|
Plagegeister aller Art und deren Bekämpfung: Unterstrichene Wörter mit Werbung - CouponWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
29.07.2013, 14:53 | #1 |
| Unterstrichene Wörter mit Werbung - Coupon Hallo, seit zwei Wochen habe ich das Problem mit den unterstrichenen Wörtern bei Firefox, bei denen Werbung erscheint. Auch rechts unten so eine Coupon Werbung. Auch so Microsoft certified popups erscheinen auf einigen Seiten, nicht bei allen. Hab eigentlich alles, was man im Board über das Therma findet schon ausprobiert(OTL,dds, adwcleaner,TFC usw.) aber das Problem ist immer noch da. Bitte helft mir: Was für einen Logfile bzw txt soll ich posten? Danke in voraus |
29.07.2013, 14:59 | #2 |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - Coupon hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
29.07.2013, 15:13 | #3 |
| Unterstrichene Wörter mit Werbung - Coupon FRST Logfile:
__________________Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-07-2013 Ran by utti (administrator) on 29-07-2013 16:05:10 Running from C:\Users\utti\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ACE GmbH) C:\Program Files\Videoload Manager\ContentManager.exe (Empolis GmbH) c:\program files\common files\gnab\service\servicecontroller.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Nalpeiron Ltd.) C:\Windows\system32\NLSSRV32.EXE (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Microsoft Corporation) C:\Program Files\Windows Mail\WinMail.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4390912 2007-02-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-02-15] (Synaptics, Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [151552 2006-11-15] (Intel Corporation) HKLM\...\Run: [UVS10 Preload] - C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-10] (Ulead Systems, Inc.) HKLM\...\Run: [toolbar_eula_launcher] - C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\madmax\...\Run: [BullGuard] - "C:\Program Files\BullGuard Software\BullGuard\BullGuard.exe" [x] ==================== Internet (Whitelisted) ==================== ProxyServer: 192.168.2.1:80 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - DefaultScope value is missing. BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL (Protect Software GmbH) BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll (Super Add-on Software) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: fluxhttp - {8E2D00A0-82C6-4821-90BC-07F290841BB6} - C:\Program Files\Common Files\fluxDVD\Lib\XEB\xebnavigation.ax () Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: haufereader - No CLSID Value - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 45 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default FF Homepage: hxxp://www.comdirect.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @fluxdvd.com/NPAPIX - C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll () FF Plugin: @fluxdvd.com/NPFluxBrowserHelper - C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks) FF Plugin: @protectdisc.com/NPMPDRM - C:\Program Files\Common Files\mpDRM\NPMPDRM.dll () FF Plugin: @protectdisc.com/NPWMDRMWrapper - C:\Program Files\Common Files\mpDRM\NPWMDRMWrapper.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @veetle.com/vbp;version=0.9.17 - C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.17 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.17 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\utti\AppData\Local\Citrix\Plugins\94\npappdetector.dll (Citrix Online) FF Extension: No Name - C:\Users\utti\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: DownloadHelper - C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{400F0BDB-6C49-43A4-BE1F-76D7327A604D}] C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla FF Extension: fluxDVD Download Manager - C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi FF Extension: No Name - C:\Program Files\Super_Lyrics\125.