|
Plagegeister aller Art und deren Bekämpfung: Problem: Internet Explorer Meldung getwindowinfoWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.07.2013, 15:49 | #31 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Steckt irgendwas am PC? USB Stick oder so?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.07.2013, 17:19 | #32 |
| Problem: Internet Explorer Meldung getwindowinfo nein gar nichts
__________________Jetzt bin ich sprachlos. Ich habe gerade das Laptop ganz runter gefahren. Das Netzteil abgemacht und nochmal hochgefahren. Es kommt weder die IE Fehlermeldung noch der blaue Bildschirm. Wieder runter gefahren Netzteil wieder dran gehängt, hochgefahren und es läuft, als wäre nie was gewesen...sag mir bitte, dass ich nicht spinne |
22.07.2013, 17:49 | #33 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Du spinnst nicht
__________________Öffne bitte FRST, setz nen Haken bei Additional und scanne, poste beide Logfiles. Ausserdem: Navigiere zu C:\Windows\Minidump und nimm das vom Datum her letzte, aktuellste Dump-File, pack es in ein ZIP Archiv und häng es an, ich will mir das mal anschauen
__________________ |
23.07.2013, 11:26 | #34 |
| Problem: Internet Explorer Meldung getwindowinfo FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-07-2013 02 (ATTENTION: FRST version is 6 days old) Ran by Judith (administrator) on 23-07-2013 12:16:47 Running from C:\Users\Judith\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe () C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (Acronis) C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Andrea Electronics Corporation) C:\Windows\system32\aestsrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\COMPUTERBILD-Cloud\Data\Tools\mounter.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (IDT, Inc.) C:\Windows\system32\STacSV.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (IDT, Inc.) C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Sonic Solutions) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (SugarSync, Inc.) C:\Program Files\SugarSync\SugarSync.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dropbox, Inc.) C:\Users\Judith\AppData\Roaming\Dropbox\bin\Dropbox.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Judith\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== Lsa: [Authentication Packages] msv1_0 relog_ap Inc.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [151952 2012-11-29] (Apple Inc.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKCU\...\Run: [Speech Recognition] - C:\Windows\Speech\Common\sapisvr.exe [49664 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [ICQ] - C:\Users\Judith\AppData\Roaming\ICQM\icq.exe [27598184 2013-04-10] (ICQ) HKCU\...\Run: [COMPUTERBILD-Cloud] - C:\Program Files\COMPUTERBILD-Cloud\CGCClient.exe [1781840 2012-08-08] () HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [19603048 2013-06-03] (Skype Technologies S.A.) HKCU\...\Run: [SugarSync] - C:\Program Files\SugarSync\SugarSync.exe [12419424 2013-06-26] (SugarSync, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BTTray.lnk ShortcutTarget: BTTray.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\T-Online\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\T-Online\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\FRST\Quarantine\Windows\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Judith\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {752A9793-46C2-4927-9DCE-8FD9351F6B79} URL = hxxp://www.google.de/search?q={searchTerms} BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: ICQ Sparberater - {E2B5568A-B3BC-49D6-9BEA-4A549AA1E01E} - C:\Program Files\icq\Internet Explorer\icq.dll () Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File Toolbar: HKCU -No Name - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File Toolbar: HKCU -No Name - {00000000-0000-0000-0000-000000000000} - No File Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -No Name - {DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab Handler: msdaipp - No CLSID Value - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprjplug;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Judith\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Judith\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-13.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-14.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-15.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\icqplugin-16.xml FF SearchPlugin: C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\foxsearch.src FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com FF Extension: ICQ Sparberater - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\ciuvo-extension@icq.de FF Extension: ReminderFox - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} FF Extension: NoiaFoxoption - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\NoiaFoxoption@davidvincent.tld.xpi FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\pi8ce2ez.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF HKCU\...\Firefox\Extensions: [{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46}] C:\Users\Judith\AppData\Local\{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46} FF Extension: XULRunner - C:\Users\Judith\AppData\Local\{E6CF7BE8-F072-4CC8-AA98-DD0D516AFE46} Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Judith\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (Google Talk Plugin) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Judith\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.16) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (YouTube) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Facebook) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm\1.0.3_0 CHR Extension: (Google+) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm\1.2.0.418_0 CHR Extension: (Google Calendar) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0 CHR Extension: (Amazon) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\geblioikemedmjjpddghjecgonjcpddl\1.0_0 CHR Extension: (TweetDeck) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl\3.1.3_0 CHR Extension: (Dropbox) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl\3.0.6_0 CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0 CHR Extension: (Evernote Web) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0 CHR Extension: (Picasa) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb\6.2.2_0 CHR Extension: (Gmail) - C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ========================== Services (Whitelisted) ================= R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [411168 2007-02-16] (Acronis) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-06-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-06-20] (Avira Operations GmbH & Co. KG) R2 DokanMounter; C:\Program Files\COMPUTERBILD-Cloud\Data\Tools\mounter.exe [14848 2012-02-15] () S3 TDslMgrService; C:\Program Files\T-Online\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) S3 UPnPService; C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) ==================== Drivers (Whitelisted) ==================== S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26080 2012-10-08] (Wondershare) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-06-20] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-06-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-03-06] (Avira Operations GmbH & Co. KG) R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [299024 2012-04-09] (EldoS Corporation) R2 Dokan; C:\Windows\system32\drivers\dokan.sys [95744 2012-02-15] (Windows (R) Win 7 DDK provider) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 dsltestSp5; C:\Windows\System32\Drivers\dsltestSp5.sys [26816 2007-09-12] (Printing Communications Assoc., Inc. (PCAUSA)) R0 hotcore3; C:\Windows\System32\drivers\hotcore3.sys [39472 2007-08-21] (Paragon Software Group) S3 RRNetCap; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2012-12-12] (RapidSolution Software AG) R3 RRNetCapMP; C:\Windows\System32\DRIVERS\rrnetcap.sys [31848 2012-12-12] (RapidSolution Software AG) S4 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2009-01-10] (Duplex Secure Ltd.) R3 SSCBFS3; C:\Windows\System32\DRIVERS\sscbfs3.sys [295936 2013-01-30] (EldoS Corporation) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2012-08-27] (Avira GmbH) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [31360 2012-07-20] (The OpenVPN Project) S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [35592 2012-11-15] (Anchorfree Inc.) R3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [39048 2012-12-12] (RapidSolution Software AG) R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [32768 2008-12-13] (Acronis) R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex) R2 {2E444BE9-B8EC-4ce6-8C2B-6536FB7F4FB7}; C:\Program Files\Dell\MediaDirect\000.fcl [13560 2007-04-02] (Cyberlink Corp.) S3 ActivHidSerMini; system32\DRIVERS\activhidsermini.sys [x] S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 catchme; \??\C:\ComboFix\catchme.sys [x] S4 IpInIp; system32\DRIVERS\ipinip.sys [x] S4 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S4 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 prmvmouse; system32\DRIVERS\activmouse.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-22 17:35 - 2013-07-22 17:35 - 00143624 _____ C:\Windows\Minidump\Mini072213-03.dmp 2013-07-22 12:09 - 2013-07-22 12:09 - 00143624 _____ C:\Windows\Minidump\Mini072213-02.dmp 2013-07-22 11:51 - 2013-07-22 11:51 - 00000194 _____ C:\Users\Judith\Desktop\Fixlist.txt 2013-07-22 09:42 - 2013-07-22 09:42 - 00143624 _____ C:\Windows\Minidump\Mini072213-01.dmp 2013-07-20 20:20 - 2013-07-20 20:21 - 00143624 _____ C:\Windows\Minidump\Mini072013-11.dmp 2013-07-20 20:13 - 2013-07-20 20:13 - 00143624 _____ C:\Windows\Minidump\Mini072013-10.dmp 2013-07-20 20:07 - 2013-07-20 20:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-09.dmp 2013-07-20 19:15 - 2013-07-20 19:15 - 00143624 _____ C:\Windows\Minidump\Mini072013-08.dmp 2013-07-20 19:07 - 2013-07-20 19:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-07.dmp 2013-07-20 19:00 - 2013-07-20 19:00 - 00143624 _____ C:\Windows\Minidump\Mini072013-06.dmp 2013-07-20 18:26 - 2013-07-20 18:27 - 00143624 _____ C:\Windows\Minidump\Mini072013-05.dmp 2013-07-20 18:20 - 2013-07-20 18:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-04.dmp 2013-07-20 18:14 - 2013-07-20 18:14 - 00143624 _____ C:\Windows\Minidump\Mini072013-03.dmp 2013-07-20 18:04 - 2013-07-20 18:06 - 00001885 _____ C:\AdwCleaner[S3].txt 2013-07-20 17:50 - 2013-07-20 17:51 - 00143624 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 17:44 - 2013-07-20 17:44 - 00143624 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 17:43 - 2013-07-22 17:35 - 219078175 _____ C:\Windows\MEMORY.DMP 2013-07-20 13:10 - 2013-07-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Judith\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-20 13:09 - 2013-07-20 13:09 - 00602112 _____ (OldTimer Tools) C:\Users\Judith\Downloads\OTL.exe 2013-07-20 12:48 - 2013-07-20 12:52 - 00004974 _____ C:\Windows\ie8_main.log 2013-07-20 12:48 - 2013-07-20 12:48 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-20 12:45 - 2013-07-20 12:46 - 14938992 _____ (Microsoft Corporation) C:\Users\Judith\Downloads\IE8-WindowsVista-x86-DEU.exe 2013-07-20 12:45 - 2013-07-20 12:45 - 21703480 _____ (Mozilla) C:\Users\Judith\Downloads\Firefox_Setup_22.0.exe 2013-07-19 17:45 - 2013-07-19 17:45 - 00000000 ____D C:\Program Files\ESET 2013-07-19 17:45 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Desktop\SecurityCheck.exe 2013-07-19 17:34 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Downloads\SecurityCheck.exe 2013-07-19 17:33 - 2013-07-19 17:33 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu (1).exe 2013-07-19 15:22 - 2013-07-19 15:22 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu.exe 2013-07-19 13:26 - 2013-07-22 09:57 - 00026496 _____ C:\Users\Judith\Downloads\Addition.txt 2013-07-19 13:23 - 2013-07-19 13:23 - 00003328 _____ C:\Users\Judith\Desktop\JRT.txt 2013-07-19 12:03 - 2013-07-19 12:03 - 00000000 ____D C:\Windows\ERUNT 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Downloads\JRT.exe 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Desktop\JRT.exe 2013-07-19 11:50 - 2013-07-19 11:52 - 00011518 _____ C:\AdwCleaner[S2].txt 2013-07-19 11:50 - 2013-07-19 11:52 - 00000098 _____ C:\Windows\DeleteOnReboot.bat 2013-07-19 11:50 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Desktop\adwcleaner2305.exe 2013-07-19 11:18 - 2013-07-19 11:18 - 00030260 _____ C:\ComboFix.txt 2013-07-19 10:47 - 2013-07-19 10:45 - 05091168 ____R (Swearware) C:\Users\Judith\Desktop\ComboFix.exe 2013-07-19 10:47 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-19 10:47 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-19 10:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-19 10:47 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-19 10:46 - 2013-07-19 11:18 - 00000000 ____D C:\Qoobox 2013-07-19 10:45 - 2013-07-19 11:15 - 00000000 ____D C:\Windows\erdnt 2013-07-19 