Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: tcbhn wurde beendet

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 11.08.2013, 12:35   #31
Rosanja
 
tcbhn wurde beendet - Standard

tcbhn wurde beendet



Ich habe den PC damals beim Aldi gekauft und es war alles Installiert, ein Bekannter hat mir alles angeschlossen, deshalb weiss ich nicht ob es eine DVD gab. Ich habe alles durchsucht und leider keine für Vista gefunden. Aber eine CD mit Office XP Windows für den PC meiner Tochter. Nur zur Info ich habe eine Externe Festplatte darauf sind alle meine Sicherungen! Könnte ich Vister deinstallieren und XP draufspielen? Wie bekomme ich Firefox gelöscht? Ich habe mir Chrome runtergeladen!

FRST:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-07-2013
Ran by Olaf at 2013-08-11 13:30:42
Running from C:\Users\Olaf\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Adobe Flash Player 11 ActiveX (Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (Version: 11.7.700.224)
Adobe Reader X (10.1.4) - Deutsch (Version: 10.1.4)
Adobe Shockwave Player (Version: 11)
Adobe® Photoshop® Album Starter Edition 3.2 (Version: 3.2.0)
Apple Application Support (Version: 2.3.3)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
ArcSoft Software Suite
Audacity 1.2.6
Avanquest update (Version: 1.21)
Big Fish Games: Game Manager (Version: 3.0.1.60)
Bonjour (Version: 3.0.0.10)
CCleaner (Version: 2.36)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
Corel Applications
Creative DVD Audio Plugin for Audigy Series
D3DX10 (Version: 15.4.2368.0902)
DHTML Editing Component (Version: 6.02.0001)
Driver Genius Professional Edition
Echoes of the Past: Das versteinerte Königshaus
Echoes of the Past: Die Zitadellen der Zeit
Echoes of the Past: Die Zitadellen der Zeit Sammleredition
Emsisoft Anti-Malware (Version: 8.0)
Facebook Video Calling 1.2.0.287 (Version: 1.2.287)
Firebird SQL Server - MAGIX Edition (Version: 2.1.27.0)
FormatFactory 2.90 (Version: 2.90)
Google Chrome (Version: 28.0.1500.95)
Google Update Helper (Version: 1.3.21.153)
Hardware Diagnose Tools (Version: 5.00.4262.12)
HP Customer Experience Enhancements (Version: 1.00.0000)
HP Easy Setup - Core (Version: 1.00.0000)
HP Easy Setup - Frontend (Version: 5.00.0000)
HP Picasso Media Center Add-In (Version: 1.0.0)
HP Update (Version: 4.000.005.005)
iCloud (Version: 2.1.1.3)
Iminent (Version: 6.27.21.0)
InstallRTC (Version: 1.0.0)
Intel(R) Matrix Storage Manager
Intel(R) PRO Network Connections Drivers
Intel® Viiv™ Software (Version: 1.6.361.6)
InterVideo DeviceService (Version: 1.0.0)
InterVideo WinDVD 6 (Version: 6.0-B6.42)
iTunes (Version: 11.0.2.26)
Java 2 Runtime Environment, SE v1.4.2_14 (Version: 1.4.2_14)
Java 7 Update 11 (Version: 7.0.110)
Java Auto Updater (Version: 2.1.9.0)
Java(TM) 6 Update 2 (Version: 1.6.0.20)
Java(TM) 6 Update 29 (Version: 6.0.290)
Java(TM) SE Runtime Environment 6 Update 1 (Version: 1.6.0.10)
Junk Mail filter update (Version: 15.4.3502.0922)
LightScribe  1.4.124.1 (Version: 1.4.124.1)
LUMIX Simple Viewer (Version: 0.99.0000)
MAGIX Foto Clinic 4.5 (D) (Version: 4.5.3.2)
MAGIX Foto Manager 2006 (D) (Version: 3.0.1.71)
MAGIX Fotos auf CD & DVD 5.0 deLuxe (D) (Version: 5.0.0.0)
MAGIX Music Manager (D) (Version: 1.1.1.692)
MAGIX Online Druck Service
MAGIX Screenshare (Version: 4.3.6.1987)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6)
Mesh Runtime (Version: 15.4.5722.2)
Messenger Companion (Version: 15.4.3502.0922)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 German Language Pack (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2833941)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft LifeCam (Version: 1.40.164.0)
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1)
Microsoft Office XP Professional mit FrontPage (Version: 10.0.6626.0)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual J# .NET Redistributable Package 1.1 (Version: 1.1.4322)
Microsoft Works (Version: 08.05.0822)
Microsoft XML Parser (Version: 8.0.7820.0)
MobileMe Control Panel (Version: 3.1.8.0)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Nero 7 Premium (Version: 7.02.1290)
NVIDIA 3D Vision Treiber 311.06 (Version: 311.06)
NVIDIA Display Control Panel (Version: 6.14.12.5896)
NVIDIA Grafiktreiber 311.06 (Version: 311.06)
NVIDIA Install Application (Version: 2.1002.108.688)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1106)
NVIDIA Systemsteuerung 311.06 (Version: 311.06)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
OcxSetup (Version: 1.0.0)
Optimierte Multimedia-Tastatur-Lösung
PHOTOfunSTUDIO -viewer- (Version: 1.00.000)
PhotoMail Maker (Version: 1.0.0.1040)
Picasa 3 (Version: 3.9)
Plus-HD-2.3 (Version: 1.27.153.8)
Python 2.4.3 (Version: 2.4.3150)
QuickTime (Version: 7.73.80.64)
radio ffn Rekorder Version 3.02.8
RealArcade
RealDownloader (Version: 1.3.0)
RealPlayer (Version: 16.0.0)
Realtek High Definition Audio Driver (Version: 6.0.1.5322)
RealUpgrade 1.1 (Version: 1.1.0)
RTL GAME CENTER (Version: 1.2010.6.23)
Sandlot Games Client Services 1.2.2
Segoe UI (Version: 15.4.2271.0615)
Spelling Dictionaries Support For Adobe Reader 8 (Version: 8.0.0)
Steganos Safe Home 2007 (Version: 9.0.3)
STRATO Backup Manager (Version: 1.0.0)
Super Lyrics
TeamViewer 7 (Version: 7.0.17271)
T-Online WLAN-Access Finder
Turbo Lister 2 (Version: 2.0.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
VideoPad Videobearbeitungs-Software
Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0)
VLC media player 1.1.11 (Version: 1.1.11)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Mobile-Gerätecenter (Version: 6.1.6965.0)
Windows Mobile-Gerätecenter: Treiberupdate (Version: 6.1.6965.0)
WinRAR archiver
 

==================== Restore Points  =========================

20-07-2013 17:00:57 Windows Update
22-07-2013 18:43:58 Windows Update
22-07-2013 22:21:08 Entfernt Konz 2012
22-07-2013 22:22:06 Removed Bing Bar
22-07-2013 22:26:46 Removed Ask Toolbar.
23-07-2013 15:36:29 Removed MEDION GoPal Assistant
23-07-2013 15:43:05 Removed Nero 7 Premium. Available with Windows Installer version 1.2 and later.
23-07-2013 15:52:22 Removed Google Chrome Frame
28-07-2013 14:07:58 Windows Update
28-07-2013 17:02:33 Windows-Sicherung
31-07-2013 15:57:19 Tweaking.com - Windows Repair
03-08-2013 11:48:20 Windows Update
05-08-2013 19:53:57 Windows-Sicherung
10-08-2013 09:43:48 Windows Update
10-08-2013 10:14:23 Removed Nero 7 Premium. Available with Windows Installer version 1.2 and later.
10-08-2013 14:56:26 Removed Nero 7 Premium. Available with Windows Installer version 1.2 and later.

