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-20 13:10 - 2013-07-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Judith\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-20 13:09 - 2013-07-20 13:09 - 00602112 _____ (OldTimer Tools) C:\Users\Judith\Downloads\OTL.exe 2013-07-20 12:48 - 2013-07-20 12:52 - 00004974 _____ C:\Windows\ie8_main.log 2013-07-20 12:48 - 2013-07-20 12:48 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-20 12:45 - 2013-07-20 12:46 - 14938992 _____ (Microsoft Corporation) C:\Users\Judith\Downloads\IE8-WindowsVista-x86-DEU.exe 2013-07-20 12:45 - 2013-07-20 12:45 - 21703480 _____ (Mozilla) C:\Users\Judith\Downloads\Firefox_Setup_22.0.exe 2013-07-19 17:45 - 2013-07-19 17:45 - 00000000 ____D C:\Program Files\ESET 2013-07-19 17:45 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Desktop\SecurityCheck.exe 2013-07-19 17:34 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Downloads\SecurityCheck.exe 2013-07-19 17:33 - 2013-07-19 17:33 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu (1).exe 2013-07-19 15:22 - 2013-07-19 15:22 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu.exe 2013-07-19 13:26 - 2013-07-20 11:21 - 00026743 _____ C:\Users\Judith\Downloads\Addition.txt 2013-07-19 13:23 - 2013-07-19 13:23 - 00003328 _____ C:\Users\Judith\Desktop\JRT.txt 2013-07-19 12:03 - 2013-07-19 12:03 - 00000000 ____D C:\Windows\ERUNT 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Downloads\JRT.exe 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Desktop\JRT.exe 2013-07-19 11:50 - 2013-07-19 11:52 - 00011518 _____ C:\AdwCleaner[S2].txt 2013-07-19 11:50 - 2013-07-19 11:52 - 00000098 _____ C:\Windows\DeleteOnReboot.bat 2013-07-19 11:50 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Desktop\adwcleaner2305.exe 2013-07-19 11:18 - 2013-07-19 11:18 - 00030260 _____ C:\ComboFix.txt 2013-07-19 10:47 - 2013-07-19 10:45 - 05091168 ____R (Swearware) C:\Users\Judith\Desktop\ComboFix.exe 2013-07-19 10:47 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-19 10:47 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-19 10:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-19 10:46 - 2013-07-19 11:18 - 00000000 ____D C:\Qoobox 2013-07-19 10:45 - 2013-07-19 11:15 - 00000000 ____D C:\Windows\erdnt 2013-07-19 10:44 - 2013-07-19 10:45 - 05091168 ____R (Swearware) C:\Users\Judith\Downloads\ComboFix.exe 2013-07-18 19:58 - 2013-07-18 19:58 - 00000000 ____D C:\FRST 2013-07-18 19:56 - 2013-07-18 19:56 - 01218860 _____ (Farbar) C:\Users\Judith\Downloads\FRST.exe 2013-07-18 19:53 - 2013-07-18 19:53 - 00000000 ____D C:\Users\Judith\Qtrax 2013-07-18 19:48 - 2013-07-18 19:48 - 00793536 _____ C:\Users\Judith\Downloads\ZipOpenerSetup.exe 2013-07-18 17:13 - 2013-07-18 17:14 - 00033686 _____ C:\AdwCleaner[S1].txt 2013-07-18 17:12 - 2013-07-18 17:12 - 00033720 _____ C:\AdwCleaner[R1].txt 2013-07-18 17:11 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Downloads\adwcleaner2305.exe 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setuperr.log 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setupact.log 2013-07-17 12:22 - 2013-07-20 17:38 - 00006232 _____ C:\Windows\PFRO.log 2013-07-16 23:17 - 2013-07-18 16:41 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-07-16 23:16 - 2013-07-17 12:29 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Windows Net Data 2013-07-16 23:15 - 2013-06-27 07:14 - 00031816 _____ C:\Windows\Launcher.exe 2013-07-16 23:04 - 2013-07-16 23:04 - 00000000 ____D C:\Users\Judith\AppData\Local\Software Updater 2013-07-16 22:03 - 2013-07-16 22:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-16 20:10 - 2013-07-16 20:10 - 00283168 _____ C:\Users\Judith\Downloads\Setup (1).exe 2013-07-16 14:35 - 2013-07-16 14:35 - 00895488 _____ M:\Dokumente\Visitenkarten.doc 2013-07-13 03:25 - 2013-07-13 03:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2845142_WM64$ 2013-07-13 03:25 - 2007-07-27 10:41 - 00016760 ____N (Microsoft Corporation) C:\Windows\system32\spmsg.dll 2013-07-12 16:40 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-12 16:39 