10:44 - 2013-07-19 10:45 - 05091168 ____R (Swearware) C:\Users\Judith\Downloads\ComboFix.exe 2013-07-18 19:58 - 2013-07-18 19:58 - 00000000 ____D C:\FRST 2013-07-18 19:56 - 2013-07-18 19:56 - 01218860 _____ (Farbar) C:\Users\Judith\Downloads\FRST.exe 2013-07-18 19:53 - 2013-07-18 19:53 - 00000000 ____D C:\Users\Judith\Qtrax 2013-07-18 19:48 - 2013-07-18 19:48 - 00793536 _____ C:\Users\Judith\Downloads\ZipOpenerSetup.exe 2013-07-18 17:13 - 2013-07-18 17:14 - 00033686 _____ C:\AdwCleaner[S1].txt 2013-07-18 17:12 - 2013-07-18 17:12 - 00033720 _____ C:\AdwCleaner[R1].txt 2013-07-18 17:11 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Downloads\adwcleaner2305.exe 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setuperr.log 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setupact.log 2013-07-17 12:22 - 2013-07-20 17:38 - 00006232 _____ C:\Windows\PFRO.log 2013-07-16 23:17 - 2013-07-18 16:41 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-07-16 23:16 - 2013-07-22 11:56 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Windows Net Data 2013-07-16 23:15 - 2013-06-27 07:14 - 00031816 _____ C:\Windows\Launcher.exe 2013-07-16 23:04 - 2013-07-16 23:04 - 00000000 ____D C:\Users\Judith\AppData\Local\Software Updater 2013-07-16 22:03 - 2013-07-16 22:06 - 00000000 ____D C:\Windows\system32\MRT 2013-07-16 20:10 - 2013-07-16 20:10 - 00283168 _____ C:\Users\Judith\Downloads\Setup (1).exe 2013-07-16 14:35 - 2013-07-16 14:35 - 00895488 _____ M:\Dokumente\Visitenkarten.doc 2013-07-13 03:25 - 2013-07-13 03:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2845142_WM64$ 2013-07-13 03:25 - 2007-07-27 10:41 - 00016760 ____N (Microsoft Corporation) C:\Windows\system32\spmsg.dll 2013-07-12 16:40 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-12 16:39 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-12 16:39 - 2013-05-29 13:30 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 16:39 - 2013-05-29 13:30 - 00916480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 16:39 - 2013-05-29 13:30 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-12 16:39 - 2013-05-29 13:28 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 06016000 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll 2013-07-12 16:39 - 2013-05-29 13:26 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00630272 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-12 16:39 - 2013-05-29 13:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 11111424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 02004992 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-12 16:39 - 2013-05-29 13:24 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-12 16:39 - 2013-05-29 13:24 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-12 16:39 - 2013-05-29 11:47 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-12 16:39 - 2013-05-29 10:07 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-12 16:39 - 2013-05-29 10:06 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-12 16:39 - 2013-05-29 10:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-12 16:39 - 2013-05-29 10:04 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 16:39 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-12 16:39 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-12 16:39 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-12 16:39 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-12 16:39 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-12 16:39 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-12 16:39 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-12 16:38 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 21:53 - 2013-07-10 21:53 - 00024064 _____ M:\Dokumente\Windows Phone Store.doc 2013-07-10 21:51 - 2013-07-10 21:51 - 00000840 _____ C:\Users\Judith\Desktop\Wuala.lnk 2013-07-10 21:48 - 2013-07-22 18:36 - 00000000 ___RD C:\Users\Judith\Dropbox 2013-07-10 21:48 - 2013-07-10 21:48 - 00000992 _____ C:\Users\Judith\Desktop\Dropbox.lnk 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala OverlayIcons 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala CBFS 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-10 21:47 - 2013-07-10 21:45 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-10 21:47 - 2012-04-09 16:27 - 00299024 _____ (EldoS Corporation) C:\Windows\system32\Drivers\cbfs3.sys 2013-07-10 21:47 - 2012-04-09 16:27 - 00223760 _____ (EldoS Corporation) C:\Windows\system32\CbFsNetRdr3.dll 2013-07-10 21:47 - 2012-04-09 16:27 - 00158224 _____ (EldoS Corporation) C:\Windows\system32\CbFsMntNtf3.dll 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-10 21:44 - 2013-07-10 21:44 - 00000000 ____D C:\Program Files\Dropbox 2013-07-10 21:43 - 2013-07-10 21:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-10 21:40 - 2013-07-22 18:36 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Dropbox 2013-07-10 21:39 - 2013-07-10 21:40 - 33578320 _____ (Dropbox, Inc.) C:\Users\Judith\Downloads\Dropbox 2.2.8.exe 2013-07-10 21:38 - 2013-07-10 21:38 - 00000000 ____D M:\Dokumente\Mein SugarSync 2013-07-10 21:36 - 2013-07-10 21:38 - 00000000 ____D C:\Users\Judith\AppData\Local\SugarSync 2013-07-10 21:35 - 2013-07-10 21:35 - 00001692 _____ C:\Users\Public\Desktop\SugarSync.lnk 2013-07-10 21:35 - 2013-01-30 13:12 - 00225024 _____ (EldoS Corporation) C:\Windows\system32\SSCbFsNetRdr3.dll 2013-07-10 21:35 - 2013-01-30 13:12 - 00159488 _____ (EldoS Corporation) C:\Windows\system32\SSCbFsMntNtf3.dll 2013-07-10 21:33 - 2013-07-10 21:42 - 00000828 _____ C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wuala.lnk 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Wuala 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Local\Wuala 2013-07-10 21:33 - 2013-01-30 13:11 - 00295936 _____ (EldoS Corporation) C:\Windows\system32\Drivers\sscbfs3.sys 2013-07-10 21:32 - 2013-07-10 21:35 - 00000000 ____D C:\Program Files\SugarSync 2013-07-10 21:29 - 2013-07-10 21:29 - 22964952 _____ C:\Users\Judith\Downloads\WualaSetup_04_13.exe 2013-07-10 21:27 - 2013-07-10 21:28 - 20911672 _____ (SugarSync, Inc.) C:\Users\Judith\Downloads\SugarSyncSetup_2.0.27.exe 2013-07-07 21:25 - 2013-07-07 21:25 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00001853 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\ProgramData\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\Program Files\Avira 2013-07-07 21:21 - 2013-06-20 14:48 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-07 21:21 - 2013-03-06 16:13 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-07 21:21 - 2012-08-27 15:50 