==================== Hosts content: ==========================

2006-11-02 12:23 - 2006-09-18 23:41 - 00000736 ____A C:\Windows\system32\Drivers\etc\hosts
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {0568804D-6FDF-46DF-9FF2-1948BB8636AB} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27] (Adobe Systems Incorporated)
Task: {09C0034D-8657-4DE1-8EEC-F9897D5695AA} - System32\Tasks\NCH Software\videopadShakeIcon => C:\Program Files\NCH Software\VideoPad\VideoPad.exe [2013-01-27] (NCH Software)
Task: {0B15B809-99AF-419D-94C0-B1C773C306AD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-20] (Google Inc.)
Task: {0E01E7C3-9558-44BA-9FBB-B1B57F5B86F1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {0E96532C-3B2B-44C1-90BA-7F13CA501ED3} - System32\Tasks\Microsoft\Windows\WindowsBackup\CheckFull => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation)
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {2ED36C22-45D8-432F-A894-17FD629EA9E4} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-18] (Microsoft Corp.)
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {3D51B747-599F-4056-80E5-59E7C7DEC6B7} - System32\Tasks\User_Feed_Synchronization-{713C853D-16EB-4E3C-9AA1-35C296B67C10} => C:\Windows\system32\msfeedssync.exe [2011-11-06] (Microsoft Corporation)
Task: {43A05BEB-6B12-44F9-9021-56CC2207FB24} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.)
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-18] (Microsoft Corporation)
Task: {4CE713F7-3F24-4204-8A06-7F57389A912D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-18] (Microsoft Corporation)
Task: {4FEFDE2E-CF7B-454E-9CDA-22AA39A7741B} - System32\Tasks\HP-Online-Aktualisierungsprogramm => c:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-02-17] (Hewlett-Packard Co.)
Task: {552801B9-5EB1-49A5-AB14-52C2F7D259EF} - System32\Tasks\NCH Software\videopadDowngrade => C:\Program Files\NCH Software\VideoPad\videopad.exe [2013-01-27] (NCH Software)
Task: {562CE0C6-F0A0-4985-9A8C-851DBE47F3B1} - System32\Tasks\BFGLaunch_stone-of-destiny_s2_l2_gF2080T1L2_d167401155[1] => C:\Users\Olaf\AppData\Local\Temp\stone-of-destiny_s2_l2_gF2080T1L2_d167401155[1].exe No File
Task: {5BFFE95E-631C-4DE9-930E-024ADB4F6B14} - System32\Tasks\Steganos Agent => C:\Program Files\Steganos Safe Home\SteganosAgent.exe [2006-12-05] ()
Task: {61398903-0F8E-447C-98A6-E120573C6E64} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27] (Adobe Systems Incorporated)
Task: {6306DA7D-9019-4042-91FD-1D44D6EB4318} - System32\Tasks\BFGLaunch_fashion-craze_s2_l2_gF2238T1L2_d134644565[1] => C:\Users\Olaf\AppData\Local\Temp\fashion-craze_s2_l2_gF2238T1L2_d134644565[1].exe No File
Task: {720AAE8C-F14F-4C56-82BE-FCB74E1E08C7} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {73318A8D-623C-4485-AFFC-630891545622} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-20] (Adobe Systems Incorporated)
Task: {7567DA21-7F32-4997-848A-82D04FC183E2} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation)
Task: {7A513F29-5009-421E-86C1-DCC79D76AFA6} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {7DB83568-6916-4EA2-A28C-45A1FB24A9B4} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {81685675-E43F-408E-9D63-DAF87BBACD7F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {84AD09F3-0363-4407-BEEA-8C5BD2CC8097} - System32\Tasks\Java => C:\Program Files\Java\jre6\bin\jusched.exe No File
Task: {85DD6276-7838-4232-8FF8-CB15EF58DF2E} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => c:\program files\real\realplayer\Update\realsched.exe [2013-01-19] (RealNetworks, Inc.)
Task: {87BD1C97-0934-4021-9770-D7B1B1D7BD60} - System32\Tasks\DSite => C:\Users\Olaf\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File
Task: {8B480174-D82C-4A8B-87BA-E31D091FBEE8} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2008-01-18] (Microsoft Corporation)
Task: {8EB3A4B7-9C62-4B08-BBD5-E9D07C405232} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-18] (Microsoft Corporation)
Task: {935C56FB-D42B-44EE-AC9D-1AA796AE50F5} - System32\Tasks\Microsoft_Hardware_Launch_vVX3000_exe => C:\Windows\vVX3000.exe [2007-04-10] (Microsoft Corporation)
Task: {95203A9F-5EA3-4B81-BFA3-71B4BC5CF928} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation)
Task: {9B8ACEE6-311B-49BC-A6BD-AFEACE7ACE22} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1566220321-2446519374-2048356015-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2012-11-30] (RealNetworks, Inc.)
Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-18] (Microsoft Corporation)
Task: {ABFD2AB8-A215-4E35-9FD6-B9A5601667D8} - System32\Tasks\BFGLaunch_bfgclient => C:\Program Files\bfgclient\bfgclient.exe [2011-08-19] ()
Task: {ADCC9A85-0C50-4AB5-9E44-4B9F6284A276} - System32\Tasks\Real Networks Scheduler => C:\Program Files\Common Files\Real\Update_OB\realsched.exe No File
Task: {BF1C88C9-B12C-4864-AE01-6708114BA952} - System32\Tasks\Microsoft\Windows\RestartManager\{FB86C79C-478C-4f3f-ACE2-A09F149B1F14} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {C3FA9EBC-FB39-4AE9-9E95-815475E63CFD} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe No File
Task: {D5416E71-9E9F-48C1-B2D5-3AB4B800F53D} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {D7AF7F31-F249-44C7-ABA8-F7D445C0B5E0} - System32\Tasks\Super Lyrics Update => C:\Program Files\Super_Lyrics\SuperLupdater.exe [2013-07-22] (Super Add-on Software)
Task: {DAB924FD-E6EF-440F-93CD-EFC99231D994} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-07-20] (Google Inc.)
Task: {E3EA736A-C48A-4E4A-915A-621B34A323F4} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: {E609BE22-FE85-4943-9724-2850F6E23B7B} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation)
Task: {E8C81B95-6D19-40F4-A23E-AE86EF0ED417} - System32\Tasks\User_Feed_Synchronization-{F658E2FC-1F92-4830-9F47-9F66D638EB43} => C:\Windows\system32\msfeedssync.exe [2011-11-06] (Microsoft Corporation)
Task: {EA1D2880-8265-4C27-92EF-B7589412DB10} - System32\Tasks\BFGLaunch_bfgprocess => C:\Program Files\bfgclient\bfgprocess.exe [2011-08-19] ()
Task: {F1A24C80-DAA3-4545-A909-B89B215396B2} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core.job => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA.job => C:\Users\Olaf\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Super Lyrics Update.job => C:\Program Files\Super_Lyrics\SuperLupdater.exe

==================== Faulty Device Manager Devices =============

Name: Microsoft-ISATAP-Adapter
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Microsoft-ISATAP-Adapter #3
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: =========================

Application errors:
==================
Error: (08/10/2013 09:01:45 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (08/10/2013 09:01:45 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (08/10/2013 08:47:53 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (08/10/2013 08:47:53 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (08/10/2013 04:51:33 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (08/10/2013 04:51:33 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service) (User: )
Description: Eintrag <C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA> in der Hash-Zuordnung kann nicht aktualisiert werden.

Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)


System errors:
=============
Error: (08/11/2013 01:16:16 PM) (Source: Service Control Manager) (User: )
Description: NVIDIA Update Service Daemon%%1069

Error: (08/11/2013 01:16:16 PM) (Source: Service Control Manager) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330

Error: (08/11/2013 01:15:02 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058

Error: (08/11/2013 01:15:02 PM) (Source: Service Control Manager) (User: )
Description: Net.Pipe-Listeneradapterwas

Error: (08/11/2013 01:15:02 PM) (Source: Service Control Manager) (User: )
Description: Net.Msmq-Listeneradaptermsmq

Error: (08/11/2013 01:14:07 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalAktivierung{D215781D-019E-4FA0-903D-0CDCDE13A4F5}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)

Error: (08/11/2013 01:13:51 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 10.08.2013 um 21:06:24 unerwartet heruntergefahren.

Error: (08/10/2013 09:03:31 PM) (Source: Service Control Manager) (User: )
Description: NVIDIA Update Service Daemon%%1069

Error: (08/10/2013 09:03:31 PM) (Source: Service Control Manager) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330

Error: (08/10/2013 09:01:55 PM) (Source: Service Control Manager) (User: )
Description: Net.Tcp-ListeneradapterNet.Tcp-Portfreigabedienst%%1058


Microsoft Office Sessions:
=========================
Error: (08/10/2013 09:01:45 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe

Error: (08/10/2013 09:01:45 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe

Error: (08/10/2013 08:47:53 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe

Error: (08/10/2013 08:47:53 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe

Error: (08/10/2013 04:51:33 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe

Error: (08/10/2013 04:51:33 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}\recordingmanager.exe

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\DB

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA

Error: (08/10/2013 00:54:25 PM) (Source: Windows Search Service)(User: )
Description: Kontext:  Anwendung, SystemIndex Katalog


Details:
	Ein an das System angeschlossenes Gerät funktioniert nicht.   (0x8007001f)
C:\USERS\OLAF\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\5S97VOZC.DEFAULT\CACHE\3\AA


==================== Memory info =========================== 

Percentage of memory in use: 53%
Total physical RAM: 2558.58 MB
Available physical RAM: 1193.02 MB
Total Pagefile: 5351.68 MB
Available Pagefile: 3875.03 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905.57 MB

==================== Drives ================================

Drive c: (HP) (Fixed) (Total:292.8 GB) (Free:83.75 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive j: (Elements) (Fixed) (Total:1397.26 GB) (Free:1057.89 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 1549F232)
Partition 1: (Active) - (Size=293 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=5 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (MBR Code: Windows XP) (Size: 1397 GB) (Disk ID: 00111F03)
Partition 1: (Not Active) - (Size=-698724909056) - (Type=07 NTFS)

==================== End Of Log ============================
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-07-2013 (ATTENTION: FRST version is 21 days old)
Ran by Olaf (administrator) on 11-08-2013 13:29:13
Running from C:\Users\Olaf\Desktop
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
() C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
() C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Iminent) C:\Program Files\Common Files\Umbrella\umbrella.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
() C:\Program Files\Steganos Safe Home\SteganosHotKeyService.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\tv_w32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Company) C:\hp\kbd\kbd.exe
(Microsoft Corporation) C:\Windows\system32\sdclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe

==================== Registry (Whitelisted) ==================

MountPoints2: {f75312be-89cf-11de-a996-001a92486b3f} - J:\Menu.exe
HKU\IUSR_NMPR\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-18] (Microsoft Corporation)
HKU\IUSR_NMPR\...\Run: [ICQ] - "C:\Program Files\ICQ6\ICQ.exe" silent [x]
HKU\IUSR_NMPR\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x]
HKU\IUSR_NMPR\...\RunOnce: [ICQ Lite] - C:\Program Files\ICQLite\ICQLite.exe -trayboot [x]
HKU\IUSR_NMPR\...\RunOnce: [DATA BECKER Registrierung] - "C:\Program Files\Internet Explorer\Iexplore.exe" C:\Program Files\DATA BECKER\Visitenkarten-Druckerei 10\Support\Online\index.htm [x]

==================== Internet (Whitelisted) ====================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {99BF4F38-A3A2-412A-996F-AAD9A3406746} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06
SearchScopes: HKCU - {639C8579-AFEB-4039-886E-D4B7612A0244} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=YYYYYYYYDE&apn_uid=E918B100-3F16-4AFE-9A56-655241D70738&apn_sauid=FA585939-A01E-4CF2-B412-32F822B64359
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll (Super Add-on Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Super Lyrics - {B9020890-9E08-446B-87B0-0C5CD0436D86} - C:\Program Files\Super_Lyrics\116.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value - 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default
FF user.js: detected! => C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\user.js
FF SelectedSearchEngine: Google.de
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/radio ffn Rekorder - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( )
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede-pws.xml
FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede.xml
FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com
FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\plugin@starstable.com
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: ciuvo-extension - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\ciuvo-extension@icq.de.xpi
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi
FF Extension: No Name - C:\Program Files\Super_Lyrics\125.xpi

Chrome: 
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Shockwave for Director) - C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealArcade Mozilla Plugin) - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll (RealNetworks)
CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (phonostar Detector) - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( )
CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Docs) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (Super Lyrics) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnjcnjlaajofpendibcoodneacalfho\1.125_0
CHR Extension: (YouTube) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (RealDownloader) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0
CHR Extension: (Gmail) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [bgnjcnjlaajofpendibcoodneacalfho] - C:\Program Files\Super_Lyrics\125.crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2938408 2013-07-02] (Emsisoft GmbH)
S3 AlertService; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [188416 2006-09-11] (Intel(R) Corporation)
R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [208896 2006-09-03] ()
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-08-10] (The Firebird Project)
S2 IntelDHSvcConf; C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [29696 2006-05-10] (Intel(R) Corporation)
S3 ISSM; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [75264 2006-09-11] (Intel(R) Corporation)
S3 M1 Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [26624 2006-09-01] ()
S3 MCLServiceATL; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [167936 2006-09-11] (Intel(R) Corporation)
R2 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
S3 Remote UI Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [544256 2006-09-11] (Intel(R) Corporation)
R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2864448 2013-08-05] (Iminent)
S3 stllssvr; "c:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [x]