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG) R2 ContentMgrService; C:\Program Files\Videoload Manager\ContentManager.exe [508928 2008-03-12] (ACE GmbH) S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Sued Foto Service\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-13] (Empolis GmbH) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) S4 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.) S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc. ) S3 hitmanpro35; C:\Windows\system32\drivers\hitmanpro36.sys [25888 2012-03-28] () S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51088 2004-03-18] (HP) S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-03-18] (HP) S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-03-18] (HP) R3 Iviaspi; C:\Windows\System32\drivers\iviaspi.sys [16024 2006-11-22] (InterVideo, Inc.) S3 LTXMD_VAC; C:\Windows\System32\drivers\lmvac.sys [18912 2008-06-30] (Windows (R) Codename Longhorn DDK provider) R1 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2010-01-24] (microOLAP Technologies LTD) R1 PSSDKLBF; C:\Windows\system32\Drivers\pssdklbf.sys [53312 2010-01-24] (microOLAP Technologies LTD) R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [277504 2007-07-05] (Realtek Semiconductor Corporation ) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1729152 2007-02-07] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH) S3 w810bus; C:\Windows\System32\DRIVERS\w810bus.sys [58288 2006-02-20] (MCCI) S3 w810mdfl; C:\Windows\System32\DRIVERS\w810mdfl.sys [8336 2006-02-20] (MCCI) S3 w810mdm; C:\Windows\System32\DRIVERS\w810mdm.sys [94064 2006-02-20] (MCCI) S3 w810mgmt; C:\Windows\System32\DRIVERS\w810mgmt.sys [85408 2006-02-20] (MCCI) S3 w810obex; C:\Windows\System32\DRIVERS\w810obex.sys [83344 2006-02-20] (MCCI) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-29 16:04 - 2013-07-29 16:04 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST.exe 2013-07-29 16:04 - 2013-07-29 16:04 - 00000000 ____D C:\FRST 2013-07-29 14:57 - 2013-07-29 14:57 - 00000000 _____ C:\Users\utti\defogger_reenable 2013-07-29 12:14 - 2013-07-29 12:14 - 00000000 ____D C:\Program Files\ESET 2013-07-29 12:13 - 2013-07-29 12:14 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu.exe 2013-07-29 12:11 - 2013-07-29 12:11 - 00010290 _____ C:\Users\utti\Desktop\attach.txt 2013-07-29 12:01 - 2013-07-29 12:01 - 00700783 ____R (Swearware) C:\Users\utti\Downloads\dds+.exe 2013-07-29 11:56 - 2013-07-29 11:56 - 00000000 ____D C:\Users\utti\AppData\Roaming\Avira 2013-07-29 11:54 - 2013-07-29 11:55 - 00448512 _____ (OldTimer Tools) C:\Users\utti\Downloads\TFC.exe 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:49 - 2013-07-29 11:14 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:49 - 2013-07-29 11:14 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:49 - 2013-07-29 11:14 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:43 - 2013-07-29 11:43 - 00001223 _____ C:\AdwCleaner[S3].txt 2013-07-29 10:58 - 2013-07-29 15:29 - 00090648 _____ C:\Windows\PFRO.log 2013-07-27 12:36 - 2013-07-27 12:36 - 00001261 _____ C:\AdwCleaner[S2].txt 2013-07-27 12:22 - 2013-07-27 12:22 - 00001100 _____ C:\AdwCleaner[R2].txt 2013-07-27 12:17 - 2013-07-27 12:18 - 00001039 _____ C:\AdwCleaner[R1].txt 2013-07-27 12:17 - 2013-07-27 12:17 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner.exe 2013-07-27 12:11 - 2013-07-27 12:14 - 00036262 _____ C:\Users\utti\Downloads\Addition.txt 2013-07-24 23:10 - 2013-07-24 23:10 - 00000810 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-24 22:50 - 2013-07-24 22:50 - 00280368 _____ (Mozilla) C:\Users\utti\Downloads\Firefox Setup Stub 22.0.exe 2013-07-23 12:44 - 2013-07-27 12:14 - 00000000 ____D C:\Program Files\Super_Lyrics 2013-07-14 22:07 - 2013-07-14 22:12 - 00000000 ____D C:\Windows\system32\MRT 2013-07-14 15:36 - 2013-07-14 15:37 - 00005423 _____ C:\AdwCleaner[S1].txt 2013-07-14 15:25 - 2013-07-14 15:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-14 