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-07 21:04 - 2013-07-07 21:06 - 104943936 _____ C:\Users\Judith\Downloads\avira3737_free_antivirus_de.exe 2013-07-01 18:20 - 2013-07-01 18:20 - 00005384 _____ C:\Users\Judith\Downloads\Mundharmonika+Noten.htm (7).html 2013-06-28 11:52 - 2013-06-28 11:52 - 00000865 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-06-28 11:50 - 2013-06-28 11:51 - 22937227 _____ C:\Users\Judith\Downloads\vlc-2.0.7-win32.exe 2013-06-24 18:21 - 2013-06-24 18:21 - 00024064 _____ M:\Dokumente\Schreib-ab homepage.doc 2013-06-24 17:53 - 2013-07-20 12:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-06-24 17:25 - 2013-06-24 17:25 - 00001038 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-06-24 12:29 - 2013-06-24 12:29 - 00017196 _____ C:\Users\Judith\.recently-used.xbel ==================== One Month Modified Files and Folders ======= 2013-07-23 12:11 - 2012-03-04 13:20 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-23 12:09 - 2012-11-24 15:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA.job 2013-07-23 11:36 - 2006-11-02 14:52 - 01339706 _____ C:\Windows\WindowsUpdate.log 2013-07-23 11:34 - 2012-11-28 17:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-23 09:18 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-23 09:18 - 2006-11-02 14:47 - 00003664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-22 23:14 - 2011-07-22 18:56 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Skype 2013-07-22 21:38 - 2012-03-04 13:19 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-22 18:38 - 2006-11-02 12:33 - 01560022 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-22 18:37 - 2012-12-10 21:36 - 00000000 __SHD C:\Users\Judith\wc 2013-07-22 18:37 - 2012-12-10 21:35 - 00000000 ____D C:\Users\Judith\AppData\Roaming\COMPUTERBILD Cloud 2013-07-22 18:36 - 2013-07-10 21:48 - 00000000 ___RD C:\Users\Judith\Dropbox 2013-07-22 18:36 - 2013-07-10 21:40 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Dropbox 2013-07-22 18:32 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-22 18:15 - 2010-05-25 18:16 - 00008524 _____ C:\Windows\bthservsdp.dat 2013-07-22 18:15 - 2006-11-02 15:01 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-22 17:41 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-22 17:35 - 2013-07-22 17:35 - 00143624 _____ C:\Windows\Minidump\Mini072213-03.dmp 2013-07-22 17:35 - 2013-07-20 17:43 - 219078175 _____ C:\Windows\MEMORY.DMP 2013-07-22 17:35 - 2012-02-13 21:18 - 00000000 ____D C:\Windows\Minidump 2013-07-22 12:09 - 2013-07-22 12:09 - 00143624 _____ C:\Windows\Minidump\Mini072213-02.dmp 2013-07-22 11:56 - 2013-07-16 23:16 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Windows Net Data 2013-07-22 11:51 - 2013-07-22 11:51 - 00000194 _____ C:\Users\Judith\Desktop\Fixlist.txt 2013-07-22 11:51 - 2008-12-10 20:45 - 00000000 ___RD C:\Users\Judith\Desktop 2013-07-22 10:02 - 2013-01-01 15:20 - 00000000 ____D C:\Users\Judith\Downloads\Mercedes USB STick 2013-07-22 09:57 - 2013-07-19 13:26 - 00026496 _____ C:\Users\Judith\Downloads\Addition.txt 2013-07-22 09:42 - 2013-07-22 09:42 - 00143624 _____ C:\Windows\Minidump\Mini072213-01.dmp 2013-07-20 20:21 - 2013-07-20 20:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-11.dmp 2013-07-20 20:13 - 2013-07-20 20:13 - 00143624 _____ C:\Windows\Minidump\Mini072013-10.dmp 2013-07-20 20:07 - 2013-07-20 20:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-09.dmp 2013-07-20 19:15 - 2013-07-20 19:15 - 00143624 _____ C:\Windows\Minidump\Mini072013-08.dmp 2013-07-20 19:07 - 2013-07-20 19:07 - 00143624 _____ C:\Windows\Minidump\Mini072013-07.dmp 2013-07-20 19:00 - 2013-07-20 19:00 - 00143624 _____ C:\Windows\Minidump\Mini072013-06.dmp 2013-07-20 18:52 - 2008-12-13 16:15 - 00000000 ____D M:\Dokumente\Programme 2013-07-20 18:27 - 2013-07-20 18:26 - 00143624 _____ C:\Windows\Minidump\Mini072013-05.dmp 2013-07-20 18:20 - 2013-07-20 18:20 - 00143624 _____ C:\Windows\Minidump\Mini072013-04.dmp 2013-07-20 18:14 - 2013-07-20 18:14 - 00143624 _____ C:\Windows\Minidump\Mini072013-03.dmp 2013-07-20 18:06 - 2013-07-20 18:04 - 00001885 _____ C:\AdwCleaner[S3].txt 2013-07-20 17:59 - 2009-10-26 21:40 - 00000000 ____D C:\Users\Judith\Downloads\USB Stick grau 1 2013-07-20 17:51 - 2013-07-20 17:50 - 00143624 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 17:44 - 2013-07-20 17:44 - 00143624 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 17:38 - 2013-07-17 12:22 - 00006232 _____ C:\Windows\PFRO.log 2013-07-20 17:38 - 2012-04-27 17:53 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-20 13:10 - 2013-07-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Judith\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-20 13:09 - 2013-07-20 13:09 - 00602112 _____ (OldTimer Tools) C:\Users\Judith\Downloads\OTL.exe 2013-07-20 12:52 - 2013-07-20 12:48 - 00004974 _____ C:\Windows\ie8_main.log 2013-07-20 12:50 - 2008-12-13 11:46 - 00000000 ____D C:\Users\Judith\AppData\Local\Adobe 2013-07-20 12:48 - 2013-07-20 12:48 - 00000852 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-20 12:48 - 2013-06-24 17:53 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 12:46 - 2013-07-20 12:45 - 14938992 _____ (Microsoft Corporation) C:\Users\Judith\Downloads\IE8-WindowsVista-x86-DEU.exe 2013-07-20 12:45 - 2013-07-20 12:45 - 21703480 _____ (Mozilla) C:\Users\Judith\Downloads\Firefox_Setup_22.0.exe 2013-07-20 11:45 - 2008-12-10 20:46 - 00183296 _____ C:\Users\Judith\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-20 11:43 - 2006-11-02 14:47 - 00530840 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-20 11:34 - 2009-01-05 14:33 - 00027430 _____ C:\Users\Judith\AppData\Roaming\nvModes.001 2013-07-20 11:32 - 2013-02-17 16:41 - 00000000 ____D C:\Program Files\Freetec 2013-07-20 11:32 - 2013-02-17 16:39 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-20 11:31 - 2012-01-09 17:23 - 00000000 ____D M:\Dokumente\VirtualDJ 2013-07-20 11:30 - 2009-01-10 19:23 - 00000000 ____D C:\Program Files\OpenOffice.org 3 2013-07-19 17:45 - 2013-07-19 17:45 - 00000000 ____D C:\Program Files\ESET 2013-07-19 17:34 - 2013-07-19 17:45 - 00891062 _____ C:\Users\Judith\Desktop\SecurityCheck.exe 2013-07-19 17:34 - 2013-07-19 17:34 - 00891062 _____ C:\Users\Judith\Downloads\SecurityCheck.exe 2013-07-19 17:33 - 2013-07-19 17:33 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu (1).exe 2013-07-19 15:22 - 2013-07-19 15:22 - 02347384 _____ (ESET) C:\Users\Judith\Downloads\esetsmartinstaller_enu.exe 2013-07-19 13:23 - 2013-07-19 13:23 - 00003328 _____ C:\Users\Judith\Desktop\JRT.txt 2013-07-19 12:03 - 2013-07-19 12:03 - 00000000 ____D C:\Windows\ERUNT 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Downloads\JRT.exe 2013-07-19 12:02 - 2013-07-19 12:02 - 00559341 _____ (Oleg N. Scherbakov) C:\Users\Judith\Desktop\JRT.exe 2013-07-19 11:52 - 2013-07-19 11:50 - 00011518 _____ C:\AdwCleaner[S2].txt 2013-07-19 11:52 - 2013-07-19 11:50 - 00000098 _____ C:\Windows\DeleteOnReboot.bat 2013-07-19 11:18 - 2013-07-19 11:18 - 00030260 _____ C:\ComboFix.txt 2013-07-19 11:18 - 2013-07-19 10:46 - 00000000 ____D C:\Qoobox 2013-07-19 11:18 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-07-19 11:18 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-19 11:15 - 2013-07-19 10:45 - 00000000 ____D C:\Windows\erdnt 2013-07-19 11:09 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-07-19 11:07 - 2006-11-02 12:22 - 59244544 _____ C:\Windows\system32\config\SOFTWARE.