==================== Drivers (Whitelisted) ====================

S3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [54072 2012-04-30] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R2 ACEDRV07; C:\Windows\system32\drivers\ACEDRV07.sys [101376 2007-09-27] (Protect Software GmbH)
R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.)
S3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50208 2013-07-02] (Emsisoft GmbH)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [21248 2003-09-20] (Padus, Inc.)
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [90536 2008-05-27] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-05-27] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [122152 2008-05-27] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [115496 2008-05-27] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [25768 2008-05-27] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [111912 2008-05-27] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [117672 2008-05-27] (MCCI Corporation)
R1 SLEE_14_DRIVER; C:\Windows\system32\drivers\Sleen14.sys [72480 2006-11-08] (Softwareentwicklung Remus - ArchiCrypt )
S3 TSHWMDTCP; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [4608 2006-07-13] ()
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 ZD1211BU(ZyDAS); system32\DRIVERS\zd1211Bu.sys [x]
S3 ZDPSp60; System32\Drivers\ZDPSp60.sys [x]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-08-10 14:35 - 2013-08-10 21:06 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware
2013-08-10 14:30 - 2013-08-10 14:34 - 187662064 _____ (Emsisoft GmbH                                               ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent
2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-08-05 22:19 - 2013-08-10 10:21 - 00000000 ____D C:\Program Files\Common Files\Umbrella
2013-08-05 22:19 - 2013-08-05 22:20 - 00000000 ____D C:\Program Files\Iminent
2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe
2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe
2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp
2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat
2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup
2013-07-30 15:50 - 2013-08-05 21:27 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-07-30 15:49 - 2011-10-24 13:35 - 00000000 ____D C:\Users\Olaf\Downloads\Tweaking.com - Windows Repair
2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio
2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio
2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip
2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp
2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe
2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe
2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe
2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1
2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe
2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe
2013-07-23 18:18 - 2013-07-22 20:26 - 01219874 _____ (Farbar) C:\Users\Olaf\Desktop\FRST.exe
2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp
2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT
2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe
2013-07-23 15:32 - 2013-07-23 15:38 - 00030353 _____ C:\AdwCleaner[S1].txt
2013-07-23 15:32 - 2013-07-23 15:38 - 00000105 _____ C:\Windows\DeleteOnReboot.bat
2013-07-23 15:27 - 2013-07-23 15:28 - 00031376 _____ C:\AdwCleaner[R1].txt
2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe
2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics
2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk
2013-07-22 23:27 - 2013-07-22 23:28 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe
2013-07-22 22:10 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-22 22:10 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-22 22:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-22 22:07 - 2013-07-22 22:09 - 00000000 ____D C:\Qoobox
2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt
2013-07-22 22:02 - 2013-07-22 23:56 - 00000000 ___SD C:\32788R22FWJFW
2013-07-22 21:07 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-22 21:07 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-22 21:07 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-22 21:07 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-22 21:07 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-22 21:07 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-22 21:07 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-22 21:07 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-22 21:07 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-22 21:07 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-22 21:07 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-22 21:07 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-22 21:07 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-22 21:07 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-22 21:07 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-22 21:07 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe
2013-07-22 20:34 - 2013-07-22 20:34 - 00000000 ____D C:\FRST
2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp
2013-07-20 23:16 - 2013-08-11 13:14 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job
2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
2013-07-20 19:31 - 2013-07-20 19:32 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-20 19:22 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-07-20 19:20 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-20 19:20 - 2013-05-08 06:37 - 00905576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-07-20 19:19 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-20 19:19 - 2013-05-03 00:03 - 03603832 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-07-20 19:19 - 2013-05-03 00:03 - 03551096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-07-20 19:19 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-07-20 19:19 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00985600 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-07-20 19:19 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-07-20 19:19 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-20 19:19 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-20 19:19 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-20 19:19 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-20 19:19 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-20 19:19 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-20 19:19 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-20 19:19 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-20 19:19 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-07-20 19:18 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp
2013-07-20 18:37 - 2013-08-11 13:14 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-20 18:37 - 2013-08-10 20:47 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common
2013-07-20 18:29 - 2013-07-20 18:30 - 00393064 _____ (Softonic                                        ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe

==================== One Month Modified Files and Folders =======

2013-08-11 13:29 - 2007-04-02 16:15 - 00000000 ___RD C:\Users\Olaf\Desktop
2013-08-11 13:21 - 2006-11-02 12:33 - 01586480 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-11 13:17 - 2011-12-12 16:11 - 01768361 _____ C:\Windows\WindowsUpdate.log
2013-08-11 13:14 - 2013-07-20 23:16 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job
2013-08-11 13:14 - 2013-07-20 18:37 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-11 13:14 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-11 13:14 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-11 13:14 - 2006-11-02 14:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-11 13:13 - 2008-01-08 16:06 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-11 13:13 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-10 21:06 - 2013-08-10 14:35 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-08-10 21:06 - 2006-11-02 15:01 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-10 20:53 - 2012-04-25 14:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-10 20:47 - 2013-07-20 18:37 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-10 15:23 - 2013-04-10 15:28 - 00006374 _____ C:\Windows\PFRO.log
2013-08-10 15:09 - 2011-11-23 21:41 - 00001134 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA.job
2013-08-10 15:09 - 2011-11-23 21:41 - 00001112 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core.job
2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-08-10 14:37 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Public\Desktop
2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware
2013-08-10 14:34 - 2013-08-10 14:30 - 187662064 _____ (Emsisoft GmbH                                               ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe
2013-08-10 14:34 - 2007-01-20 20:04 - 00000000 ____D C:\Program Files\Google
2013-08-10 11:56 - 2007-06-27 14:40 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-08-10 10:21 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Common Files\Umbrella
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent
2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-08-05 22:20 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Iminent
2013-08-05 22:16 - 2007-04-12 17:11 - 00000000 ____D C:\Users\Olaf\AppData\Local\Adobe
2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe
2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe
2013-08-05 21:35 - 2007-04-02 16:27 - 00146568 _____ C:\Users\Olaf\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-05 21:32 - 2006-11-02 14:47 - 00443208 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp
2013-08-05 21:31 - 2013-04-13 13:15 - 295539634 _____ C:\Windows\MEMORY.DMP
2013-08-05 21:31 - 2009-05-13 17:54 - 00000000 ____D C:\Windows\Minidump
2013-08-05 21:27 - 2013-07-30 15:50 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-08-03 14:48 - 2007-07-10 16:43 - 03716436 _____ C:\Users\Mariessa\01 Heul Doch.wma
2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat
2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup
2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio
2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio
2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip
2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp
2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe
2013-07-24 00:16 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe
2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe
2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1
2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe
2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe
2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp
2013-07-23 17:52 - 2007-04-02 21:35 - 00000000 ____D C:\Users\Olaf\AppData\Local\Google
2013-07-23 17:38 - 2008-07-29 10:55 - 00000000 ____D C:\Users\Gast\Desktop
2013-07-23 17:38 - 2007-05-12 17:08 - 00000000 ____D C:\Program Files\InterActual
2013-07-23 17:38 - 2007-01-20 19:54 - 00000000 ___RD C:\Users\IUSR_NMPR\Desktop
2013-07-23 17:37 - 2011-05-03 15:47 - 00000000 ____D C:\Program Files\Medion GoPal Assistant
2013-07-23 17:22 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT
2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe
2013-07-23 15:38 - 2013-07-23 15:32 - 00030353 _____ C:\AdwCleaner[S1].txt
2013-07-23 15:38 - 2013-07-23 15:32 - 00000105 _____ C:\Windows\DeleteOnReboot.bat
2013-07-23 15:33 - 2013-01-27 13:53 - 00000000 ____D C:\ProgramData\GinyasBrowserCompanion
2013-07-23 15:28 - 2013-07-23 15:27 - 00031376 _____ C:\AdwCleaner[R1].txt
2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe
2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics
2013-07-23 00:21 - 2007-01-20 19:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-07-22 23:56 - 2013-07-22 22:02 - 00000000 ___SD C:\32788R22FWJFW
2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk
2013-07-22 23:28 - 2013-07-22 23:27 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe
2013-07-22 23:14 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-22 23:14 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-07-22 22:09 - 2013-07-22 22:07 - 00000000 ____D C:\Qoobox
2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt
2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe
2013-07-22 20:50 - 2012-11-06 23:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-22 20:45 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-22 20:34 - 2013-07-22 20:34 - 00000000 ____D C:\FRST
2013-07-22 20:26 - 2013-07-23 18:18 - 01219874 _____ (Farbar) C:\Users\Olaf\Desktop\FRST.exe
2013-07-20 23:25 - 2013-04-13 03:02 - 00000796 _____ C:\Windows\setupact.log
2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp
2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
2013-07-20 19:32 - 2013-07-20 19:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-20 18:56 - 2012-04-25 14:17 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-20 18:56 - 2011-08-28 08:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp
2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common
2013-07-20 18:31 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-07-20 18:30 - 2013-07-20 18:29 - 00393064 _____ (Softonic                                        ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-11 13:22