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-12 16:39 - 2013-05-29 13:30 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 16:39 - 2013-05-29 13:30 - 00916480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 16:39 - 2013-05-29 13:30 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-12 16:39 - 2013-05-29 13:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 06016000 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-12 16:39 - 2013-05-29 13:24 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-12 16:39 - 2013-05-29 11:47 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-12 16:39 - 2013-05-29 10:07 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-12 16:39 - 2013-05-29 10:06 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-12 16:39 - 2013-05-29 10:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-12 16:39 - 2013-05-29 10:04 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 16:39 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-12 16:39 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-12 16:39 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-12 16:39 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-12 16:39 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-12 16:39 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-12 16:38 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 21:53 - 2013-07-10 21:53 - 00024064 _____ M:\Dokumente\Windows Phone Store.doc 2013-07-10 21:51 - 2013-07-10 21:51 - 00000840 _____ C:\Users\Judith\Desktop\Wuala.lnk 2013-07-10 21:48 - 2013-07-21 10:43 - 00000000 ___RD C:\Users\Judith\Dropbox 2013-07-10 21:48 - 2013-07-10 21:48 - 00000992 _____ C:\Users\Judith\Desktop\Dropbox.lnk 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala OverlayIcons 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala CBFS 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-10 21:47 - 2013-07-10 21:45 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-10 21:47 - 2012-04-09 16:27 - 00299024 _____ (EldoS Corporation) C:\Windows\system32\Drivers\cbfs3.sys 2013-07-10 21:47 - 2012-04-09 16:27 - 00223760 _____ (EldoS Corporation) C:\Windows\system32\CbFsNetRdr3.dll 2013-07-10 21:47 - 2012-04-09 16:27 - 00158224 _____ (EldoS Corporation) C:\Windows\system32\CbFsMntNtf3.dll 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-10 21:44 - 2013-07-10 21:44 - 00000000 ____D C:\Program Files\Dropbox 2013-07-10 21:43 - 2013-07-10 21:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-10 21:40 - 2013-07-21 10:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Dropbox 2013-07-10 21:39 - 2013-07-10 21:40 - 33578320 _____ (Dropbox, Inc.) C:\Users\Judith\Downloads\Dropbox 2.2.8.exe 2013-07-10 21:38 - 2013-07-10 21:38 - 00000000 ____D M:\Dokumente\Mein SugarSync 2013-07-10 21:36 - 2013-07-10 21:38 - 00000000 ____D C:\Users\Judith\AppData\Local\SugarSync 2013-07-10 21:35 - 2013-07-10 21:35 - 00001692 _____ C:\Users\Public\Desktop\SugarSync.lnk 2013-07-10 21:35 - 2013-01-30 13:12 - 00225024 _____ (EldoS Corporation) C:\Windows\system32\SSCbFsNetRdr3.dll 2013-07-10 21:35 - 2013-01-30 13:12 - 00159488 _____ (EldoS Corporation) C:\Windows\system32\SSCbFsMntNtf3.dll 2013-07-10 21:33 - 2013-07-10 21:42 - 00000828 _____ C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wuala.lnk 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Wuala 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Local\Wuala 2013-07-10 21:33 - 2013-01-30 13:11 - 00295936 _____ (EldoS Corporation) C:\Windows\system32\Drivers\sscbfs3.sys 2013-07-10 21:32 - 2013-07-10 21:35 - 00000000 ____D C:\Program Files\SugarSync 2013-07-10 21:29 - 2013-07-10 21:29 - 22964952 _____ C:\Users\Judith\Downloads\WualaSetup_04_13.exe 2013-07-10 21:27 - 2013-07-10 21:28 - 20911672 _____ (SugarSync, Inc.) C:\Users\Judith\Downloads\SugarSyncSetup_2.0.27.exe 2013-07-07 21:25 - 2013-07-07 21:25 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00001853 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\ProgramData\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\Program Files\Avira 2013-07-07 21:21 - 