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 45350912 _____ C:\Windows\system32\config\COMPON~2.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 24903680 _____ C:\Windows\system32\config\SYSTEM.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00786432 _____ C:\Windows\system32\config\DEFAULT.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak 2013-07-19 11:07 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\SAM.bak 2013-07-19 11:04 - 2008-12-10 20:45 - 00000000 ____D C:\Users\Judith 2013-07-19 10:45 - 2013-07-19 10:47 - 05091168 ____R (Swearware) C:\Users\Judith\Desktop\ComboFix.exe 2013-07-19 10:45 - 2013-07-19 10:44 - 05091168 ____R (Swearware) C:\Users\Judith\Downloads\ComboFix.exe 2013-07-18 19:58 - 2013-07-18 19:58 - 00000000 ____D C:\FRST 2013-07-18 19:56 - 2013-07-18 19:56 - 01218860 _____ (Farbar) C:\Users\Judith\Downloads\FRST.exe 2013-07-18 19:53 - 2013-07-18 19:53 - 00000000 ____D C:\Users\Judith\Qtrax 2013-07-18 19:48 - 2013-07-18 19:48 - 00793536 _____ C:\Users\Judith\Downloads\ZipOpenerSetup.exe 2013-07-18 17:14 - 2013-07-18 17:13 - 00033686 _____ C:\AdwCleaner[S1].txt 2013-07-18 17:13 - 2008-12-13 19:22 - 00000000 ____D C:\ProgramData\ICQ 2013-07-18 17:13 - 2008-12-13 13:43 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-18 17:12 - 2013-07-18 17:12 - 00033720 _____ C:\AdwCleaner[R1].txt 2013-07-18 17:11 - 2013-07-19 11:50 - 00662345 _____ C:\Users\Judith\Desktop\adwcleaner2305.exe 2013-07-18 17:11 - 2013-07-18 17:11 - 00662345 _____ C:\Users\Judith\Downloads\adwcleaner2305.exe 2013-07-18 16:41 - 2013-07-16 23:17 - 00000830 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-07-18 14:38 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setuperr.log 2013-07-18 13:19 - 2013-07-18 13:19 - 00000000 _____ C:\Windows\setupact.log 2013-07-18 03:09 - 2012-11-24 15:33 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core.job 2013-07-17 14:02 - 2008-12-13 19:48 - 00000000 ____D M:\Dokumente\Sicherung 2013-07-17 12:06 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\ShellNew 2013-07-17 11:49 - 2011-11-22 19:00 - 00000000 ____D C:\Program Files\DsNET Corp 2013-07-16 23:04 - 2013-07-16 23:04 - 00000000 ____D C:\Users\Judith\AppData\Local\Software Updater 2013-07-16 22:06 - 2013-07-16 22:03 - 00000000 ____D C:\Windows\system32\MRT 2013-07-16 20:10 - 2013-07-16 20:10 - 00283168 _____ C:\Users\Judith\Downloads\Setup (1).exe 2013-07-16 14:35 - 2013-07-16 14:35 - 00895488 _____ M:\Dokumente\Visitenkarten.doc 2013-07-16 12:14 - 2008-12-13 12:30 - 00002637 _____ C:\Users\Judith\Desktop\Microsoft Office Word 2003.lnk 2013-07-14 20:33 - 2012-01-20 19:03 - 00000000 ____D M:\Dokumente\Handys N97 Galaxy Ace 2013-07-13 04:07 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-13 03:48 - 2008-12-13 12:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-13 03:47 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-13 03:25 - 2013-07-13 03:25 - 00000000 __HDC C:\Windows\$NtUninstallKB2845142_WM64$ 2013-07-13 03:02 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 09:31 - 2008-12-13 12:53 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Mozilla 2013-07-10 21:53 - 2013-07-10 21:53 - 00024064 _____ M:\Dokumente\Windows Phone Store.doc 2013-07-10 21:51 - 2013-07-10 21:51 - 00000840 _____ C:\Users\Judith\Desktop\Wuala.lnk 2013-07-10 21:48 - 2013-07-10 21:48 - 00000992 _____ C:\Users\Judith\Desktop\Dropbox.lnk 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala OverlayIcons 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Wuala CBFS 2013-07-10 21:47 - 2013-07-10 21:47 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-10 21:45 - 2013-07-10 21:47 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-10 21:45 - 2013-07-10 21:45 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-10 21:45 - 2012-06-30 12:00 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-10 21:45 - 2011-12-22 15:59 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-10 21:44 - 2013-07-10 21:44 - 00000000 ____D C:\Program Files\Dropbox 2013-07-10 21:43 - 2013-07-10 21:43 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-10 21:42 - 2013-07-10 21:33 - 00000828 _____ C:\Users\Judith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wuala.lnk 2013-07-10 21:40 - 2013-07-10 21:39 - 33578320 _____ (Dropbox, Inc.) C:\Users\Judith\Downloads\Dropbox 2.2.8.exe 2013-07-10 21:40 - 2010-02-17 17:02 - 00039424 _____ M:\Dokumente\mailaccounts community Free sms accounts.doc 2013-07-10 21:38 - 2013-07-10 21:38 - 00000000 ____D M:\Dokumente\Mein SugarSync 2013-07-10 21:38 - 2013-07-10 21:36 - 00000000 ____D C:\Users\Judith\AppData\Local\SugarSync 2013-07-10 21:35 - 2013-07-10 21:35 - 00001692 _____ C:\Users\Public\Desktop\SugarSync.lnk 2013-07-10 21:35 - 2013-07-10 21:32 - 00000000 ____D C:\Program Files\SugarSync 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Wuala 2013-07-10 21:33 - 2013-07-10 21:33 - 00000000 ____D C:\Users\Judith\AppData\Local\Wuala 2013-07-10 21:29 - 2013-07-10 21:29 - 22964952 _____ C:\Users\Judith\Downloads\WualaSetup_04_13.exe 2013-07-10 21:28 - 2013-07-10 21:27 - 20911672 _____ (SugarSync, Inc.) C:\Users\Judith\Downloads\SugarSyncSetup_2.0.27.exe 2013-07-07 21:25 - 2013-07-07 21:25 - 00000000 ____D C:\Users\Judith\AppData\Roaming\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00001853 _____ C:\Users\Public\Desktop\Avira Control Center.lnk 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\ProgramData\Avira 2013-07-07 21:21 - 2013-07-07 21:21 - 00000000 ____D C:\Program Files\Avira 2013-07-07 21:06 - 2013-07-07 21:04 - 104943936 _____ C:\Users\Judith\Downloads\avira3737_free_antivirus_de.exe 2013-07-06 17:47 - 2012-08-30 13:55 - 00000000 ____D