|
Log-Analyse und Auswertung: tcbhn wurde beendetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.08.2013, 12:35 | #31 |
| tcbhn wurde beendet Ich habe den PC damals beim Aldi gekauft und es war alles Installiert, ein Bekannter hat mir alles angeschlossen, deshalb weiss ich nicht ob es eine DVD gab. Ich habe alles durchsucht und leider keine für Vista gefunden. Aber eine CD mit Office XP Windows für den PC meiner Tochter. Nur zur Info ich habe eine Externe Festplatte darauf sind alle meine Sicherungen! Könnte ich Vister deinstallieren und XP draufspielen? Wie bekomme ich Firefox gelöscht? Ich habe mir Chrome runtergeladen! FRST: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-07-2013 Ran by Olaf at 2013-08-11 13:30:42 Running from C:\Users\Olaf\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Reader X (10.1.4) - Deutsch (Version: 10.1.4) Adobe Shockwave Player (Version: 11) Adobe® Photoshop® Album Starter Edition 3.2 (Version: 3.2.0) Apple Application Support (Version: 2.3.3) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (Version: 2.1.3.127) ArcSoft Software Suite Audacity 1.2.6 Avanquest update (Version: 1.21) Big Fish Games: Game Manager (Version: 3.0.1.60) Bonjour (Version: 3.0.0.10) CCleaner (Version: 2.36) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000) Corel Applications Creative DVD Audio Plugin for Audigy Series D3DX10 (Version: 15.4.2368.0902) DHTML Editing Component (Version: 6.02.0001) Driver Genius Professional Edition Echoes of the Past: Das versteinerte Königshaus Echoes of the Past: Die Zitadellen der Zeit Echoes of the Past: Die Zitadellen der Zeit Sammleredition Emsisoft Anti-Malware (Version: 8.0) Facebook Video Calling 1.2.0.287 (Version: 1.2.287) Firebird SQL Server - MAGIX Edition (Version: 2.1.27.0) FormatFactory 2.90 (Version: 2.90) Google Chrome (Version: 28.0.1500.95) Google Update Helper (Version: 1.3.21.153) Hardware Diagnose Tools (Version: 5.00.4262.12) HP Customer Experience Enhancements (Version: 1.00.0000) HP Easy Setup - Core (Version: 1.00.0000) HP Easy Setup - Frontend (Version: 5.00.0000) HP Picasso Media Center Add-In (Version: 1.0.0) HP Update (Version: 4.000.005.005) iCloud (Version: 2.1.1.3) Iminent (Version: 6.27.21.0) InstallRTC (Version: 1.0.0) Intel(R) Matrix Storage Manager Intel(R) PRO Network Connections Drivers Intel® Viiv™ Software (Version: 1.6.361.6) InterVideo DeviceService (Version: 1.0.0) InterVideo WinDVD 6 (Version: 6.0-B6.42) iTunes (Version: 11.0.2.26) Java 2 Runtime Environment, SE v1.4.2_14 (Version: 1.4.2_14) Java 7 Update 11 (Version: 7.0.110) Java Auto Updater (Version: 2.1.9.0) Java(TM) 6 Update 2 (Version: 1.6.0.20) Java(TM) 6 Update 29 (Version: 6.0.290) Java(TM) SE Runtime Environment 6 Update 1 (Version: 1.6.0.10) Junk Mail filter update (Version: 15.4.3502.0922) LightScribe 1.4.124.1 (Version: 1.4.124.1) LUMIX Simple Viewer (Version: 0.99.0000) MAGIX Foto Clinic 4.5 (D) (Version: 4.5.3.2) MAGIX Foto Manager 2006 (D) (Version: 3.0.1.71) MAGIX Fotos auf CD & DVD 5.0 deLuxe (D) (Version: 5.0.0.0) MAGIX Music Manager (D) (Version: 1.1.1.692) MAGIX Online Druck Service MAGIX Screenshare (Version: 4.3.6.1987) MAGIX Speed burnR (MSI) (Version: 7.0.2.6) Mesh Runtime (Version: 15.4.5722.2) Messenger Companion (Version: 15.4.3502.0922) Microsoft .NET Framework 1.1 (Version: 1.1.4322) Microsoft .NET Framework 1.1 German Language Pack (Version: 1.1.4322) Microsoft .NET Framework 1.1 Security Update (KB2698023) Microsoft .NET Framework 1.1 Security Update (KB2833941) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft LifeCam (Version: 1.40.164.0) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office XP Professional mit FrontPage (Version: 10.0.6626.0) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual J# .NET Redistributable Package 1.1 (Version: 1.1.4322) Microsoft Works (Version: 08.05.0822) Microsoft XML Parser (Version: 8.0.7820.0) MobileMe Control Panel (Version: 3.1.8.0) MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Nero 7 Premium (Version: 7.02.1290) NVIDIA 3D Vision Treiber 311.06 (Version: 311.06) NVIDIA Display Control Panel (Version: 6.14.12.5896) NVIDIA Grafiktreiber 311.06 (Version: 311.06) NVIDIA Install Application (Version: 2.1002.108.688) NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1106) NVIDIA Systemsteuerung 311.06 (Version: 311.06) NVIDIA Update 1.11.3 (Version: 1.11.3) NVIDIA Update Components (Version: 1.11.3) OcxSetup (Version: 1.0.0) Optimierte Multimedia-Tastatur-Lösung PHOTOfunSTUDIO -viewer- (Version: 1.00.000) PhotoMail Maker (Version: 1.0.0.1040) Picasa 3 (Version: 3.9) Plus-HD-2.3 (Version: 1.27.153.8) Python 2.4.3 (Version: 2.4.3150) QuickTime (Version: 7.73.80.64) radio ffn Rekorder Version 3.02.8 RealArcade RealDownloader (Version: 1.3.0) RealPlayer (Version: 16.0.0) Realtek High Definition Audio Driver (Version: 6.0.1.5322) RealUpgrade 1.1 (Version: 1.1.0) RTL GAME CENTER (Version: 1.2010.6.23) Sandlot Games Client Services 1.2.2 Segoe UI (Version: 15.4.2271.0615) Spelling Dictionaries Support For Adobe Reader 8 (Version: 8.0.0) Steganos Safe Home 2007 (Version: 9.0.3) STRATO Backup Manager (Version: 1.0.0) Super Lyrics TeamViewer 7 (Version: 7.0.17271) T-Online WLAN-Access Finder Turbo Lister 2 (Version: 2.0.0) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) VideoPad Videobearbeitungs-Software Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0) VLC media player 1.1.11 (Version: 1.1.11) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3555.0308) Windows Live Family Safety (Version: 15.4.3555.0308) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live Mesh (Version: 15.4.3502.0922) Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2) Windows Live Messenger (Version: 15.4.3538.0513) Windows Live Messenger Companion Core (Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0) WinRAR archiver ==================== Restore Points ========================= 20-07-2013 17:00:57 Windows Update 22-07-2013 18:43:58 Windows Update 22-07-2013 22:21:08 Entfernt Konz 2012 22-07-2013 22:22:06 Removed Bing Bar 22-07-2013 22:26:46 Removed Ask Toolbar. 23-07-2013 15:36:29 Removed MEDION GoPal Assistant 23-07-2013 15:43:05 Removed Nero 7 Premium. Available with Windows Installer version 1.2 and later. 23-07-2013 15:52:22 Removed Google Chrome Frame 28-07-2013 14:07:58 Windows Update 28-07-2013 17:02:33 Windows-Sicherung 31-07-2013 15:57:19 Tweaking.com - Windows Repair 03-08-2013 11:48:20 Windows Update 05-08-2013 19:53:57 Windows-Sicherung 10-08-2013 09:43:48 Windows Update 10-08-2013 10:14:23 Removed Nero 7 Premium. Available with Windows Installer version 1.2 and later. 10-08-2013 14:56:26 Removed Nero 7 Premium. Available with Windows Installer version 1.2 and later. ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000736 ____A C:\Windows\system32\Drivers\etc\hosts ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0568804D-6FDF-46DF-9FF2-1948BB8636AB} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27] (Adobe Systems Incorporated) Task: {09C0034D-8657-4DE1-8EEC-F9897D5695AA} - System32\Tasks\NCH Software\videopadShakeIcon => C:\Program Files\NCH Software\VideoPad\VideoPad.exe [2013-01-27] (NCH Software) Task: {0B15B809-99AF-419D-94C0-B1C773C306AD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-20] (Google Inc.) Task: {0E01E7C3-9558-44BA-9FBB-B1B57F5B86F1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {0E96532C-3B2B-44C1-90BA-7F13CA501ED3} - System32\Tasks\Microsoft\Windows\WindowsBackup\CheckFull => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2ED36C22-45D8-432F-A894-17FD629EA9E4} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-18] (Microsoft Corp.) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3D51B747-599F-4056-80E5-59E7C7DEC6B7} - System32\Tasks\User_Feed_Synchronization-{713C853D-16EB-4E3C-9AA1-35C296B67C10} => C:\Windows\system32\msfeedssync.exe [2011-11-06] (Microsoft Corporation) Task: {43A05BEB-6B12-44F9-9021-56CC2207FB24} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-18] (Microsoft Corporation) Task: {4CE713F7-3F24-4204-8A06-7F57389A912D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-18] (Microsoft Corporation) Task: {4FEFDE2E-CF7B-454E-9CDA-22AA39A7741B} - System32\Tasks\HP-Online-Aktualisierungsprogramm => c:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-02-17] (Hewlett-Packard Co.) Task: {552801B9-5EB1-49A5-AB14-52C2F7D259EF} - System32\Tasks\NCH Software\videopadDowngrade => C:\Program Files\NCH Software\VideoPad\videopad.exe [2013-01-27] (NCH Software) Task: {562CE0C6-F0A0-4985-9A8C-851DBE47F3B1} - System32\Tasks\BFGLaunch_stone-of-destiny_s2_l2_gF2080T1L2_d167401155[1] => C:\Users\Olaf\AppData\Local\Temp\stone-of-destiny_s2_l2_gF2080T1L2_d167401155[1].exe No File Task: {5BFFE95E-631C-4DE9-930E-024ADB4F6B14} - System32\Tasks\Steganos Agent => C:\Program Files\Steganos Safe Home\SteganosAgent.exe [2006-12-05] () Task: {61398903-0F8E-447C-98A6-E120573C6E64} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27] (Adobe Systems Incorporated) Task: {6306DA7D-9019-4042-91FD-1D44D6EB4318} - System32\Tasks\BFGLaunch_fashion-craze_s2_l2_gF2238T1L2_d134644565[1] => C:\Users\Olaf\AppData\Local\Temp\fashion-craze_s2_l2_gF2238T1L2_d134644565[1].exe No File Task: {720AAE8C-F14F-4C56-82BE-FCB74E1E08C7} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {73318A8D-623C-4485-AFFC-630891545622} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-20] (Adobe Systems Incorporated) Task: {7567DA21-7F32-4997-848A-82D04FC183E2} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation) Task: {7A513F29-5009-421E-86C1-DCC79D76AFA6} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {7DB83568-6916-4EA2-A28C-45A1FB24A9B4} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {81685675-E43F-408E-9D63-DAF87BBACD7F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {84AD09F3-0363-4407-BEEA-8C5BD2CC8097} - System32\Tasks\Java => C:\Program Files\Java\jre6\bin\jusched.exe No File Task: {85DD6276-7838-4232-8FF8-CB15EF58DF2E} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => c:\program files\real\realplayer\Update\realsched.exe [2013-01-19] (RealNetworks, Inc.) Task: {87BD1C97-0934-4021-9770-D7B1B1D7BD60} - System32\Tasks\DSite => C:\Users\Olaf\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File Task: {8B480174-D82C-4A8B-87BA-E31D091FBEE8} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2008-01-18] (Microsoft Corporation) Task: {8EB3A4B7-9C62-4B08-BBD5-E9D07C405232} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-18] (Microsoft Corporation) Task: {935C56FB-D42B-44EE-AC9D-1AA796AE50F5} - System32\Tasks\Microsoft_Hardware_Launch_vVX3000_exe => C:\Windows\vVX3000.exe [2007-04-10] (Microsoft Corporation) Task: {95203A9F-5EA3-4B81-BFA3-71B4BC5CF928} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {9B8ACEE6-311B-49BC-A6BD-AFEACE7ACE22} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-18] (Microsoft Corporation) Task: {ABFD2AB8-A215-4E35-9FD6-B9A5601667D8} - System32\Tasks\BFGLaunch_bfgclient => C:\Program Files\bfgclient\bfgclient.exe [2011-08-19] () Task: {ADCC9A85-0C50-4AB5-9E44-4B9F6284A276} - System32\Tasks\Real Networks Scheduler => C:\Program Files\Common Files\Real\Update_OB\realsched.exe No File Task: {BF1C88C9-B12C-4864-AE01-6708114BA952} - System32\Tasks\Microsoft\Windows\RestartManager\{FB86C79C-478C-4f3f-ACE2-A09F149B1F14} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {C3FA9EBC-FB39-4AE9-9E95-815475E63CFD} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe No File Task: {D5416E71-9E9F-48C1-B2D5-3AB4B800F53D} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {D7AF7F31-F249-44C7-ABA8-F7D445C0B5E0} - System32\Tasks\Super Lyrics Update => C:\Program Files\Super_Lyrics\SuperLupdater.exe [2013-07-22] (Super Add-on Software) Task: {DAB924FD-E6EF-440F-93CD-EFC99231D994} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-20] (Google Inc.) Task: {E3EA736A-C48A-4E4A-915A-621B34A323F4} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: {E609BE22-FE85-4943-9724-2850F6E23B7B} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation) Task: {E8C81B95-6D19-40F4-A23E-AE86EF0ED417} - System32\Tasks\User_Feed_Synchronization-{F658E2FC-1F92-4830-9F47-9F66D638EB43} => C:\Windows\system32\msfeedssync.exe [2011-11-06] (Microsoft Corporation) Task: {EA1D2880-8265-4C27-92EF-B7589412DB10} - System32\Tasks\BFGLaunch_bfgprocess => C:\Program Files\bfgclient\bfgprocess.exe [2011-08-19] () Task: {F1A24C80-DAA3-4545-A909-B89B215396B2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core.job => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA.job => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Super Lyrics Update.job => C:\Program Files\Super_Lyrics\SuperLupdater.exe ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Microsoft-ISATAP-Adapter #3 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (08/10/2013 09:01:45 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/10/2013 09:01:45 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/10/2013 08:47:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/10/2013 08:47:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/10/2013 04:51:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/10/2013 04:51:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (08/11/2013 01:16:16 PM) (Source: Service Control Manager) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (08/11/2013 01:16:16 PM) (Source: Service Control Manager) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (08/11/2013 01:15:02 PM) (Source: Service Control Manager) (User: ) Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058 Error: (08/11/2013 01:15:02 PM) (Source: Service Control Manager) (User: ) Description: Net.Pipe-Listeneradapterwas Error: (08/11/2013 01:15:02 PM) (Source: Service Control Manager) (User: ) Description: Net.Msmq-Listeneradaptermsmq Error: (08/11/2013 01:14:07 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalAktivierung{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (08/11/2013 01:13:51 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 10.08.2013 um 21:06:24 unerwartet heruntergefahren. Error: (08/10/2013 09:03:31 PM) (Source: Service Control Manager) (User: ) Description: NVIDIA Update Service Daemon%%1069 Error: (08/10/2013 09:03:31 PM) (Source: Service Control Manager) (User: ) Description: nvUpdatusService.