==================== End Of Log ============================
         
--- --- ---


Liebe Grüße

Tanja

Alt 11.08.2013, 16:35   #32
schrauber
/// the machine
/// TB-Ausbilder
 

tcbhn wurde beendet - Standard

tcbhn wurde beendet



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
MountPoints2: {f75312be-89cf-11de-a996-001a92486b3f} - J:\Menu.exe
SearchScopes: HKCU - {639C8579-AFEB-4039-886E-D4B7612A0244} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=U3&apn_dtid=YYYYYYYYDE&apn_uid=E918B100-3F16-4AFE-9A56-655241D70738&apn_sauid=FA585939-A01E-4CF2-B412-32F822B64359
BHO: Super Lyrics - {B9020890-9E08-446B-87B0-0C5CD0436D86} - C:\Program Files\Super_Lyrics\116.dll No File
CHR Extension: (Super Lyrics) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnjcnjlaajofpendibcoodneacalfho\1.125_0
CHR HKLM\...\Chrome\Extension: [bgnjcnjlaajofpendibcoodneacalfho] - C:\Program Files\Super_Lyrics\125.crx
R2 SProtection; C:\Program Files\Common Files\Umbrella\umbrella.exe [2864448 2013-08-05] (Iminent)
S3 stllssvr; "c:\Program Files\Common Files\SureThing Shared\stllssvr.exe" [x]
C:\Program Files\Common Files\Umbrella
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent
2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-08-05 22:19 - 2013-08-10 10:21 - 00000000 ____D C:\Program Files\Common Files\Umbrella
2013-08-05 22:19 - 2013-08-05 22:20 - 00000000 ____D C:\Program Files\Iminent
2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics
2013-07-20 23:16 - 2013-08-11 13:14 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job
2013-08-10 10:21 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Common Files\Umbrella
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Iminent
2013-08-05 22:38 - 2013-08-05 22:38 - 00000000 ____D C:\ProgramData\Iminent
2013-08-05 22:20 - 2013-08-05 22:20 - 00000611 _____ C:\Windows\system32\InstallUtil.InstallLog
2013-08-05 22:20 - 2013-08-05 22:19 - 00000000 ____D C:\Program Files\Iminent
2013-07-23 15:33 - 2013-01-27 13:53 - 00000000 ____D C:\ProgramData\GinyasBrowserCompanion
2013-07-23 15:09 - 2013-07-23 15:09 - 00000000 ____D C:\Program Files\Super_Lyrics
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Revo Uninstaller Pro - Uninstall Software, Remove Programs easily, Forced Uninstall, Leftovers Uninstaller
Benutz das zum restlosen Entfernen von Firefox. Ebenso bitte alles von Nvidia deinstallieren und dann neu installieren.
__________________

__________________

Alt 12.08.2013, 16:29   #33
Rosanja
 
tcbhn wurde beendet - Standard

tcbhn wurde beendet



Hab alles so gemacht wie du gesagt hast. Es kommt folgende Meldung:
Looks you don´t know what to do. To prevent damage to the system the tool will exit.
Wenn ich OK drücke passiert nichts.
??????????
__________________

Alt 12.08.2013, 17:40   #34
schrauber
/// the machine
/// TB-Ausbilder
 

tcbhn wurde beendet - Standard

tcbhn wurde beendet



wann kommt die Meldung?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.08.2013, 15:15   #35
Rosanja
 
tcbhn wurde beendet - Standard

tcbhn wurde beendet



nachdem ich den Fix Button gedrückt habe!


Alt 13.08.2013, 18:13   #36
schrauber
/// the machine
/// TB-Ausbilder
 

tcbhn wurde beendet - Standard

tcbhn wurde beendet



FRST löschen, neu laden. Überprüf deine fixlist, die muss so aussehen wie oben, dann nochmal probieren.
__________________
--> tcbhn wurde beendet

Alt 14.08.2013, 18:06   #37
Rosanja
 
tcbhn wurde beendet - Standard

tcbhn wurde beendet



Hab es hinbekommen, beim ersten Mal habe ich einen Fehler gemacht!
Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-08-2013 01
Ran by Olaf at 2013-08-14 18:42:03 Run:2
Running from C:\Users\Olaf\Downloads
Boot Mode: Normal

==============================================

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f75312be-89cf-11de-a996-001a92486b3f} => Key not found.
HKCR\CLSID\{f75312be-89cf-11de-a996-001a92486b3f} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{639C8579-AFEB-4039-886E-D4B7612A0244} => Key not found.
HKCR\Wow6432Node\CLSID\{639C8579-AFEB-4039-886E-D4B7612A0244} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9020890-9E08-446B-87B0-0C5CD0436D86} => Key not found.
HKCR\CLSID\{B9020890-9E08-446B-87B0-0C5CD0436D86} => Key not found.
C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnjcnjlaajofpendibcoodneacalfho directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\bgnjcnjlaajofpendibcoodneacalfho => Key not found.
"C:\Program Files\Super_Lyrics\125.crx" => File/Directory not found.
SProtection => Service not found.
stllssvr => Service not found.
"C:\Program Files\Common Files\Umbrella" => File/Directory not found.
"C:\Users\Olaf\AppData\Roaming\Iminent" => File/Directory not found.
"C:\ProgramData\Iminent" => File/Directory not found.
"C:\Windows\system32\InstallUtil.InstallLog" => File/Directory not found.
"C:\Program Files\Common Files\Umbrella" => File/Directory not found.
"C:\Program Files\Iminent" => File/Directory not found.
"C:\Program Files\Super_Lyrics" => File/Directory not found.
"C:\Windows\Tasks\Super Lyrics Update.job" => File/Directory not found.
"C:\Program Files\Common Files\Umbrella" => File/Directory not found.
"C:\Users\Olaf\AppData\Roaming\Iminent" => File/Directory not found.
"C:\ProgramData\Iminent" => File/Directory not found.
"C:\Windows\system32\InstallUtil.InstallLog" => File/Directory not found.
"C:\Program Files\Iminent" => File/Directory not found.
"C:\ProgramData\GinyasBrowserCompanion" => File/Directory not found.
"C:\Program Files\Super_Lyrics" => File/Directory not found.