C:\Users\Judith\AppData\Roaming\vlc 2013-07-06 15:41 - 2010-01-15 17:53 - 00000000 ____D C:\Users\Judith\AppData\Roaming\dvdcss 2013-07-01 19:15 - 2008-12-13 16:17 - 00000000 ____D M:\Dokumente\Allerlei 2013-07-01 18:20 - 2013-07-01 18:20 - 00005384 _____ C:\Users\Judith\Downloads\Mundharmonika+Noten.htm (7).html 2013-06-28 15:16 - 2008-12-13 18:22 - 00074752 _____ C:\Users\Judith\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-06-28 11:52 - 2013-06-28 11:52 - 00000865 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-06-28 11:51 - 2013-06-28 11:50 - 22937227 _____ C:\Users\Judith\Downloads\vlc-2.0.7-win32.exe 2013-06-27 14:47 - 2013-04-01 16:03 - 00000000 ____D M:\Dokumente\Flug USA Herbst 2013 2013-06-27 07:14 - 2013-07-16 23:15 - 00031816 _____ C:\Windows\Launcher.exe 2013-06-24 18:23 - 2011-03-28 18:58 - 00000000 ____D C:\Users\Judith\AppData\Roaming\DVDVideoSoft 2013-06-24 18:21 - 2013-06-24 18:21 - 00024064 _____ M:\Dokumente\Schreib-ab homepage.doc 2013-06-24 17:26 - 2008-12-13 13:43 - 00000000 ____D C:\Program Files\DVDVideoSoft 2013-06-24 17:25 - 2013-06-24 17:25 - 00001038 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-06-24 17:14 - 2012-10-13 13:42 - 70431848 _____ (DVDVideoSoft Ltd. ) C:\Users\Judith\Downloads\FreeStudio.exe 2013-06-24 12:30 - 2010-08-09 12:10 - 00000000 ____D C:\Users\Judith\.gimp-2.6 2013-06-24 12:29 - 2013-06-24 12:29 - 00017196 _____ C:\Users\Judith\.recently-used.xbel 2013-06-24 00:37 - 2006-11-02 12:24 - 75733144 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-22 18:39 ==================== End Of Log ============================ --- --- --- --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 17-07-2013 02 Ran by Judith at 2013-07-23 12:18:42 Running from C:\Users\Judith\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= AAVUpdateManager (Version: 18.00.0000) Acronis*True*Image*Home (Version: 10.0.4942) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) Apple Application Support (Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (Version: 2.1.3.127) Ashampoo Burning Studio 2013 v.11.0.5 (Version: 11.0.5) Audacity 1.2.6 Audacity 1.3.6 (Unicode) Audials (Version: 10.1.509.900) Audiograbber 1.83 SE (Version: 1.83 SE) Avidemux 2.5 (Version: 2.5.1.5249) Avira Free Antivirus (Version: 13.0.0.3737) AVS Screen Capture version 2.0.2 AVS Update Manager 1.0 AVS Video Editor 6 AVS Video Recorder 2.5 AVS4YOU Software Navigator 1.4 Bonjour (Version: 3.0.0.10) capella 7 (Version: 7.1.6) CCleaner (Version: 3.25) CD- und DVD-Sharing (Version: 1.0.1.4) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) COMPUTERBILD-Cloud D3DX10 (Version: 15.4.2368.0902) Dell Resource CD (Version: 1.00.0000) DivxToDVD 0.5.2b (Version: 0.5.2b) Dropbox (HKCU Version: 2.2.8) DSL-Manager EclipseCrossword (Version: 1.2.57) ESET Online Scanner v3 FileZilla Client 3.6.0.2 (Version: 3.6.0.2) FormatFactory 2.50 (Version: 2.50) Forte Free 2.0 Free Audio CD Burner version 1.4.7 Free Studio version 2013 (Version: 6.1.3.622) Free Video to iPod Converter version 4.2.16.305 Free Video to JPG Converter version 1.5 Free Video to MP3 Converter version 3.2 Free YouTube Download 2.9 Free YouTube to iPod Converter version 3.2 Free YouTube to MP3 Converter version 3.11.34.1015 (Version: 3.11.34.1015) FreeMind (Version: 0.8.1) GIMP 2.6.12 (Version: 2.6.12) GOM Player (Version: 2.1.40.5106) Google Chrome (HKCU Version: 28.0.1500.72) Google Earth (Version: 6.2.0.5905) Google Talk Plugin (Version: 4.2.1.14031) Google Update Helper (Version: 1.3.21.153) Hervorhebe-Funktion (Windows Live Toolbar) (Version: 03.01.0146) HotPotatoes v 6.3.0.3 ICQ 8.0 (build 6014) (HKCU Version: 8.0.6014.0) ICQ Sparberater (Version: 1.4.9) IsoBuster 2.3 (Version: 2.3) iTunes (Version: 11.0.0.163) Japanese Fonts Support For Adobe Reader 9 (Version: 9.0.0) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Junk Mail filter update (Version: 15.4.3502.0922) MAGIX Foto Manager 10 (Version: 8.0.1.136) MAGIX Online Druck Service (Version: 3.4.3.0) MAGIX Screenshare (Version: 4.3.6.1987) MAGIX Xtreme Foto & Grafik Designer 5 (Silver) (Version: 5.1.2.15876) MediaDirect (Version: 4.7) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Standard Edition 2003 (Version: 11.0.8173.0) Microsoft Search Enhancement Pack (Version: 3.0.133.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Windows Media Video 9 VCM Microsoft XML Parser (Version: 8.0.7820.0) MindManager Smart (Version: 2.1.3) Mozilla Firefox 22.0 (x86 de) (Version: 22.0) Mozilla Maintenance Service (Version: 22.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) neroxml (Version: 1.0.0) No23 Recorder (Version: 2.1.0.3) Notepad++ (Version: 6.2.3) NVIDIA Drivers Octava SD4 (Version: 5.01) OutlookAddinSetup (Version: 1.0.0) Paragon Partition Manager 2007 PDF24 Creator 5.2.0 PDFCreator (Version: 1.2.3) Pfadfinder 2.0 (Version: 1.0.7) Phase 5 HTML-Editor (Version: 5.6.2.3) Phoenix Backup Professional (Version: 3.5.000) PixiePack Codec Pack (Version: 1.1.400.0) Plus-HD-2.3 (Version: 1.27.153.8) QuickTime (Version: 7.72.80.56) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealPlayer (Version: 15.0.4) RealUpgrade 1.1 (Version: 1.1.0) River Past Video Cleaner Pro (Version: 7.7.7) Roxio Creator Audio (Version: 3.3.0) Roxio Creator Copy (Version: 3.3.0) Roxio Creator Data (Version: 3.3.0) Roxio Creator DE (Version: 3.3.0) Roxio Creator Tools (Version: 3.3.0) Roxio Drag-to-Disc (Version: 9.0) Roxio Express Labeler (Version: 2.1.0) Roxio MyDVD DE (Version: 9.0.117) Roxio Update Manager (Version: 3.0.0) Rund um (2.0) ... Erlebnis Biologie 1 RS (Version: 1.00.0000) Rund um (2.0) ... Erlebnis Chemie RP HE NI (Version: 1.00.0000) Rund um (2.0) ... Erlebnis Naturwissenschaften 5 RP (Version: 1.00.0000) Rund um ... Biologie heute entdecken 1 (Version: 1.00.0000) Rund um ... Biologie heute entdecken 2 (Teil 1) (Version: 1.00.0000) Rund um ... Biologie heute entdecken 2 (Teil 2) (Version: 1.00.0000) Segoe UI (Version: 15.4.2271.0615) Sicherheitsupdate für Windows Media Player (KB2845142) SigmaTel Audio (Version: 5.10.5210.0) Skype™ 6.5 (Version: 6.5.158) Smart Menus (Windows Live Toolbar) (Version: 03.01.0146) Sonic Activation Module (Version: 1.0) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0) Steuer-Spar-Erklärung 2011 (Version: 16.17) Steuer-Spar-Erklärung 2012 (Version: 17.02) Streambox Vcr Suite 2 SugarSync (Version: 2.0.27.114357) Text-To-Speech-Runtime (Version: 1.0.0.0) Toxic Biohazard TubeBox (Version: 4.1.1.0) Ulead GIF Animator Lite Edition 1.0 Uninstall 1.0.0.1 Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) VLC