\UpdatusUser%%1330 Error: (08/10/2013 09:01:55 PM) (Source: Service Control Manager) (User: ) Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058 Microsoft Office Sessions: ========================= Error: (08/10/2013 09:01:45 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe Error: (08/10/2013 09:01:45 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe Error: (08/10/2013 08:47:53 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe Error: (08/10/2013 08:47:53 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe Error: (08/10/2013 04:51:33 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe Error: (08/10/2013 04:51:33 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 2558.58 MB Available physical RAM: 1193.02 MB Total Pagefile: 5351.68 MB Available Pagefile: 3875.03 MB Total Virtual: 2047.88 MB Available Virtual: 1905.57 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:292.8 GB) (Free:83.75 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive j: (Elements) (Fixed) (Total:1397.26 GB) (Free:1057.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 298 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=293 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=5 GB) - (Type=07 NTFS) ======================================================== Disk: 5 (MBR Code: Windows XP) (Size: 1397 GB) (Disk ID: 00111F03) Partition 1: (Not Active) - (Size=-698724909056) - (Type=07 NTFS) ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-07-2013 (ATTENTION: FRST version is 21 days old) Ran by Olaf (administrator) on 11-08-2013 13:29:13 Running from C:\Users\Olaf\Desktop Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe () C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe (Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation) C:\Windows\ehome\ehsched.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe () C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (Iminent) C:\Program Files\Common Files\Umbrella\umbrella.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe () C:\Program Files\Steganos Safe Home\SteganosHotKeyService.exe (Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\tv_w32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Hewlett-Packard Company) C:\hp\kbd\kbd.exe (Microsoft Corporation) C:\Windows\system32\sdclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe ==================== Registry (Whitelisted) ================== MountPoints2: {f75312be-89cf-11de-a996-001a92486b3f} - J:\Menu.exe HKU\IUSR_NMPR\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-18] (Microsoft Corporation) HKU\IUSR_NMPR\...\Run: [ICQ] - "C:\Program Files\ICQ6\ICQ.exe" silent [x] HKU\IUSR_NMPR\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x] HKU\IUSR_NMPR\...\RunOnce: [ICQ Lite] - C:\Program Files\ICQLite\ICQLite.exe -trayboot [x] HKU\IUSR_NMPR\...\RunOnce: [DATA BECKER Registrierung] - "C:\Program Files\Internet Explorer\Iexplore.exe" C:\Program Files\DATA BECKER\Visitenkarten-Druckerei 10\Support\Online\index.htm [x] ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {99BF4F38-A3A2-412A-996F-AAD9A3406746} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06 SearchScopes: HKCU - {639C8579-AFEB-4039-886E-D4B7612A0244} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=YYYYYYYYDE&apn_uid=E918B100-3F16-4AFE-9A56-655241D70738&apn_sauid=FA585939-A01E-4CF2-B412-32F822B64359 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll (Super Add-on Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Super Lyrics - {B9020890-9E08-446B-87B0-0C5CD0436D86} - C:\Program Files\Super_Lyrics\116.dll No File BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msdaipp - No CLSID Value - Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default FF user.js: detected! => C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\user.js FF SelectedSearchEngine: Google.de FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @real.com/nppl3260;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @phonostar.de/radio ffn Rekorder - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede.xml FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\plugin@starstable.com FF Extension: Microsoft .NET Framework Assistant - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: ciuvo-extension - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\ciuvo-extension@icq.de.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi FF Extension: No Name - C:\Program Files\Super_Lyrics\125.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Shockwave for Director) - C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealArcade Mozilla Plugin) - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll (RealNetworks) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (phonostar Detector) - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( ) CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Docs) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (Super Lyrics) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnjcnjlaajofpendibcoodneacalfho\1.125_0 CHR Extension: (YouTube) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (RealDownloader) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0 CHR Extension: (Gmail) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [bgnjcnjlaajofpendibcoodneacalfho] - C:\Program Files\Super_Lyrics\125.crx CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx ========================== Services (Whitelisted) ================= R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2938408 2013-07-02] (Emsisoft GmbH) S3 AlertService; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [188416 2006-09-11] (Intel(R) Corporation) R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.) R2 DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [208896 2006-09-03] () R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) S3 FirebirdServerMAGIXInstance; C:\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-08-10] (The Firebird Project) S2 IntelDHSvcConf; C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [29696 2006-05-10] (Intel(R) Corporation) S3 ISSM; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [75264 2006-09-11] (Intel(R) Corporation) S3 M1 Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [26624 2006-09-01] () S3 MCLServiceATL; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [167936 2006-09-11] (Intel(R) Corporation) R2 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () S3 Remote UI Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [544256 2006-09-11] (Intel(R) Corporation) R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2864448 2013-08-05] (Iminent) S3 stllssvr; "c:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [x] ==================== Drivers (Whitelisted) ==================== S3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [54072 2012-04-30] (Emsisoft GmbH) R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH) R2 ACEDRV07; C:\Windows\system32\drivers\ACEDRV07.sys [101376 2007-09-27] (Protect Software GmbH) R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) S3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50208 2013-07-02] (Emsisoft GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [21248 2003-09-20] (Padus, Inc.) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [90536 2008-05-27] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-05-27] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [122152 2008-05-27] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [115496 2008-05-27] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [25768 2008-05-27] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [111912 2008-05-27] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [117672 2008-05-27] (MCCI Corporation) R1 SLEE_14_DRIVER; C:\Windows\system32\drivers\Sleen14.sys [72480 2006-11-08] (Softwareentwicklung Remus - ArchiCrypt ) S3 TSHWMDTCP; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [4608 2006-07-13] () S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 massfilter; system32\drivers\massfilter.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 ZD1211BU(ZyDAS); system32\DRIVERS\zd1211Bu.sys [x] S3 ZDPSp60; System32\Drivers\ZDPSp60.sys [x] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2013-08-10 14:35 - 2013-08-10 21:06 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware 2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware 2013-08-10 14:30 - 2013-08-10 14:34 - 187662064 _____ (Emsisoft GmbH ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent 2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-08-05 22:19 - 2013-08-10 10:21 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2013-08-05 22:19 - 2013-08-05 22:20 - 00000000 ____D C:\Program Files\Iminent 2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe 2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe 2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp 2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat 2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup 2013-07-30 15:50 - 2013-08-05 21:27 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-07-30 15:49 - 2011-10-24 13:35 - 00000000 ____D C:\Users\Olaf\Downloads\Tweaking.com - Windows Repair 2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio 2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio 2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip 2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp 2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe 2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe 2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe 2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1 2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe 2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe 2013-07-23 18:18 - 2013-07-22 20:26 - 01219874 _____ (Farbar) C:\Users\Olaf\Desktop\FRST.exe 2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp 2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe 2013-07-23 15:32 - 2013-07-23 15:38 - 00030353 _____ C:\AdwCleaner[S1].txt 2013-07-23 15:32 - 2013-07-23 15:38 - 00000105 _____ C:\Windows\DeleteOnReboot.bat 2013-07-23 15:27 - 2013-07-23 15:28 - 00031376 _____ C:\AdwCleaner[R1].txt 2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe 2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics 2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk 2013-07-22 23:27 - 2013-07-22 23:28 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe 2013-07-22 22:10 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-22 22:10 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-22 22:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-22 22:07 - 2013-07-22 22:09 - 00000000 ____D C:\Qoobox 2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt 2013-07-22 22:02 - 2013-07-22 23:56 - 00000000 ___SD C:\32788R22FWJFW 2013-07-22 21:07 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-22 21:07 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-22 21:07 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-22 21:07 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-22 21:07 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-22 21:07 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-22 21:07 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-22 21:07 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-22 21:07 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-22 21:07 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-22 21:07 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-22 21:07 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-22 21:07 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-22 21:07 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-22 21:07 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-22 21:07 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe 2013-07-22 20:34 - 2013-07-22 20:34 - 00000000 ____D C:\FRST 2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 23:16 - 2013-08-11 13:14 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk 2013-07-20 19:31 - 2013-07-20 19:32 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 19:22 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-20 19:20 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-20 19:20 - 2013-05-08 06:37 - 00905576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-20 19:19 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-20 19:19 - 2013-05-03 00:03 - 03603832 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-07-20 19:19 - 2013-05-03 00:03 - 03551096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-20 19:19 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-07-20 19:19 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00985600 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-07-20 19:19 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-07-20 19:19 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-20 19:19 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-20 19:19 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-20 19:19 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-20 19:19 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-20 19:19 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-20 19:19 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-20 19:19 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-20 19:19 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-20 19:18 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 18:37 - 2013-08-11 13:14 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 18:37 - 2013-08-10 20:47 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common 2013-07-20 18:29 - 2013-07-20 18:30 - 00393064 _____ (Softonic ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe ==================== One Month Modified Files and Folders ======= 2013-08-11 13:29 - 2007-04-02 16:15 - 00000000 ___RD C:\Users\Olaf\Desktop 2013-08-11 13:21 - 2006-11-02 12:33 - 01586480 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-11 13:17 - 2011-12-12 16:11 - 01768361 _____ C:\Windows\WindowsUpdate.log 2013-08-11 13:14 - 2013-07-20 23:16 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-08-11 13:14 - 2013-07-20 18:37 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-11 13:14 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-11 13:14 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-11 13:14 - 2006-11-02 14:37 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-08-11 13:13 - 2008-01-08 16:06 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-11 13:13 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-10 21:06 - 2013-08-10 14:35 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware 2013-08-10 21:06 - 2006-11-02 15:01 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-10 20:53 - 2012-04-25 14:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-10 20:47 - 2013-07-20 18:37 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-10 15:23 - 2013-04-10 15:28 - 00006374 _____ C:\Windows\PFRO.log 2013-08-10 15:09 - 2011-11-23 21:41 - 00001134 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA.job 2013-08-10 15:09 - 2011-11-23 21:41 - 00001112 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core.job 2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2013-08-10 14:37 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Public\Desktop 2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware 2013-08-10 14:34 - 2013-08-10 14:30 - 187662064 _____ (Emsisoft GmbH ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe 2013-08-10 14:34 - 2007-01-20 20:04 - 00000000 ____D C:\Program Files\Google 2013-08-10 11:56 - 2007-06-27 14:40 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-08-10 10:21 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent 2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-08-05 22:20 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Iminent 2013-08-05 22:16 - 2007-04-12 17:11 - 00000000 ____D C:\Users\Olaf\AppData\Local\Adobe 2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe 2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe 2013-08-05 21:35 - 2007-04-02 16:27 - 00146568 _____ C:\Users\Olaf\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-05 21:32 - 2006-11-02 14:47 - 00443208 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp 2013-08-05 21:31 - 2013-04-13 13:15 - 295539634 _____ C:\Windows\MEMORY.DMP 2013-08-05 21:31 - 2009-05-13 17:54 - 00000000 ____D C:\Windows\Minidump 2013-08-05 21:27 - 2013-07-30 15:50 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-03 14:48 - 2007-07-10 16:43 - 03716436 _____ C:\Users\Mariessa\01 Heul Doch.wma 2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat 2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup 2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio 2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio 2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip 2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp 2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe 2013-07-24 00:16 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe 2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe 2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1 2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe 2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe 2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp 2013-07-23 17:52 - 2007-04-02 21:35 - 00000000 ____D C:\Users\Olaf\AppData\Local\Google 2013-07-23 17:38 - 2008-07-29 10:55 - 00000000 ____D C:\Users\Gast\Desktop 2013-07-23 17:38 - 2007-05-12 17:08 - 00000000 ____D C:\Program Files\InterActual 2013-07-23 17:38 - 2007-01-20 19:54 - 00000000 ___RD C:\Users\IUSR_NMPR\Desktop 2013-07-23 17:37 - 2011-05-03 15:47 - 00000000 ____D C:\Program Files\Medion GoPal Assistant 2013-07-23 17:22 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe 2013-07-23 15:38 - 2013-07-23 15:32 - 00030353 _____ C:\AdwCleaner[S1].txt 2013-07-23 15:38 - 2013-07-23 15:32 - 00000105 _____ C:\Windows\DeleteOnReboot.bat 2013-07-23 15:33 - 2013-01-27 13:53 - 00000000 ____D C:\ProgramData\GinyasBrowserCompanion 2013-07-23 15:28 - 2013-07-23 15:27 - 00031376 _____ C:\AdwCleaner[R1].txt 2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe 2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics 2013-07-23 00:21 - 2007-01-20 19:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-07-22 23:56 - 2013-07-22 22:02 - 00000000 ___SD C:\32788R22FWJFW 2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk 2013-07-22 23:28 - 2013-07-22 23:27 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe 2013-07-22 23:14 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-22 23:14 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-07-22 22:09 - 2013-07-22 22:07 - 00000000 ____D C:\Qoobox 2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt 2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe 2013-07-22 20:50 - 2012-11-06 23:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-22 20:45 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-22 20:34 - 2013-07-22 20:34 - 00000000 ____D C:\FRST 2013-07-22 20:26 - 2013-07-23 18:18 - 01219874 _____ (Farbar) C:\Users\Olaf\Desktop\FRST.exe 2013-07-20 23:25 - 2013-04-13 03:02 - 00000796 _____ C:\Windows\setupact.log 2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk 2013-07-20 19:32 - 2013-07-20 19:31 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 18:56 - 2012-04-25 14:17 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-20 18:56 - 2011-08-28 08:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common 2013-07-20 18:31 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-20 18:30 - 2013-07-20 18:29 - 00393064 _____ (Softonic ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-11 13:22 ==================== End Of Log ============================ Liebe Grüße Tanja |
11.08.2013, 16:35 | #32 |
/// the machine /// TB-Ausbilder | tcbhn wurde beendet Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter MountPoints2: {f75312be-89cf-11de-a996-001a92486b3f} - J:\Menu.exe SearchScopes: HKCU - {639C8579-AFEB-4039-886E-D4B7612A0244} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=YYYYYYYYDE&apn_uid=E918B100-3F16-4AFE-9A56-655241D70738&apn_sauid=FA585939-A01E-4CF2-B412-32F822B64359 BHO: Super Lyrics - {B9020890-9E08-446B-87B0-0C5CD0436D86} - C:\Program Files\Super_Lyrics\116.dll No File CHR Extension: (Super Lyrics) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnjcnjlaajofpendibcoodneacalfho\1.125_0 CHR HKLM\...\Chrome\Extension: [bgnjcnjlaajofpendibcoodneacalfho] - C:\Program Files\Super_Lyrics\125.crx R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2864448 2013-08-05] (Iminent) S3 stllssvr; "c:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [x] C:\Program Files\Common Files\Umbrella 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent 2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-08-05 22:19 - 2013-08-10 10:21 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2013-08-05 22:19 - 2013-08-05 22:20 - 00000000 ____D C:\Program Files\Iminent 2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics 2013-07-20 23:16 - 2013-08-11 13:14 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-08-10 10:21 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Common Files\Umbrella 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent 2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent 2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog 2013-08-05 22:20 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Iminent 2013-07-23 15:33 - 2013-01-27 13:53 - 00000000 ____D C:\ProgramData\GinyasBrowserCompanion 2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Revo Uninstaller Pro - Uninstall Software, Remove Programs easily, Forced Uninstall, Leftovers Uninstaller Benutz das zum restlosen Entfernen von Firefox. Ebenso bitte alles von Nvidia deinstallieren und dann neu installieren.