2013-06-20 14:48 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-07 21:21 - 2013-03-06 16:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-07 21:21 - 2012-08-27 15:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-07 21:04 - 2013-07-07 21:06 - 104943936 _____ C:\Users\Judith\Downloads\avira3737_free_antivirus_de.exe 2013-07-01 18:20 - 2013-07-01 18:20 - 00005384 _____ C:\Users\Judith\Downloads\Mundharmonika+Noten.htm (7).html 2013-06-28 11:52 - 2013-06-28 11:52 - 00000865 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-06-28 11:50 - 2013-06-28 11:51 - 22937227 _____ C:\Users\Judith\Downloads\vlc-2.0.7-win32.exe 2013-06-24 18:21 - 2013-06-24 18:21 - 00024064 _____ M:\Dokumente\Schreib-ab homepage.doc 2013-06-24 17:53 - 2013-07-20 12:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-06-24 17:25 - 2013-06-24 17:25 - 00001038 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-06-24 12:29 - 2013-06-24 12:29 - 00017196 _____ C:\Users\Judith\.recently-used.xbel ==================== One Month Modified Files and Folders ======= 2013-07-22 09:42 - 2013-07-22 09:42 - 00143624 _____ C:\Windows\Minidump\Mini072213-01.dmp 2013-07-22 09:42 - 2012-02-13 21:18 - 00000000 ____D C:\Windows\Minidump 2013-07-22 09:42 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-22 09:42 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-22 09:42 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-22 09:41 - 2013-07-20 17:43 - 219110943 _____ C:\Windows\MEMORY.DMP 2013-07-21 10:43 - 2013-07-10 21:48 - 00000000 ___RD C:\Users\Judith\Dropbox 2013-07-21 10:43 - 2013-07-10 21:40 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Dropbox 2013-07-21 10:40 - 2012-03-04 13:19 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 20:21 - 2013-07-20 20:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-11.dmp 2013-07-20 20:19 - 2012-11-28 17:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-20 20:13 - 2013-07-20 20:13 - 00143624 _____ C:\Windows\Minidump\Mini072013-10.dmp 2013-07-20 20:11 - 2012-03-04 13:20 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 20:09 - 2012-11-24 15:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA.job 2013-07-20 20:07 - 2013-07-20 20:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-09.dmp 2013-07-20 19:15 - 2013-07-20 19:15 - 00143624 _____ C:\Windows\Minidump\Mini072013-08.dmp 2013-07-20 19:07 - 2013-07-20 19:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-07.dmp 2013-07-20 19:00 - 2013-07-20 19:00 - 00143624 _____ C:\Windows\Minidump\Mini072013-06.dmp 2013-07-20 18:52 - 2008-12-13 16:15 - 00000000 ____D M:\Dokumente\Programme 2013-07-20 18:27 - 2013-07-20 18:26 - 00143624 _____ C:\Windows\Minidump\Mini072013-05.dmp 2013-07-20 18:20 - 2013-07-20 18:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-04.dmp 2013-07-20 18:14 - 2013-07-20 18:14 - 00143624 _____ C:\Windows\Minidump\Mini072013-03.dmp 2013-07-20 18:12 - 2012-12-10 21:35 - 00000000 ____D C:\Users\Judith\AppData\Roaming\COMPUTERBILD Cloud 2013-07-20 18:07 - 2010-05-25 18:16 - 00008524 _____ C:\Windows\bthservsdp.dat 2013-07-20 18:07 - 2006-11-02 15:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-20 18:07 - 2006-11-02 14:52 - 01287636 _____ C:\Windows\WindowsUpdate.log 2013-07-20 18:06 - 2013-07-20 18:04 - 00001885 _____ C:\AdwCleaner[S3].txt 2013-07-20 17:59 - 2009-10-26 21:40 - 00000000 ____D C:\Users\Judith\Downloads\USB Stick grau 1 2013-07-20 17:51 - 2013-07-20 17:50 - 00143624 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 17:44 - 2013-07-20 17:44 - 00143624 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 17:38 - 2013-07-17 12:22 - 00006232 _____ C:\Windows\PFRO.log 2013-07-20 17:38 - 2012-04-27 17:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-20 17:34 - 2011-07-22 18:56 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Skype 2013-07-20 13:16 - 2010-10-13 15:12 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-07-20 13:13 - 2013-07-20 13:13 - 00000912 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-20 13:13 - 2010-10-13 15:12 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-20 