media player 2.0.7 (Version: 2.0.7) VoiceOver Kit (Version: 1.30.128.0) White Christmas 3D Screensaver and Animated Wallpaper 1.0 (Version: 1.0) WIDCOMM Bluetooth Software 6.0.1.3100 (Version: 6.0.1.3100) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Toolbar-Erweiterung (Windows Live Toolbar) (Version: 03.01.0146) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0) Windows Utils WinRAR archiver Wuala (HKCU Version: 1.0.428.0) Wuala CBFS (Version: 3.2.107.0) Wuala OverlayIcons (Version: 1.0.0.2) XMedia Recode 3.0.8.5 (Version: 3.0.8.5) ==================== Restore Points ========================= 10-07-2013 19:33:20 Gerätetreiber-Paketinstallation: SugarSync 10-07-2013 19:43:57 Installed Java 7 Update 25 11-07-2013 12:13:12 Geplanter Prüfpunkt 13-07-2013 01:00:57 Windows Update 14-07-2013 19:50:22 Geplanter Prüfpunkt 15-07-2013 11:45:56 Geplanter Prüfpunkt 16-07-2013 09:23:01 Geplanter Prüfpunkt 16-07-2013 20:02:16 Windows Update 16-07-2013 21:05:28 Free YouTube Download Manager 17-07-2013 09:50:36 JavaFX 2.1.1 wird entfernt 17-07-2013 09:52:26 Removed LibreOffice 3.6 17-07-2013 22:00:04 Geplanter Prüfpunkt 19-07-2013 08:47:18 ComboFix created restore point 19-07-2013 08:49:20 ComboFix created restore point 20-07-2013 09:25:52 OpenOffice.org 3.1 wird entfernt 20-07-2013 09:30:26 Removed VirtualDJ Home FREE 20-07-2013 09:31:37 Free YouTube Download Manager 22-07-2013 15:48:36 Windows Update ==================== Hosts content: ========================== 2010-11-10 18:16 - 2013-07-19 11:05 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {07EFF3F8-57E9-4060-AC8B-63C03D320C8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0DF7E8C6-4CF7-4DE8-8BAA-516D9BB205F9} - System32\Tasks\EPUpdater => C:\Users\Judith\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File Task: {18BF61D8-8C4D-46C1-A397-EB7A6DC96E58} - System32\Tasks\{658EA475-F343-45E9-AF82-B67E5CDA0A49} => c:\program files\mozilla firefox\firefox.exe [2013-06-18] (Mozilla Corporation) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2461E8E9-EE40-4DBD-A19C-B63B76A58539} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {2DB895D9-D2FC-42EA-B3EF-22E6FC0EE2F5} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {36D7A5B8-4472-4F24-A887-D37F62033E77} - System32\Tasks\{1CCCC0B6-CFDB-4CC2-A42A-85FEE189240A} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3C6D8EF0-298B-4F31-80A7-9F3D060DE516} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3758001449-3176424044-3867666295-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {3D5CB9AB-CBA4-4773-8496-A0BB1355C097} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {4692C054-BD6B-44FE-AC34-6E8EF7BED887} - System32\Tasks\Hoolapp Init => C:\Users\Judith\AppData\Roaming\HOOLAP~1\Hoolapp.exe No File Task: {521E92D9-3347-43B0-8FD9-81111C6875F5} - System32\Tasks\icqSWU => C:\Windows\System32\cscript.exe [2009-04-11] (Microsoft Corporation) Task: {5392E7AF-501E-42B5-9C13-F4F38D0AB0FA} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {54427084-6145-4C10-A6BE-3852819D9086} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-11-24] (Piriform Ltd) Task: {572A6935-217D-4A4B-A21E-F741DF8B66F0} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation) Task: {5EA3018C-5A19-4672-A5D9-1E6798A5DDB6} - System32\Tasks\Microsoft\Windows\RestartManager\{5A2F064A-6F7D-43b3-A3E7-66C404102C38} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {61858FB2-F17C-4365-A209-A1C513102D64} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation) Task: {6319641D-EF8F-47AB-8F8B-8686C8D0EF51} - System32\Tasks\Hoolapp For Android => C:\Users\Judith\AppData\Roaming\HOOLAP~1\UPDATE~1\UPDATE~1.EXE No File Task: {6C51054D-758B-4BAD-86DD-53F1A46E3A90} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3758001449-3176424044-3867666295-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-04-30] (RealNetworks, Inc.) Task: {8B3D2A13-BD5E-409A-B91D-4112FC8C84DF} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {937DE204-BC75-40F1-9F78-99C92C20A7F9} - System32\Tasks\{9FB8FE6B-80F2-4C6A-AF86-BBF69CEFAF15} => C:\Program Files\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {9B411A20-1FFE-430A-9A15-1FEEBA8C6738} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-04] (Google Inc.) Task: {9CEB093B-75B3-4E5C-82E3-0F00F56EEF97} - System32\Tasks\Microsoft\Windows\RestartManager\{413EBFE5-7F85-4328-8E7F-EE0B67E7758A} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {9EBD668F-185F-49E8-A084-D7A3454DC025} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-03-04] (Google Inc.) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {A860C6A5-C081-4512-A41B-3CDA091A9F23} - System32\Tasks\User_Feed_Synchronization-{FFEC623E-F341-4E38-8943-ABB2B7D24138} => C:\Windows\system32\msfeedssync.exe [2013-05-29] (Microsoft Corporation) Task: {AB23B889-8915-4BBB-80B5-64EC1C18B82B} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Judith => C:\Program Files\Windows Calendar\wincal.exe [2009-04-11] (Microsoft Corporation) Task: {B15FE2B6-56A5-467A-83AD-9A5C39F49798} - \BrowserDefendert No Task File Task: {CA11AF58-3534-4B3A-B808-9E78362DCECC} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-24] (Google Inc.) Task: {CB162C08-E516-4B6C-BBBD-B990E6451AF1} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation) Task: {D0645CD6-D80F-4895-89A2-31762C52DF3B} - System32\Tasks\DSite => C:\Users\Judith\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File Task: {D36A0565-494E-4C1B-A28D-24EBCC2C4439} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DB14B352-D4C4-4BEA-81ED-DC36F12E827B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-24] (Google Inc.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000Core.job => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3758001449-3176424044-3867666295-1000UA.job => C:\Users\Judith\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{FFEC623E-F341-4E38-8943-ABB2B7D24138}.job => C:\Windows\system32\msfeedssync.