==== End of Fixlog ====
         

Alt 15.08.2013, 08:14   #38
schrauber
/// the machine
/// TB-Ausbilder
 

tcbhn wurde beendet - Standard

tcbhn wurde beendet



Frisches FRST Scanlog bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 15.08.2013, 15:19   #39
Rosanja
 
tcbhn wurde beendet - Standard

tcbhn wurde beendet



Eben hatte ich ein ganz buntes Pixelbild und einen Absturz (ich wollte während des Scans ins Internet.

Fehler:
Code:
ATTFilter
Problemsignatur:
  Problemereignisname:	BlueScreen
  Betriebsystemversion:	6.0.6002.2.2.0.768.3
  Gebietsschema-ID:	1031

Zusatzinformationen zum Problem:
  BCCode:	116
  BCP1:	8FC20008
  BCP2:	98F5C8D4
  BCP3:	C000009A
  BCP4:	00000004
  OS Version:	6_0_6002
  Service Pack:	2_0
  Product:	768_1

Dateien, die bei der Beschreibung des Problems hilfreich sind:
  C:\Windows\Minidump\Mini081513-01.dmp
  C:\Users\Olaf\AppData\Local\Temp\WER-317228-0.sysdata.xml
  C:\Users\Olaf\AppData\Local\Temp\WER909B.tmp.version.txt

Lesen Sie unsere Datenschutzrichtlinie:
  hxxp://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0407
         
FRST:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-08-2013 01
Ran by Olaf (administrator) on 15-08-2013 16:11:25
Running from C:\Users\Olaf\Downloads
Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
() C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(Hewlett-Packard Company) c:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
() C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
() C:\Program Files\Steganos Safe Home\SteganosHotKeyService.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\TeamViewer.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Hewlett-Packard Company) C:\hp\kbd\kbd.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version7\tv_w32.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-18] (Microsoft Corporation)
HKLM\...\Run: [hpsysdrv] - c:\hp\support\hpsysdrv.exe [65536 2006-09-28] (Hewlett-Packard Company)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [151552 2006-09-29] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [3784704 2006-11-09] (Realtek Semiconductor)
HKLM\...\Run: [SAFEHOME HotKeys] - C:\Program Files\Steganos Safe Home\SteganosHotKeyService.exe [25088 2006-12-05] ()
HKLM\...\Run: [KBD] - C:\HP\KBD\KbdStub.EXE [65536 2006-12-08] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295072 2013-01-19] (RealNetworks, Inc.)
HKLM\...\Run: [emsisoft anti-malware] - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe [2928040 2013-07-02] (Emsisoft GmbH)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\IUSR_NMPR\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\IUSR_NMPR\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [ 2008-01-18] (Microsoft Corporation)
HKU\IUSR_NMPR\...\Run: [ICQ] - "C:\Program Files\ICQ6\ICQ.exe" silent [x]
HKU\IUSR_NMPR\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [x]
HKU\IUSR_NMPR\...\RunOnce: [ICQ Lite] - C:\Program Files\ICQLite\ICQLite.exe -trayboot [x]
HKU\IUSR_NMPR\...\RunOnce: [DATA BECKER Registrierung] - C:\Program Files\Internet Explorer\Iexplore.exe [ 2013-05-29] (Microsoft Corporation)
HKU\UpdatusUser\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\UpdatusUser.Olaf-PC\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=71&bd=Pavilion&pf=desktop
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {99BF4F38-A3A2-412A-996F-AAD9A3406746} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=cb-hp06
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU -&Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp - No CLSID Value - 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default
FF user.js: detected! => C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\user.js
FF SelectedSearchEngine: Google.de
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/JavaPlugin,version=10.11.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/npracplug;version=1.0.0.0 - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.0.282 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @phonostar.de/radio ffn Rekorder - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( )
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede-pws.xml
FF SearchPlugin: C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\searchplugins\googlede.xml
FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\7125a285-7e68-47aa-9d72-e81874f4d47e@d3fcdb92-135d-4a8a-8cf6-11e3b57c5fda.com
FF Extension: No Name - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\plugin@starstable.com
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: ciuvo-extension - C:\Users\Olaf\AppData\Roaming\Mozilla\Firefox\Profiles\5s97vozc.default\Extensions\ciuvo-extension@icq.de.xpi
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi

Chrome: 
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Shockwave for Director) - C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealArcade Mozilla Plugin) - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll (RealNetworks)
CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (phonostar Detector) - C:\Program Files\radio ffn Rekorder\npphonostarDetectNP.dll ( )
CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Olaf\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (RealDownloader) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0
CHR Extension: (Gmail) - C:\Users\Olaf\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx

========================== Services (Whitelisted) =================

R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [2938408 2013-07-02] (Emsisoft GmbH)
S3 AlertService; C:\Program Files\Intel\IntelDH\CCU\AlertService.exe [188416 2006-09-11] (Intel(R) Corporation)
R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 DQLWinService; C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [208896 2006-09-03] ()
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-08-10] (The Firebird Project)
S2 IntelDHSvcConf; C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [29696 2006-05-10] (Intel(R) Corporation)
S3 ISSM; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe [75264 2006-09-11] (Intel(R) Corporation)
S3 M1 Server; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe [26624 2006-09-01] ()
S3 MCLServiceATL; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe [167936 2006-09-11] (Intel(R) Corporation)
R2 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
S3 Remote UI Service; C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe [544256 2006-09-11] (Intel(R) Corporation)