15:24 - 2013-07-14 15:24 - 00559441 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT.exe 2013-07-14 06:09 - 2013-07-14 06:09 - 00000393 _____ C:\zoek-results.log 2013-07-14 06:09 - 2013-07-14 06:09 - 00000000 ____D C:\Users\utti\Qtrax 2013-07-14 06:08 - 2013-07-14 06:08 - 01274079 _____ C:\Users\utti\Downloads\zoek.exe 2013-07-14 06:05 - 2013-07-29 15:34 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-14 06:05 - 2013-07-14 13:17 - 00000000 ____D C:\Users\utti\AppData\Roaming\Zip Opener Packages 2013-07-14 06:04 - 2013-07-14 06:04 - 00793536 _____ C:\Users\utti\Downloads\ZipOpenerSetup.exe 2013-07-14 05:30 - 2013-07-14 05:30 - 00591904 _____ C:\Users\utti\Downloads\VuuPC_Setup.exe 2013-07-13 09:18 - 2013-07-13 09:19 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-13 09:17 - 2013-07-13 09:17 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\utti\Downloads\SpyHunter-Installer.exe 2013-07-12 18:33 - 2013-07-15 10:28 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-12 18:30 - 2013-07-12 18:31 - 25326392 _____ (DVDVideoSoft Ltd. ) C:\Users\utti\Downloads\FreeYouTubeToMP3Converter.exe 2013-07-12 11:58 - 2013-07-12 11:59 - 00000000 ____D C:\Users\utti\AppData\Roaming\XnView 2013-07-12 11:57 - 2013-07-12 11:58 - 00000732 _____ C:\Users\utti\Desktop\XnView.lnk 2013-07-12 11:57 - 2013-07-12 11:57 - 00000000 ____D C:\Program Files\XnView 2013-07-12 11:53 - 2013-07-12 11:54 - 15188720 _____ (Gougelet Pierre-e ) C:\Users\utti\Downloads\XnView-win-full_2.03.exe 2013-07-12 11:45 - 2013-07-12 11:45 - 00000000 ____D C:\Users\utti\AppData\Roaming\WinZipper 2013-07-12 11:39 - 2013-07-12 11:39 - 00291760 _____ C:\Users\utti\Desktop\hafner kreis schwarz.eps 2013-07-12 11:33 - 2013-07-12 11:33 - 00000000 ____D C:\Users\utti\AppData\Local\emaze 2013-07-12 09:26 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 09:26 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-12 09:26 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 09:26 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-12 09:26 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 09:26 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 09:26 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-12 09:26 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 09:26 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-12 09:26 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-12 09:26 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-12 09:26 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 09:26 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 09:26 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 09:26 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-12 09:26 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 08:48 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-12 08:48 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-12 08:48 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-12 08:48 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-12 08:48 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-12 08:48 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-12 08:48 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-12 08:47 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 05:56 - 2013-07-10 05:59 - 534746810 _____ C:\Users\utti\Dokumente\Image.nrg 2013-07-09 17:08 - 2013-07-09 17:08 - 00002513 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00002003 _____ C:\Users\Public\Desktop\Nero Online-Upgrade.