__________________ |
12.08.2013, 16:29 | #33 |
| tcbhn wurde beendet Hab alles so gemacht wie du gesagt hast. Es kommt folgende Meldung:
__________________Looks you don´t know what to do. To prevent damage to the system the tool will exit. Wenn ich OK drücke passiert nichts. ?????????? |
12.08.2013, 17:40 | #34 |
/// the machine /// TB-Ausbilder | tcbhn wurde beendet wann kommt die Meldung?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.08.2013, 15:15 | #35 |
| tcbhn wurde beendet nachdem ich den Fix Button gedrückt habe! |
13.08.2013, 18:13 | #36 |
/// the machine /// TB-Ausbilder | tcbhn wurde beendet FRST löschen, neu laden. Überprüf deine fixlist, die muss so aussehen wie oben, dann nochmal probieren.
__________________ --> tcbhn wurde beendet |
14.08.2013, 18:06 | #37 |
| tcbhn wurde beendet Hab es hinbekommen, beim ersten Mal habe ich einen Fehler gemacht! Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-08-2013 01 Ran by Olaf at 2013-08-14 18:42:03 Run:2 Running from C:\Users\Olaf\Downloads Boot Mode: Normal ============================================== HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f75312be-89cf-11de-a996-001a92486b3f} => Key not found. HKCR\CLSID\{f75312be-89cf-11de-a996-001a92486b3f} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{639C8579-AFEB-4039-886E-D4B7612A0244} => Key not found. HKCR\Wow6432Node\CLSID\{639C8579-AFEB-4039-886E-D4B7612A0244} => Key not found. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9020890-9E08-446B-87B0-0C5CD0436D86} => Key not found. HKCR\CLSID\{B9020890-9E08-446B-87B0-0C5CD0436D86} => Key not found. C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnjcnjlaajofpendibcoodneacalfho directory not found. HKLM\SOFTWARE\Google\Chrome\Extensions\bgnjcnjlaajofpendibcoodneacalfho => Key not found. "C:\Program Files\Super_Lyrics\125.crx" => File/Directory not found. SProtection => Service not found. stllssvr => Service not found. "C:\Program Files\Common Files\Umbrella" => File/Directory not found. "C:\Users\Olaf\AppData\Roaming\Iminent" => File/Directory not found. "C:\ProgramData\Iminent" => File/Directory not found. "C:\Windows\system32\InstallUtil.InstallLog" => File/Directory not found. "C:\Program Files\Common Files\Umbrella" => File/Directory not found. "C:\Program Files\Iminent" => File/Directory not found. "C:\Program Files\Super_Lyrics" => File/Directory not found. "C:\Windows\Tasks\Super Lyrics Update.job" => File/Directory not found. "C:\Program Files\Common Files\Umbrella" => File/Directory not found. "C:\Users\Olaf\AppData\Roaming\Iminent" => File/Directory not found. "C:\ProgramData\Iminent" => File/Directory not found. "C:\Windows\system32\InstallUtil.InstallLog" => File/Directory not found. "C:\Program Files\Iminent" => File/Directory not found. "C:\ProgramData\GinyasBrowserCompanion" => File/Directory not found. "C:\Program Files\Super_Lyrics" => File/Directory not found. ==== End of Fixlog ==== |
15.08.2013, 08:14 | #38 |
/// the machine /// TB-Ausbilder | tcbhn wurde beendet Frisches FRST Scanlog bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.08.2013, 15:19 | #39 |
| tcbhn wurde beendet Eben hatte ich ein ganz buntes Pixelbild und einen Absturz (ich wollte während des Scans ins Internet. Fehler: Code:
ATTFilter Problemsignatur: Problemereignisname: BlueScreen Betriebsystemversion: 6.0.6002.2.2.0.768.3 Gebietsschema-ID: 1031 Zusatzinformationen zum Problem: BCCode: 116 BCP1: 8FC20008 BCP2: 98F5C8D4 BCP3: C000009A BCP4: 00000004 OS Version: 6_0_6002 Service Pack: 2_0 Product: 768_1 Dateien, die bei der Beschreibung des Problems hilfreich sind: C:\Windows\Minidump\Mini081513-01.dmp C:\Users\Olaf\AppData\Local\Temp\WER-317228-0.sysdata.xml C:\Users\Olaf\AppData\Local\Temp\WER909B.tmp.version.txt Lesen Sie unsere Datenschutzrichtlinie: hxxp://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0407 FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-08-2013 01 Ran by Olaf (administrator) on 15-08-2013 16:11:25 Running from C:\Users\Olaf\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe () C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe (Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation) C:\Windows\ehome\ehsched.exe (MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe () C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe () C:\Program Files\Steganos Safe Home\SteganosHotKeyService.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Hewlett-Packard Company) C:\hp\kbd\kbd.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\tv_w32.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-18] (Microsoft Corporation) HKLM\...\Run: [hpsysdrv] - c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [151552 2006-09-29] (Intel Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [3784704 2006-11-09] (Realtek Semiconductor) HKLM\...\Run: [SAFEHOME HotKeys] - C:\Program Files\Steganos Safe Home\SteganosHotKeyService.exe [25088 2006-12-05] () HKLM\...\Run: [KBD] - C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] () HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.) HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295072 2013-01-19] (RealNetworks, Inc.) HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [2928040 2013-07-02] (Emsisoft GmbH) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\IUSR_NMPR\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\IUSR_NMPR\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-18] (Microsoft Corporation) HKU\IUSR_NMPR\...\Run: [ICQ] - "C:\Program Files\ICQ6\ICQ.exe" silent [x] HKU\IUSR_NMPR\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x] HKU\IUSR_NMPR\...\RunOnce: [ICQ Lite] - C:\Program Files\ICQLite\ICQLite.exe -trayboot [x] HKU\IUSR_NMPR\...\RunOnce: [DATA BECKER Registrierung] - C:\Program Files\Internet Explorer\Iexplore.exe [ 2013-05-29] (Microsoft Corporation) HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\UpdatusUser.Olaf-PC\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {99BF4F38-A3A2-412A-996F-AAD9A3406746} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06 BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msdaipp - No CLSID Value - Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default FF user.js: detected! => C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\user.js FF SelectedSearchEngine: Google.de FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @real.com/nppl3260;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @phonostar.de/radio ffn Rekorder - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede-pws.xml FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede.xml FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\plugin@starstable.com FF Extension: Microsoft .NET Framework Assistant - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: ciuvo-extension - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\ciuvo-extension@icq.de.xpi FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Shockwave for Director) - C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (RealArcade Mozilla Plugin) - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll (RealNetworks) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (phonostar Detector) - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( ) CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Google Docs) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (RealDownloader) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0 CHR Extension: (Gmail) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx ========================== Services (Whitelisted) ================= R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2938408 2013-07-02] (Emsisoft GmbH) S3 AlertService; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [188416 2006-09-11] (Intel(R) Corporation) R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.) R2 DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [208896 2006-09-03] () R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG) S3 FirebirdServerMAGIXInstance; C:\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-08-10] (The Firebird Project) S2 IntelDHSvcConf; C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [29696 2006-05-10] (Intel(R) Corporation) S3 ISSM; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [75264 2006-09-11] (Intel(R) Corporation) S3 M1 Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [26624 2006-09-01] () S3 MCLServiceATL; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [167936 2006-09-11] (Intel(R) Corporation) R2 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] () R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () S3 Remote UI Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [544256 2006-09-11] (Intel(R) Corporation) ==================== Drivers (Whitelisted) ==================== S3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [54072 2012-04-30] (Emsisoft GmbH) R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH) R2 ACEDRV07; C:\Windows\system32\drivers\ACEDRV07.sys [101376 2007-09-27] (Protect Software GmbH) R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.) S3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50208 2013-07-02] (Emsisoft GmbH) R3 pfc; C:\Windows\System32\drivers\pfc.sys [21248 2003-09-20] (Padus, Inc.) S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [90536 2008-05-27] (MCCI Corporation) S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-05-27] (MCCI Corporation) S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [122152 2008-05-27] (MCCI Corporation) S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [115496 2008-05-27] (MCCI Corporation) S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [25768 2008-05-27] (MCCI Corporation) S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [111912 2008-05-27] (MCCI Corporation) S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [117672 2008-05-27] (MCCI Corporation) R1 SLEE_14_DRIVER; C:\Windows\system32\drivers\Sleen14.sys [72480 2006-11-08] (Softwareentwicklung Remus - ArchiCrypt ) S3 TSHWMDTCP; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [4608 2006-07-13] () S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 massfilter; system32\drivers\massfilter.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 ZD1211BU(ZyDAS); system32\DRIVERS\zd1211Bu.sys [x] S3 ZDPSp60; System32\Drivers\ZDPSp60.sys [x] S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x] S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x] S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-13 19:55 - 2013-08-13 19:55 - 00000814 _____ C:\Users\Olaf\Desktop\FRST.exe.lnk 2013-08-13 19:53 - 2013-08-13 19:53 - 01068613 _____ (Farbar) C:\Users\Olaf\Downloads\FRST.exe 2013-08-12 15:50 - 2013-08-12 15:50 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja (1).zip 2013-08-12 15:38 - 2013-08-12 15:39 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja.zip 2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2013-08-10 14:35 - 2013-08-13 19:01 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware 2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware 2013-08-10 14:30 - 2013-08-10 14:34 - 187662064 _____ (Emsisoft GmbH ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe 2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe 2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe 2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp 2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat 2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup 2013-07-30 15:50 - 2013-08-05 21:27 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-07-30 15:49 - 2011-10-24 13:35 - 00000000 ____D C:\Users\Olaf\Downloads\Tweaking.com - Windows Repair 2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio 2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio 2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip 2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp 2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe 2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe 2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe 2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1 2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe 2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe 2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp 2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe 2013-07-23 15:32 - 2013-07-23 15:38 - 00030353 _____ C:\AdwCleaner[S1].txt 2013-07-23 15:32 - 2013-07-23 15:38 - 00000105 _____ C:\Windows\DeleteOnReboot.bat 2013-07-23 15:27 - 2013-07-23 15:28 - 00031376 _____ C:\AdwCleaner[R1].txt 2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe 2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk 2013-07-22 23:27 - 2013-07-22 23:28 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe 2013-07-22 22:10 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-22 22:10 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-22 22:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-22 22:10 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-22 22:07 - 2013-07-22 22:09 - 00000000 ____D C:\Qoobox 2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt 2013-07-22 22:02 - 2013-07-22 23:56 - 00000000 ___SD C:\32788R22FWJFW 2013-07-22 21:07 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-22 21:07 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-22 21:07 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-22 21:07 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-22 21:07 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-22 21:07 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-22 21:07 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-22 21:07 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-22 21:07 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-22 21:07 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-22 21:07 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-22 21:07 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-22 21:07 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-22 21:07 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-22 21:07 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-22 21:07 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe 2013-07-22 20:34 - 2013-08-12 16:45 - 00000000 ____D C:\FRST 2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk 2013-07-20 19:31 - 2013-07-20 19:32 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 19:22 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-20 19:20 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-20 19:20 - 2013-05-08 06:37 - 00905576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-20 19:19 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-20 19:19 - 2013-05-03 00:03 - 03603832 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-07-20 19:19 - 2013-05-03 00:03 - 03551096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-20 19:19 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-07-20 19:19 