==================== Drivers (Whitelisted) ====================

S3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [54072 2012-04-30] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R2 ACEDRV07; C:\Windows\system32\drivers\ACEDRV07.sys [101376 2007-09-27] (Protect Software GmbH)
R3 Afc; C:\Windows\System32\drivers\Afc.sys [11776 2005-02-23] (Arcsoft, Inc.)
S3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50208 2013-07-02] (Emsisoft GmbH)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [21248 2003-09-20] (Padus, Inc.)
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [90536 2008-05-27] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [15016 2008-05-27] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [122152 2008-05-27] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [115496 2008-05-27] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [25768 2008-05-27] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [111912 2008-05-27] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [117672 2008-05-27] (MCCI Corporation)
R1 SLEE_14_DRIVER; C:\Windows\system32\drivers\Sleen14.sys [72480 2006-11-08] (Softwareentwicklung Remus - ArchiCrypt )
S3 TSHWMDTCP; C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [4608 2006-07-13] ()
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 ZD1211BU(ZyDAS); system32\DRIVERS\zd1211Bu.sys [x]
S3 ZDPSp60; System32\Drivers\ZDPSp60.sys [x]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [x]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [x]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-08-13 19:55 - 2013-08-13 19:55 - 00000814 _____ C:\Users\Olaf\Desktop\FRST.exe.lnk
2013-08-13 19:53 - 2013-08-13 19:53 - 01068613 _____ (Farbar) C:\Users\Olaf\Downloads\FRST.exe
2013-08-12 15:50 - 2013-08-12 15:50 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja (1).zip
2013-08-12 15:38 - 2013-08-12 15:39 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja.zip
2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-08-10 14:35 - 2013-08-13 19:01 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware
2013-08-10 14:30 - 2013-08-10 14:34 - 187662064 _____ (Emsisoft GmbH                                               ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe
2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe
2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe
2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp
2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat
2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup
2013-07-30 15:50 - 2013-08-05 21:27 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-07-30 15:49 - 2011-10-24 13:35 - 00000000 ____D C:\Users\Olaf\Downloads\Tweaking.com - Windows Repair
2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio
2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio
2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip
2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp
2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe
2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe
2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe
2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1
2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe
2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe
2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp
2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT
2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe
2013-07-23 15:32 - 2013-07-23 15:38 - 00030353 _____ C:\AdwCleaner[S1].txt
2013-07-23 15:32 - 2013-07-23 15:38 - 00000105 _____ C:\Windows\DeleteOnReboot.bat
2013-07-23 15:27 - 2013-07-23 15:28 - 00031376 _____ C:\AdwCleaner[R1].txt
2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe
2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk
2013-07-22 23:27 - 2013-07-22 23:28 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe
2013-07-22 22:10 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-22 22:10 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-22 22:10 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-22 22:10 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-22 22:07 - 2013-07-22 22:09 - 00000000 ____D C:\Qoobox
2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt
2013-07-22 22:02 - 2013-07-22 23:56 - 00000000 ___SD C:\32788R22FWJFW
2013-07-22 21:07 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-22 21:07 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-22 21:07 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-22 21:07 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-07-22 21:07 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-22 21:07 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-22 21:07 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-07-22 21:07 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-22 21:07 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-07-22 21:07 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-07-22 21:07 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-22 21:07 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-22 21:07 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-22 21:07 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-22 21:07 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-07-22 21:07 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe
2013-07-22 20:34 - 2013-08-12 16:45 - 00000000 ____D C:\FRST
2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp
2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
2013-07-20 19:31 - 2013-07-20 19:32 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-20 19:22 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-07-20 19:20 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-20 19:20 - 2013-05-08 06:37 - 00905576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-07-20 19:19 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-20 19:19 - 2013-05-03 00:03 - 03603832 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-07-20 19:19 - 2013-05-03 00:03 - 03551096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-07-20 19:19 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-07-20 19:19 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00985600 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-07-20 19:19 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-07-20 19:19 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-07-20 19:19 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-07-20 19:19 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-07-20 19:19 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-07-20 19:19 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-07-20 19:19 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-07-20 19:19 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-07-20 19:19 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-07-20 19:19 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-20 19:19 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-07-20 19:18 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp
2013-07-20 18:37 - 2013-08-15 16:04 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-20 18:37 - 2013-08-15 15:47 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common
2013-07-20 18:29 - 2013-07-20 18:30 - 00393064 _____ (Softonic                                        ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe

==================== One Month Modified Files and Folders =======

2013-08-15 16:04 - 2013-08-15 16:04 - 00201176 _____ C:\Windows\Minidump\Mini081513-01.dmp
2013-08-15 16:04 - 2013-07-20 18:37 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-15 16:04 - 2009-05-13 17:54 - 00000000 ____D C:\Windows\Minidump
2013-08-15 16:04 - 2008-01-08 16:06 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-15 16:04 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-15 16:04 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-15 16:04 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-15 16:04 - 2006-11-02 14:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-08-15 16:03 - 2013-04-13 13:15 - 391700939 _____ C:\Windows\MEMORY.DMP
2013-08-15 15:53 - 2012-04-25 14:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-15 15:47 - 2013-07-20 18:37 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-15 15:26 - 2006-11-02 12:33 - 01586480 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-15 15:24 - 2011-12-12 16:11 - 01918268 _____ C:\Windows\WindowsUpdate.log
2013-08-14 21:09 - 2011-11-23 21:41 - 00001134 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001UA.job
2013-08-13 19:55 - 2013-08-13 19:55 - 00000814 _____ C:\Users\Olaf\Desktop\FRST.exe.lnk
2013-08-13 19:53 - 2013-08-13 19:53 - 01068613 _____ (Farbar) C:\Users\Olaf\Downloads\FRST.exe
2013-08-13 19:01 - 2013-08-10 14:35 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2013-08-12 16:45 - 2013-07-22 20:34 - 00000000 ____D C:\FRST
2013-08-12 15:50 - 2013-08-12 15:50 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja (1).zip
2013-08-12 15:39 - 2013-08-12 15:38 - 13381491 _____ C:\Users\Olaf\Downloads\Tanja.zip
2013-08-12 15:09 - 2011-11-23 21:41 - 00001112 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1566220321-2446519374-2048356015-1001Core.job
2013-08-10 21:06 - 2006-11-02 15:01 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-10 15:23 - 2013-04-10 15:28 - 00006374 _____ C:\Windows\PFRO.log
2013-08-10 14:37 - 2013-08-10 14:37 - 00000850 _____ C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
2013-08-10 14:35 - 2013-08-10 14:35 - 00001933 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 14:35 - 2013-08-10 14:35 - 00000000 ____D C:\Users\Olaf\Downloads\Documents\Anti-Malware
2013-08-10 14:34 - 2013-08-10 14:30 - 187662064 _____ (Emsisoft GmbH                                               ) C:\Users\Olaf\Downloads\EmsisoftAntiMalwareSetup.exe
2013-08-10 14:34 - 2007-01-20 20:04 - 00000000 ____D C:\Program Files\Google
2013-08-10 11:56 - 2007-06-27 14:40 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-08-05 22:16 - 2007-04-12 17:11 - 00000000 ____D C:\Users\Olaf\AppData\Local\Adobe
2013-08-05 22:13 - 2013-08-05 22:13 - 00288672 _____ C:\Users\Olaf\Downloads\Adobe%20Reader.exe
2013-08-05 22:11 - 2013-08-05 22:11 - 03400936 _____ C:\Users\Olaf\Downloads\installer_pdf_reader_Deutsch.exe
2013-08-05 21:35 - 2007-04-02 16:27 - 00146568 _____ C:\Users\Olaf\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-05 21:32 - 2006-11-02 14:47 - 00443208 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-05 21:31 - 2013-08-05 21:31 - 00155712 _____ C:\Windows\Minidump\Mini080513-01.dmp
2013-08-05 21:27 - 2013-07-30 15:50 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE
2013-08-03 14:48 - 2007-07-10 16:43 - 03716436 _____ C:\Users\Mariessa\01 Heul Doch.wma
2013-07-31 17:59 - 2013-07-31 17:59 - 00000207 _____ C:\Windows\tweaking.com-regbackup-OLAF-PC-Microsoft®-Windows-Vista™-Home-Premium-(32-Bit).dat
2013-07-31 17:57 - 2013-07-31 17:57 - 00000000 ____D C:\RegBackup
2013-07-30 15:47 - 2013-07-30 15:47 - 00000000 ____D C:\Users\Olaf\Desktop\tweaking.com_windows_repair_aio
2013-07-30 15:45 - 2013-07-30 15:45 - 00000000 ____D C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio
2013-07-30 15:40 - 2013-07-30 15:40 - 03517580 _____ C:\Users\Olaf\Downloads\tweaking.com_windows_repair_aio.zip
2013-07-30 15:34 - 2013-07-30 15:34 - 00139496 _____ C:\Windows\Minidump\Mini073013-01.dmp
2013-07-24 17:24 - 2013-07-24 17:24 - 00448512 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\TFC.exe
2013-07-24 00:16 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-07-23 21:19 - 2013-07-23 21:19 - 00891062 _____ C:\Users\Olaf\Desktop\SecurityCheck.exe
2013-07-23 20:31 - 2013-07-23 20:31 - 02347384 _____ (ESET) C:\Users\Olaf\Downloads\esetsmartinstaller_enu.exe
2013-07-23 18:43 - 2013-07-23 18:43 - 00000000 ____D C:\2e25bc9a05b08dace7427c46ed41c1
2013-07-23 18:36 - 2013-07-23 18:36 - 00377856 _____ C:\Users\Olaf\Desktop\gmer_2.1.19163.exe
2013-07-23 18:34 - 2013-07-23 18:34 - 00602112 _____ (OldTimer Tools) C:\Users\Olaf\Desktop\OTL.exe
2013-07-23 18:09 - 2013-07-23 18:09 - 00155632 _____ C:\Windows\Minidump\Mini072313-01.dmp
2013-07-23 17:52 - 2007-04-02 21:35 - 00000000 ____D C:\Users\Olaf\AppData\Local\Google
2013-07-23 17:38 - 2007-05-12 17:08 - 00000000 ____D C:\Program Files\InterActual
2013-07-23 17:37 - 2011-05-03 15:47 - 00000000 ____D C:\Program Files\Medion GoPal Assistant
2013-07-23 17:22 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache
2013-07-23 16:25 - 2013-07-23 16:25 - 00000000 ____D C:\Windows\ERUNT
2013-07-23 16:21 - 2013-07-23 16:21 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Olaf\Desktop\JRT.exe
2013-07-23 15:38 - 2013-07-23 15:32 - 00030353 _____ C:\AdwCleaner[S1].txt
2013-07-23 15:38 - 2013-07-23 15:32 - 00000105 _____ C:\Windows\DeleteOnReboot.bat
2013-07-23 15:28 - 2013-07-23 15:27 - 00031376 _____ C:\AdwCleaner[R1].txt
2013-07-23 15:14 - 2013-07-23 15:14 - 00666633 _____ C:\Users\Olaf\Desktop\adwcleaner.exe
2013-07-23 00:21 - 2007-01-20 19:51 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-07-22 23:56 - 2013-07-22 22:02 - 00000000 ___SD C:\32788R22FWJFW
2013-07-22 23:36 - 2013-07-22 23:36 - 00000853 _____ C:\Users\Olaf\Desktop\ComboFix(1) - Verknüpfung.lnk
2013-07-22 23:28 - 2013-07-22 23:27 - 05091940 _____ (Swearware) C:\Users\Olaf\Downloads\ComboFix.exe
2013-07-22 23:14 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-07-22 23:14 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-07-22 22:09 - 2013-07-22 22:07 - 00000000 ____D C:\Qoobox
2013-07-22 22:03 - 2013-07-22 22:03 - 00000000 ____D C:\Windows\erdnt
2013-07-22 21:06 - 2013-07-22 21:06 - 00050477 _____ C:\Users\Olaf\Downloads\Defogger.exe
2013-07-22 20:50 - 2012-11-06 23:48 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-22 20:45 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-20 23:25 - 2013-04-13 03:02 - 00000796 _____ C:\Windows\setupact.log
2013-07-20 23:19 - 2013-07-20 23:19 - 00156160 _____ C:\Windows\Minidump\Mini072013-02.dmp
2013-07-20 22:49 - 2013-07-20 22:49 - 00001991 _____ C:\Users\Olaf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk
2013-07-20 19:32 - 2013-07-20 19:31 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-07-20 18:56 - 2012-04-25 14:17 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-07-20 18:56 - 2011-08-28 08:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-07-20 18:51 - 2013-07-20 18:51 - 00160000 _____ C:\Windows\Minidump\Mini072013-01.dmp
2013-07-20 18:32 - 2013-07-20 18:32 - 02195988 _____ C:\Users\Olaf\Desktop\tdsskiller-2-8-14-0.zip
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\PiccShare
2013-07-20 18:32 - 2013-07-20 18:32 - 00000000 ____D C:\Users\Olaf\AppData\Roaming\Common
2013-07-20 18:31 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public
2013-07-20 18:30 - 2013-07-20 18:29 - 00393064 _____ (Softonic                                        ) C:\Users\Olaf\Downloads\SoftonicDownloader_fuer_kaspersky-tdsskiller.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-08-15 16:11