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00001919 _____ C:\Users\Public\Desktop\Nero - BurnSupportDisc.lnk 2013-07-05 14:41 - 2013-07-05 14:42 - 00000000 ____D C:\Users\utti\AppData\Roaming\Nero 2013-07-05 13:35 - 2013-07-05 13:37 - 101706760 _____ (Nero AG) C:\Users\utti\Downloads\Nero_BurningROM-12.5.01300_trial.exe ==================== One Month Modified Files and Folders ======= 2013-07-29 16:04 - 2013-07-29 16:04 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST.exe 2013-07-29 16:04 - 2013-07-29 16:04 - 00000000 ____D C:\FRST 2013-07-29 15:47 - 2012-07-09 21:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-29 15:38 - 2013-06-21 05:55 - 01049757 _____ C:\Windows\WindowsUpdate.log 2013-07-29 15:36 - 2007-09-06 13:49 - 00131424 _____ C:\Users\utti\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-29 15:34 - 2013-07-14 06:05 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-29 15:34 - 2011-09-27 07:57 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 15:30 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-29 15:30 - 2006-11-02 14:47 - 03790920 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-29 15:30 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-29 15:30 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-29 15:29 - 2013-07-29 10:58 - 00090648 _____ C:\Windows\PFRO.log 2013-07-29 15:28 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-29 15:21 - 2011-09-27 07:57 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 14:57 - 2013-07-29 14:57 - 00000000 _____ C:\Users\utti\defogger_reenable 2013-07-29 14:57 - 2007-09-06 13:49 - 00000000 ____D C:\Users\utti 2013-07-29 12:27 - 2007-11-20 19:32 - 00000000 ____D C:\Users\utti\Dokumente\SV Motzing 2013-07-29 12:14 - 2013-07-29 12:14 - 00000000 ____D C:\Program Files\ESET 2013-07-29 12:14 - 2013-07-29 12:13 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu.exe 2013-07-29 12:11 - 2013-07-29 12:11 - 00010290 _____ C:\Users\utti\Desktop\attach.txt 2013-07-29 12:01 - 2013-07-29 12:01 - 00700783 ____R (Swearware) C:\Users\utti\Downloads\dds+.exe 2013-07-29 11:56 - 2013-07-29 11:56 - 00000000 ____D C:\Users\utti\AppData\Roaming\Avira 2013-07-29 11:55 - 2013-07-29 11:54 - 00448512 _____ (OldTimer Tools) C:\Users\utti\Downloads\TFC.exe 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:43 - 2013-07-29 11:43 - 00001223 _____ C:\AdwCleaner[S3].txt 2013-07-29 11:30 - 2010-01-24 23:04 - 00000000 ____D C:\Users\utti\AppData\Roaming\vlc 2013-07-29 11:14 - 2013-07-29 11:49 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:14 - 2013-07-29 11:49 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:14 - 2013-07-29 11:49 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:14 - 2007-12-11 07:51 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-29 09:59 - 2012-12-31 12:07 - 00072850 _____ C:\Users\utti\Dokumente\Konto + Aktien 2011-2012.xlsx 2013-07-29 09:59 - 2012-01-03 18:57 - 00000000 ___RD C:\Users\utti\Dokumente 2013-07-28 14:03 - 2006-11-02 12:33 - 01481126 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-27 12:36 - 2013-07-27 12:36 - 00001261 _____ C:\AdwCleaner[S2].txt 2013-07-27 12:22 - 2013-07-27 12:22 - 00001100 _____ C:\AdwCleaner[R2].txt 2013-07-27 12:18 - 2013-07-27 12:17 - 00001039 _____ C:\AdwCleaner[R1].txt 2013-07-27 12:17 - 2013-07-27 12:17 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner.exe 2013-07-27 12:14 - 2013-07-27 12:11 - 00036262 _____ C:\Users\utti\Downloads\Addition.txt 2013-07-27 12:14 - 2013-07-23 12:44 - 00000000 ____D C:\Program Files\Super_Lyrics 2013-07-25 07:57 - 2010-01-25 07:57 - 00000000 ____D C:\Users\utti\dwhelper 2013-07-25 07:11 - 2011-09-13 14:38 - 00000000 ____D C:\Users\utti\Desktop\Neuer Ordner 2013-07-25 06:56 - 2011-09-27 07:56 - 00000000 ____D C:\Users\utti\AppData\Local\Deployment 2013-07-25 06:56 - 2011-09-27 07:56 - 00000000 ____D C:\Users\utti\AppData\Local\Apps\2.0 2013-07-25 06:20 - 2012-05-03 17:48 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-24 23:10 - 2013-07-24 23:10 - 00000810 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-24 23:10 - 2013-06-28 08:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-24 22:50 - 2013-07-24 22:50 - 00280368 _____ (Mozilla) C:\Users\utti\Downloads\Firefox Setup Stub 22.0.exe 2013-07-24 22:42 - 2007-11-12 18:59 - 00000000 ____D C:\Users\madmax 2013-07-24 22:42 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\Msdtc 