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00985600 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-07-20 19:19 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-07-20 19:19 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-07-20 19:19 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-20 19:19 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-20 19:19 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-20 19:19 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-20 19:19 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-20 19:19 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-20 19:19 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-20 19:19 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-20 19:19 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-20 19:18 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 18:37 - 2013-08-15 16:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-20 18:37 - 2013-08-15 15:47 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common 2013-07-20 18:29 - 2013-07-20 18:30 - 00393064 _____ (Softonic ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe ==================== One Month Modified Files and Folders ======= 2013-08-15 16:04 - 2013-08-15 16:04 - 00201176 _____ C:\Windows\Minidump\Mini081513-01.dmp 2013-08-15 16:04 - 2013-07-20 18:37 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-15 16:04 - 2009-05-13 17:54 - 00000000 ____D C:\Windows\Minidump 2013-08-15 16:04 - 2008-01-08 16:06 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-15 16:04 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-15 16:04 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-15 16:04 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-15 16:04 - 2006-11-02 14:37 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-08-15 16:03 - 2013-04-13 13:15 - 391700939 _____ C:\Windows\MEMORY.DMP 2013-08-15 15:53 - 2012-04-25 14:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-15 15:47 - 2013-07-20 18:37 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-15 15:26 - 2006-11-02 12:33 - 01586480 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-15 15:24 - 2011-12-12 16:11 - 01918268 _____ C:\Windows\WindowsUpdate.log 2013-08-14 21:09 - 2011-11-23 21:41 - 00001134 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA.job 2013-08-13 19:55 - 2013-08-13 19:55 - 00000814 _____ C:\Users\Olaf\Desktop\FRST.exe.lnk 2013-08-13 19:53 - 2013-08-13 19:53 - 01068613 _____ (Farbar) C:\Users\Olaf\Downloads\FRST.exe 2013-08-13 19:01 - 2013-08-10 14:35 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware 2013-08-12 16:45 - 2013-07-22 20:34 - 00000000 ____D C:\FRST 2013-08-12 15:50 - 2013-08-12 15:50 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja (1).zip 2013-08-12 15:39 - 2013-08-12 15:38 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja.zip 2013-08-12 15:09 - 2011-11-23 21:41 - 00001112 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core.job 2013-08-10 21:06 - 2006-11-02 15:01 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-08-10 15:23 - 2013-04-10 15:28 - 00006374 _____ C:\Windows\PFRO.log 2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk 2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware 2013-08-10 14:34 - 2013-08-10 14:30 - 187662064 _____ (Emsisoft GmbH ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe 2013-08-10 14:34 - 2007-01-20 20:04 - 00000000 ____D C:\Program Files\Google 2013-08-10 11:56 - 2007-06-27 14:40 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2013-08-05 22:16 - 2007-04-12 17:11 - 00000000 ____D C:\Users\Olaf\AppData\Local\Adobe 2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe 2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe 2013-08-05 21:35 - 2007-04-02 16:27 - 00146568 _____ C:\Users\Olaf\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-05 21:32 - 2006-11-02 14:47 - 00443208 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp 2013-08-05 21:27 - 2013-07-30 15:50 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-03 14:48 - 2007-07-10 16:43 - 03716436 _____ C:\Users\Mariessa\01 Heul Doch.wma 2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat 2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup 2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio 2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio 2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip 2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp 2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe 2013-07-24 00:16 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe 2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe 2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1 2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe 2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe 2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp 2013-07-23 17:52 - 2007-04-02 21:35 - 00000000 ____D C:\Users\Olaf\AppData\Local\Google 2013-07-23 17:38 - 2007-05-12 17:08 - 00000000 ____D C:\Program Files\InterActual 2013-07-23 17:37 - 2011-05-03 15:47 - 00000000 ____D C:\Program Files\Medion GoPal Assistant 2013-07-23 17:22 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe 2013-07-23 15:38 - 2013-07-23 15:32 - 00030353 _____ C:\AdwCleaner[S1].txt 2013-07-23 15:38 - 2013-07-23 15:32 - 00000105 _____ C:\Windows\DeleteOnReboot.bat 2013-07-23 15:28 - 2013-07-23 15:27 - 00031376 _____ C:\AdwCleaner[R1].txt 2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe 2013-07-23 00:21 - 2007-01-20 19:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-07-22 23:56 - 2013-07-22 22:02 - 00000000 ___SD C:\32788R22FWJFW 2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk 2013-07-22 23:28 - 2013-07-22 23:27 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe 2013-07-22 23:14 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-22 23:14 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-07-22 22:09 - 2013-07-22 22:07 - 00000000 ____D C:\Qoobox 2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt 2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe 2013-07-22 20:50 - 2012-11-06 23:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-22 20:45 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-20 23:25 - 2013-04-13 03:02 - 00000796 _____ C:\Windows\setupact.log 2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp 2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk 2013-07-20 19:32 - 2013-07-20 19:31 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-20 18:56 - 2012-04-25 14:17 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-20 18:56 - 2011-08-28 08:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp 2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare 2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common 2013-07-20 18:31 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-07-20 18:30 - 2013-07-20 18:29 - 00393064 _____ (Softonic ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-15 16:11 ==================== End Of Log ============================ |
15.08.2013, 18:49 | #40 | |
/// the machine /// TB-Ausbilder | tcbhn wurde beendetZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu tcbhn wurde beendet |
beendet, bild, computer, erhalte, fehler, firefox, fotogalerie, funktioniert, funktioniert nicht, funktioniert nicht mehr, jahre, kaspersky, kostenlose, medion, meldung, neu, nicht mehr, nichts, picasa, probleme, runter, schließe, schwarzes, schwere, sieben, tdss, version, virus, vista, weißer, windows, zeitlupe |