13:13 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-20 13:10 - 2013-07-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Judith\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-20 13:09 - 2013-07-20 13:09 - 00602112 _____ (OldTimer Tools) C:\Users\Judith\Downloads\OTL.exe 2013-07-20 12:52 - 2013-07-20 12:48 - 00004974 _____ C:\Windows\ie8_main.log 2013-07-20 12:50 - 2008-12-13 11:46 - 00000000 ____D C:\Users\Judith\AppData\Local\Adobe 2013-07-20 12:48 - 2013-07-20 12:48 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-20 12:48 - 2013-06-24 17:53 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 12:46 - 2013-07-20 12:45 - 14938992 _____ (Microsoft Corporation) C:\Users\Judith\Downloads\IE8-WindowsVista-x86-DEU.exe 2013-07-20 12:45 - 2013-07-20 12:45 - 21703480 _____ (Mozilla) C:\Users\Judith\Downloads\Firefox_Setup_22.0.exe 2013-07-20 11:48 - 2006-11-02 12:33 - 01560022 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-20 11:47 - 2012-12-10 21:36 - 00000000 __SHD C:\Users\Judith\wc 2013-07-20 11:45 - 2008-12-10 20:46 - 00183296 _____ C:\Users\Judith\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-20 11:43 - 2006-11-02 14:47 - 00530840 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-20 11:39 - 2008-12-10 20:45 - 00000000 ___RD C:\Users\Judith\Desktop 2013-07-20 11:34 - 2009-01-05 14:33 - 00027430 _____ C:\Users\Judith\AppData\Roaming\nvModes.001 2013-07-20 11:32 - 2013-02-17 16:41 - 00000000 ____D C:\Program Files\Freetec 2013-07-20 11:32 - 2013-02-17 16:39 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-20 11:31 - 2012-01-09 17:23 - 00000000 ____D M:\Dokumente\VirtualDJ 2013-07-20 11:30 - 2009-01-10 19:23 - 00000000 ____D C:\Program Files\OpenOffice.org 3 2013-07-20 11:21 - 2013-07-19 13:26 - 00026743 _____ C:\Users\Judith\Downloads\Addition.txt 2013-07-19 17:45 - 2013-07-19 17:45 - 00000000 ____D C:\Program Files\ESET 2013-07-19 17:34 - 2013-07-19 17:45 - 00891062 _____ C:\Users\Judith\Desktop\SecurityCheck.exe 2013-07-19 17:34 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Downloads\SecurityCheck.exe 2013-07-19 17:33 - 2013-07-19 17:33 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu (1).exe 2013-07-19 15:22 - 2013-07-19 15:22 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu.exe 2013-07-19 13:23 - 2013-07-19 13:23 - 00003328 _____ C:\Users\Judith\Desktop\JRT.txt 2013-07-19 12:03 - 2013-07-19 12:03 - 00000000 ____D C:\Windows\ERUNT 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Downloads\JRT.exe 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Desktop\JRT.exe 2013-07-19 11:52 - 2013-07-19 11:50 - 00011518 _____ C:\AdwCleaner[S2].txt 2013-07-19 11:52 - 2013-07-19 11:50 - 00000098 _____ C:\Windows\DeleteOnReboot.bat 2013-07-19 11:18 - 2013-07-19 11:18 - 00030260 _____ C:\ComboFix.txt 2013-07-19 11:18 - 2013-07-19 10:46 - 00000000 ____D C:\Qoobox 2013-07-19 11:18 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-07-19 11:18 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-19 11:15 - 2013-07-19 10:45 - 00000000 ____D C:\Windows\erdnt 2013-07-19 11:09 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-07-19 11:07 - 2006-11-02 12:22 - 59244544 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 45350912 _____ C:\Windows\system32\config\COMPON~2.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 24903680 _____ C:\Windows\system32\config\SYSTEM.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00786432 _____ C:\Windows\system32\config\DEFAULT.