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter #6 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Bluetooth Peripheral Device Description: Bluetooth Peripheral Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth Peripheral Device Description: Bluetooth Peripheral Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/22/2013 05:42:21 PM) (Source: Application Hang) (User: ) Description: Programm icq.exe, Version 8.0.6014.0 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: fb4 Anfangszeit: 01ce86f18961ffff Zeitpunkt der Beendigung: 25 Error: (07/22/2013 00:31:51 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 11:48:47 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 09:53:19 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 09:44:24 AM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:48:02 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:45:30 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:27:54 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:58:18 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:55:56 PM) (Source: EventSystem) (User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c System errors: ============= Error: (07/23/2013 00:08:05 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/23/2013 11:34:53 AM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/23/2013 09:18:34 AM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/22/2013 10:57:13 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/22/2013 09:38:32 PM) (Source: BTHUSB) (User: ) Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen. Error: (07/22/2013 06:34:05 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (07/22/2013 05:56:05 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (07/22/2013 05:42:01 PM) (Source: Service Control Manager) (User: ) Description: Windows Update Error: (07/22/2013 05:37:26 PM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (07/22/2013 05:35:50 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 22.07.2013 um 14:54:31 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= Error: (07/22/2013 05:42:21 PM) (Source: Application Hang)(User: ) Description: icq.exe8.0.6014.0fb401ce86f18961ffff25 Error: (07/22/2013 00:31:51 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 11:48:47 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 09:53:19 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/22/2013 09:44:24 AM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:48:02 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:45:30 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 06:27:54 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:58:18 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c Error: (07/20/2013 05:55:56 PM) (Source: EventSystem)(User: ) Description: d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp458007043c CodeIntegrity Errors: =================================== Date: 2013-07-20 14:48:55.523 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:55.222 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.945 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.665 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.385 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-20 14:48:54.085 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:59.555 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:59.226 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.844 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-07-17 15:37:58.504 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6001.22497_none_b34d67897fc6850f\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 57% Total physical RAM: 2045.31 MB Available physical RAM: 864.48 MB Total Pagefile: 4331.88 MB Available Pagefile: 2842.34 MB Total Virtual: 2047.88 MB Available Virtual: 1889.76 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:99.88 GB) (Free:30.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive j: (Samsung Festplatte neu) (Fixed) (Total:931.51 GB) (Free:617.61 GB) NTFS Drive m: (Daten) (Fixed) (Total:130.95 GB) (Free:4.53 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: 00000080) Partition 1: (Not Active) - (Size=47 MB) - (Type=DE) Partition 2: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=133 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: 54349CA3) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Hmmm die andere Datei lässt sich weder in ein Zip Archiv stecken noch einfach so hier anfängen. Das ist eine zickige Datei. |
23.07.2013, 12:05 | #35 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Kannst Du die Datei per Mail schicken? schrauber(at)trojaner-board.de
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.07.2013, 12:35 | #36 |
| Problem: Internet Explorer Meldung getwindowinfo Ja, ist auf dem Weg! |
23.07.2013, 13:59 | #37 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Welche Probleme bestehen sonst noch mit der Kiste? Schick mir heut abend bitte mal ne PM damit ich an den Dump denke, kann von Arbeit aus keine Dumps öffnen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.07.2013, 14:10 | #38 |
| Problem: Internet Explorer Meldung getwindowinfo Momentan habe ich keine Probleme mehr. Ich hatte mal das Problem, dass sich ein "Dealfinder" immer wieder geöffnet hat. Aber der ist jetzt auch weg. Positiver Nebeneffekt! Läuft also alles wieder. Super !!! |
23.07.2013, 18:39 | #39 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Nix zu sehen. Teste den Rechner mal ein paar Tage und melde dich wieder
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.07.2013, 12:42 | #40 |
| Problem: Internet Explorer Meldung getwindowinfo Spitze. Vielen herzlichen Dank !!! |
24.07.2013, 14:40 | #41 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Dann räumen wir noch auf Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.07.2013, 22:21 | #42 |
| Problem: Internet Explorer Meldung getwindowinfo Oh da muss ich mich dann mal durcharbeiten. Ich werde mich aber genau an deine Vorgehensweise halten. Dann weiss ich ja was zu tun ist morgen ;-) Die Kiste läuft bis jetzt ohne Probleme. Ich hoffe das bleibt auch so. Danke nochmal für deine Hilfe !!! |
29.07.2013, 08:31 | #43 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.07.2013, 12:04 | #44 |
| Problem: Internet Explorer Meldung getwindowinfo Ha, ich habe was rausgefunden. Kaum war der Malwarebytes Anti Malware installiert ging es auch schon wieder los, dass sich meine Kiste wieder automatisch runter gefahren hat und dieser blaue Bildschirm kam wieder. Ich habe Malwarebytes Anti Malware sofort deinstalliert und siehe da, alles läuft wieder. Ist doch komisch, oder? Was anderes noch: Soll ich den CCleaner besser nicht verwenden? |
29.07.2013, 15:17 | #45 |
/// the machine /// TB-Ausbilder | Problem: Internet Explorer Meldung getwindowinfo Genau, besser nicht verwenden
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Problem: Internet Explorer Meldung getwindowinfo |
anzeige, avira, beschreiben, einfach, explorer, gestern, hierbei, interne, internet, internet explorer, leicht, malwarebytes, meldung, nichts, problem, schließe, schließen, virus, virus?, vorgehen, vorschlag, webseite, wunder, überhaupt, öffnet |