==================== End Of Log ============================
         
--- --- ---

Alt 15.08.2013, 18:49   #40
schrauber
/// the machine
/// TB-Ausbilder
 

tcbhn wurde beendet - Standard

tcbhn wurde beendet



Zitat:
C:\Windows\Minidump\Mini081513-01.dmp
Diese Datei brauch ich. Als ZIP anhängen bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu tcbhn wurde beendet
beendet, bild, computer, erhalte, fehler, firefox, fotogalerie, funktioniert, funktioniert nicht, funktioniert nicht mehr, jahre, kaspersky, kostenlose, medion, meldung, neu, nicht mehr, nichts, picasa, probleme, runter, schließe, schwarzes, schwere, sieben, tdss, version, virus, vista, weißer, windows, zeitlupe




Ähnliche Themen: tcbhn wurde beendet


  1. tcbhn hat ein Problem festgestellt und muß beendet werden
    Log-Analyse und Auswertung - 08.02.2015 (1)
  2. Remoteprozeduraufruf wurde unerwartet beendet
    Plagegeister aller Art und deren Bekämpfung - 25.08.2013 (3)
  3. "tcbhn hat ein Problem festgestellt und muß beendet werden"
    Plagegeister aller Art und deren Bekämpfung - 01.08.2013 (16)
  4. Windows XP start: tcbhn.exe hat ein Problem festgestellt und muss beendet werden
    Log-Analyse und Auswertung - 23.07.2013 (30)
  5. Fehlermeldung: tcbhn wurde geschlossen
    Log-Analyse und Auswertung - 08.07.2013 (11)
  6. tcbhn wurde beendet und geschlossen!
    Log-Analyse und Auswertung - 14.06.2013 (30)
  7. tcbhn wurde beendet und geschlossen
    Plagegeister aller Art und deren Bekämpfung - 13.06.2013 (47)
  8. Tcbhn wurde beendet und geschlossen - Virus?
    Plagegeister aller Art und deren Bekämpfung - 08.06.2013 (9)
  9. tcbhn.exe wurde beendet und geschlossen.
    Plagegeister aller Art und deren Bekämpfung - 14.05.2013 (17)
  10. tcbhn.exe wurde beendet und geschlossen.
    Plagegeister aller Art und deren Bekämpfung - 07.05.2013 (3)
  11. Tcbhn wurde beendet und geschlossen
    Log-Analyse und Auswertung - 03.05.2013 (7)
  12. tcbhn hat ein Problem festgestellt und muß beendet werden
    Log-Analyse und Auswertung - 28.04.2013 (4)
  13. Meldung: tcbhn wurde beendet und geschlossen
    Plagegeister aller Art und deren Bekämpfung - 23.04.2013 (21)
  14. tcbhn wurde beendet und geschlossen?
    Log-Analyse und Auswertung - 23.04.2013 (8)
  15. Meldung: tcbhn wurde beendet und geschlossen
    Plagegeister aller Art und deren Bekämpfung - 30.03.2013 (11)
  16. tbhcn wurde beendet und geschlossen
    Log-Analyse und Auswertung - 14.03.2013 (23)
  17. tcbhn wurde beendet und geschlossen?
    Plagegeister aller Art und deren Bekämpfung - 22.02.2013 (43)

Zum Thema tcbhn wurde beendet - Ich habe den PC damals beim Aldi gekauft und es war alles Installiert, ein Bekannter hat mir alles angeschlossen, deshalb weiss ich nicht ob es eine DVD gab. Ich habe - tcbhn wurde beendet...
Archiv
Du betrachtest: tcbhn wurde beendet auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.