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-07-19 11:04 - 2008-12-10 20:45 - 00000000 ____D C:\Users\Judith 2013-07-19 10:45 - 2013-07-19 10:47 - 05091168 ____R (Swearware) C:\Users\Judith\Desktop\ComboFix.exe 2013-07-19 10:45 - 2013-07-19 10:44 - 05091168 ____R (Swearware) C:\Users\Judith\Downloads\ComboFix.exe 2013-07-18 19:58 - 2013-07-18 19:58 - 00000000 ____D C:\FRST 2013-07-18 19:56 - 2013-07-18 19:56 - 01218860 _____ (Farbar) C:\Users\Judith\Downloads\FRST.exe 2013-07-18 19:53 - 2013-07-18 19:53 - 00000000 ____D C:\Users\Judith\Qtrax 2013-07-18 19:48 - 2013-07-18 19:48 - 00793536 _____ C:\Users\Judith\Downloads\ZipOpenerSetup.exe 2013-07-18 17:14 - 2013-07-18 17:13 - 00033686 _____ C:\AdwCleaner[S1].txt 2013-07-18 17:13 - 2008-12-13 19:22 - 00000000 ____D C:\ProgramData\ICQ 2013-07-18 17:13 - 2008-12-13 13:43 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-18 17:12 - 2013-07-18 17:12 - 00033720 _____ C:\AdwCleaner[R1].txt 2013-07-18 17:11 - 2013-07-19 11:50 - 00662345 _____ C:\Users\Judith\Desktop\adwcleaner2305.exe 2013-07-18 17:11 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Downloads\adwcleaner2305.exe 2013-07-18 16:41 - 2013-07-16 23:17 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-07-18 14:38 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setuperr.log 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setupact.log 2013-07-18 03:09 - 2012-11-24 15:33 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core.job 2013-07-17 14:02 - 2008-12-13 19:48 - 00000000 ____D M:\Dokumente\Sicherung 2013-07-17 12:29 - 2013-07-16 23:16 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Windows Net Data 2013-07-17 12:06 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\ShellNew 2013-07-17 11:49 - 2011-11-22 19:00 - 00000000 ____D C:\Program Files\DsNET Corp 2013-07-16 23:16 - 2010-12-19 20:32 - 00000000 ___HD C:\Users\Judith\AppData\Local\Windows 2013-07-16 23:04 - 2013-07-16 23:04 - 00000000 ____D C:\Users\Judith\AppData\Local\Software Updater 2013-07-16 22:06 - 2013-07-16 22:03 - 00000000 ____D C:\Windows\system32\MRT 2013-07-16 20:10 - 2013-07-16 20:10 - 00283168 _____ C:\Users\Judith\Downloads\Setup (1).exe 2013-07-16 14:35 - 2013-07-16 14:35 - 00895488 _____ M:\Dokumente\Visitenkarten.doc 2013-07-16 12:14 - 2008-12-13 12:30 - 00002637 _____ C:\Users\Judith\Desktop\Microsoft Office Word 2003.lnk 2013-07-14 20:33 - 2012-01-20 19:03 - 00000000 ____D M:\Dokumente\Handys N97 Galaxy Ace 2013-07-13 04:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-13 03:48 - 2008-12-13 12:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-13 03:47 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-13 03:25 - 2013-07-13 03:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2845142_WM64$ 2013-07-13 03:02 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 09:31 - 2008-12-13 12:53 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Mozilla 2013-07-10 21:53 - 2013-07-10 21:53 - 00024064 _____ M:\Dokumente\Windows Phone Store.doc 2013-07-10 21:51 - 2013-07-10 21:51 - 00000840 _____ C:\Users\Judith\Desktop\Wuala.lnk 2013-07-10 21:48 - 2013-07-10 21:48 - 00000992 _____ C:\Users\Judith\Desktop\Dropbox.lnk 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala OverlayIcons 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala CBFS 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-10 21:45 - 2013-07-10 21:47 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-10 21:45 - 2012-06-30 12:00 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-10 21:45 - 2011-12-22 15:59 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-10 21:44 - 2013-07-10 21:44 - 00000000 ____D C:\Program Files\Dropbox 2013-07-10 21:43 - 2013-07-10 21:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-10 21:42 - 2013-07-10 21:33 - 00000828 _____ C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wuala.lnk 2013-07-10 21:40 - 2013-07-10 21:39 - 33578320 _____ (Dropbox, Inc.) C:\Users\Judith\Downloads\Dropbox 2.2.8.exe 2013-07-10 21:40 - 2010-02-17 17:02 - 00039424 _____ M:\Dokumente\mailaccounts community Free sms accounts.doc 2013-07-10 21:38 - 2013-07-10 21:38 - 00000000 ____D M:\Dokumente\Mein SugarSync 2013-07-10 21:38 - 2013-07-10 21:36 - 00000000 ____D C:\Users\Judith\AppData\Local\SugarSync 2013-07-10 21:35 - 2013-07-10 21:35 - 00001692 _____ C:\Users\Public\Desktop\SugarSync.lnk 2013-07-10 21:35 - 2013-07-10 21:32 - 00000000 ____D C:\Program Files\SugarSync 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Wuala 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Local\Wuala 2013-07-10 21:29 - 2013-07-10 21:29 - 22964952 _____ C:\Users\Judith\Downloads\WualaSetup_04_13.exe 2013-07-10 21:28 - 2013-07-10 21:27 - 20911672 _____ (SugarSync, Inc.) C:\Users\Judith\Downloads\SugarSyncSetup_2.0.27.exe 2013-07-07 21:25 - 2013-07-07 21:25 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00001853 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\ProgramData\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\Program Files\Avira 2013-07-07 21:06 - 2013-07-07 21:04 - 104943936 _____ C:\Users\Judith\Downloads\avira3737_free_antivirus_de.exe 2013-07-06 17:47 - 2012-08-30 13:55 - 00000000 ____D C:\Users\Judith\AppData\Roaming\vlc 2013-07-06 15:41 - 2010-01-15 17:53 - 00000000 ____D C:\Users\Judith\AppData\Roaming\dvdcss 2013-07-01 19:15 - 2008-12-13 16:17 - 00000000 ____D M:\Dokumente\Allerlei 2013-07-01 18:20 - 2013-07-01 18:20 - 00005384 _____ C:\Users\Judith\Downloads\Mundharmonika+Noten.htm (7).html 2013-06-28 15:16 - 2008-12-13 18:22 - 00074752 _____ C:\Users\Judith\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-06-28 11:52 - 2013-06-28 11:52 - 00000865 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-06-28 11:51 - 2013-06-28 11:50 - 22937227 _____ C:\Users\Judith\Downloads\vlc-2.0.7-win32.exe 2013-06-27 14:47 - 2013-04-01 16:03 - 00000000 ____D M:\Dokumente\Flug USA Herbst 2013 2013-06-27 07:14 - 2013-07-16 23:15 - 00031816 _____ C:\Windows\Launcher.exe 2013-06-24 18:23 - 2011-03-28 18:58 - 00000000 ____D C:\Users\Judith\AppData\Roaming\DVDVideoSoft 2013-06-24 18:21 - 2013-06-24 18:21 - 00024064 _____ M:\Dokumente\Schreib-ab homepage.doc 2013-06-24 17:26 - 2008-12-13 13:43 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-06-24 17:25 - 2013-06-24 17:25 - 00001038 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-06-24 17:14 - 2012-10-13 13:42 - 70431848 _____ (DVDVideoSoft Ltd. ) C:\Users\Judith\Downloads\FreeStudio.exe 2013-06-24 12:30 - 2010-08-09 12:10 - 00000000 ____D C:\Users\Judith\.gimp-2.6 2013-06-24 12:29 - 2013-06-24 12:29 - 00017196 _____ C:\Users\Judith\.recently-used.xbel 2013-06-24 00:37 - 2006-11-02 12:24 - 75733144 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-20 19:20 ==================== End Of Log ============================ --- --- --- Ich kann zwar normal hochfahren, aber dann wird der Bildschirm blau es erscheint fast eine ganze Seite Infos, die ich aber nicht lesen kann, weil alles innerhalb von ein paar Sekunden runter fährt. "bad header" konnte ich lesen "If this is the first time you´ve seen this stop screen restart your computer." Mehr konnte ich nicht lesen bzw. mir merken, weil er von alleine neustartet. Nach dem Neustart, wiederholte sich das Spielchen. |
22.07.2013, 13:30 | #29 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Neu booten, schnell F8 wie als wenn Du in den Safe Mode willst. Wähle "automatischen neustart bei Systemfehler deaktivieren" und boote neu, jetzt sollte der Text stehen bleiben.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2013, 14:08 | #30 |
| Problem: Internet Explorer Meldung getwindowinfo A problem has been detected and windows has been shut down to prevent damage to your computer. BAD_POOL_HEADER If this is the first timo you´ve seen this stop screen, restart your computer. If this screenapperas again, follow for any windows updates you might need. If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remod or disable components, restart your comupter, press F8 to select Advanced Startup options, and then select Safe Mode. Technical Information: *** STOP: 0x00000019 (0x00000020.0x85068118, 0x08080008) collecting data for crashdump... Initializing disk for crash dump ... Beginning dump of physical memory. Dumping physcial memory to disk: 100 Physical memory dump complete. Contact your system admin or technical supporter groupfor further assistance. Das steht auf dem Bildschirm |
Themen zu Problem: Internet Explorer Meldung getwindowinfo |
anzeige, avira, beschreiben, einfach, explorer, gestern, hierbei, interne, internet, internet explorer, leicht, malwarebytes, meldung, nichts, problem, schließe, schließen, virus, virus?, vorgehen, vorschlag, webseite, wunder, überhaupt, öffnet |