2013-07-24 22:42 - 2006-11-02 12:22 - 61603840 _____ C:\Windows\system32\config\software_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 42205184 _____ C:\Windows\system32\config\components_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 31195136 _____ C:\Windows\system32\config\system_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\default_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00094208 _____ C:\Windows\system32\config\sam_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00024576 _____ C:\Windows\system32\config\security_previous 2013-07-24 22:41 - 2011-09-11 22:29 - 00000000 ____D C:\Program Files\Grips 2013-07-24 22:41 - 2009-07-13 11:50 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-07-24 22:41 - 2007-09-19 18:13 - 00000000 ____D C:\Program Files\Azureus 2013-07-24 22:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-07-24 22:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration 2013-07-22 16:15 - 2007-09-19 18:39 - 00098816 _____ C:\Users\utti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-22 13:45 - 2008-01-10 13:35 - 00000000 ____D C:\Users\utti\Dokumente\Donnervögel 2013-07-15 13:23 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-15 10:28 - 2013-07-12 18:33 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-15 10:28 - 2011-03-18 12:18 - 00000000 ____D C:\Users\utti\AppData\Roaming\DVDVideoSoft 2013-07-14 22:12 - 2013-07-14 22:07 - 00000000 ____D C:\Windows\system32\MRT 2013-07-14 22:06 - 2006-11-02 13:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-14 15:37 - 2013-07-14 15:36 - 00005423 _____ C:\AdwCleaner[S1].txt 2013-07-14 15:30 - 2008-05-25 21:56 - 00000913 _____ C:\Users\utti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-14 15:25 - 2013-07-14 15:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-14 15:24 - 2013-07-14 15:24 - 00559441 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT.exe 2013-07-14 13:17 - 2013-07-14 06:05 - 00000000 ____D C:\Users\utti\AppData\Roaming\Zip Opener Packages 2013-07-14 06:09 - 2013-07-14 06:09 - 00000393 _____ C:\zoek-results.log 2013-07-14 06:09 - 2013-07-14 06:09 - 00000000 ____D C:\Users\utti\Qtrax 2013-07-14 06:08 - 2013-07-14 06:08 - 01274079 _____ C:\Users\utti\Downloads\zoek.exe 2013-07-14 06:04 - 2013-07-14 06:04 - 00793536 _____ C:\Users\utti\Downloads\ZipOpenerSetup.exe 2013-07-14 05:30 - 2013-07-14 05:30 - 00591904 _____ C:\Users\utti\Downloads\VuuPC_Setup.exe 2013-07-13 09:19 - 2013-07-13 09:18 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-13 09:17 - 2013-07-13 09:17 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\utti\Downloads\SpyHunter-Installer.exe 2013-07-12 21:42 - 2007-09-06 13:50 - 00000000 ____D C:\Users\utti\AppData\Roaming\Ulead Systems 2013-07-12 21:30 - 2007-06-19 15:16 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-07-12 21:23 - 2007-06-20 13:20 - 00000000 ____D C:\Program Files\InterVideo 2013-07-12 21:22 - 2007-07-09 17:31 - 00000000 ____D C:\Program Files\Common Files\InterVideo 2013-07-12 21:21 - 2012-03-26 17:25 - 00000000 ____D C:\Users\utti\AppData\Roaming\TeamViewer 2013-07-12 21:21 - 2011-11-22 23:52 - 00000000 ____D C:\Users\utti\AppData\Roaming\TuneUp Software 2013-07-12 21:21 - 2010-07-01 15:17 - 00000000 ____D C:\Users\utti\AppData\Roaming\Uniblue 2013-07-12 21:21 - 2007-09-09 14:24 - 00000000 ____D C:\Users\utti\AppData\Roaming\Sun 2013-07-12 18:31 - 2013-07-12 18:30 - 25326392 _____ (DVDVideoSoft Ltd. ) C:\Users\utti\Downloads\FreeYouTubeToMP3Converter.exe 2013-07-12 16:12 - 2007-06-20 13:06 - 00000000 ____D C:\ProgramData\Nero 2013-07-12 16:11 - 2007-06-20 13:06 - 00000000 ____D C:\Program Files\Nero 2013-07-12 11:59 - 2013-07-12 11:58 - 00000000 ____D C:\Users\utti\AppData\Roaming\XnView 2013-07-12 11:58 - 2013-07-12 11:57 - 00000732 _____ C:\Users\utti\Desktop\XnView.lnk 2013-07-12 11:57 - 2013-07-12 11:57 - 00000000 ____D C:\Program Files\XnView 2013-07-12 11:54 - 2013-07-12 11:53 - 15188720 _____ (Gougelet Pierre-e ) C:\Users\utti\Downloads\XnView-win-full_2.03.exe 2013-07-12 11:45 - 2013-07-12 11:45 - 00000000 ____D C:\Users\utti\AppData\Roaming\WinZipper 2013-07-12 11:39 - 2013-07-12 11:39 - 00291760 _____ C:\Users\utti\Desktop\hafner kreis schwarz.eps 2013-07-12 11:33 - 2013-07-12 11:33 - 00000000 ____D C:\Users\utti\AppData\Local\emaze 2013-07-12 10:01 - 2011-03-12 12:34 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-12 09:59 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-12 09:37 - 2007-06-20 14:02 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-12 09:13 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 05:59 - 2013-07-10 05:56 - 534746810 _____ C:\Users\utti\Dokumente\Image.nrg 2013-07-09 17:08 - 2013-07-09 17:08 - 00002513 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00002003 _____ C:\Users\Public\Desktop\Nero Online-Upgrade.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00001919 _____ C:\Users\Public\Desktop\Nero - BurnSupportDisc.lnk 2013-07-09 17:06 - 2007-06-20 13:06 - 00000000 ____D C:\Program Files\Common Files\Ahead 2013-07-08 13:14 - 2008-12-31 09:51 - 00042023 _____ C:\Users\utti\Dokumente\Abrechnung 2009-2012.xlsx 2013-07-05 14:42 - 2013-07-05 14:41 - 00000000 ____D C:\Users\utti\AppData\Roaming\Nero 2013-07-05 13:37 - 2013-07-05 13:35 - 101706760 _____ (Nero AG) C:\Users\utti\Downloads\Nero_BurningROM-12.5.01300_trial.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-29 15:39 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-07-2013 Ran by utti at 2013-07-29 16:07:40 Running from C:\Users\utti\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) AAVUpdateManager (Version: 4.00.0000) Activation Assistant for the 2007 Microsoft Office suites Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0) Adobe AIR (Version: 1.5.3.9130) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.7.700.224) Adobe Media Player (Version: 1.8) Adobe Reader X (10.1.7) - Deutsch (Version: 10.1.7) Adobe Shockwave Player 11.5 (Version: 11.5) Any Video Converter 3.0.6 Apple Application Support (Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Audacity 1.3.12 (Unicode) Audiograbber 1.83 SE (Version: 1.83 SE) Audiograbber MP3-Plugin (Version: 1.0) Avira Free Antivirus (Version: 13.0.0.3884) CDBurnerXP (Version: 4.5.1.4003) Disc2Phone (Version: 1.3.0.106) DivX-Setup (Version: 2.0.0.86) Dropbox (HKCU Version: 1.4.12) ElsterFormular-Upgrade (Version: 13.3.0.9066) Erotic-Lounge Manager 1.0.1517 (Version: 1.0.1517) ESET Online Scanner v3 Firebird SQL Server - MAGIX Edition 2.0.0.1 (D) (Version: 2.0.0.1) Foxit Reader (Version: 6.0.2.413) Free M4a to MP3 Converter 7.2 Google Earth (Version: 4.2.205.5730) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.5.4209.2358) Google Update Helper (Version: 1.3.21.153) GoToMeeting 5.7.0.1172 (HKCU Version: 5.7.0.1172) GPL Ghostscript 8.64 Intel(R) Graphics Media Accelerator Driver Intel(R) Matrix Storage Manager InterVideo WinDVD 8 (Version: 8.0-B6.195) iTunes (Version: 11.0.1.12) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Kastor Free Vimeo Downloader V 1.1 (Version: 1.1.0.0) LAME v3.98.2 for Audacity Lexware Info Service (Version: 2.70.00.0081) LightScribe 1.4.124.1 (Version: 1.4.124.1) Macromedia Dreamweaver 8 (Version: 8.0.0.2751) Macromedia Extension Manager (Version: 1.7.270) MainConcept MPEG-2 Decoder Pack (Version: 3.1.60203) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) MEDION Fotos auf CD Sued 6.0.2.0 (D) (Version: 6.0.2.0) MEDIONbox (Version: 1.09.0000.00050) Microsoft .NET Framework 1.1 (Version: 1.1.4322) Microsoft .NET Framework 1.1 Security Update (KB2698023) Microsoft .NET Framework 1.1 Security Update (KB2833941) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40303) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.40308) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU (Version: 10.0.40303) Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU (Version: 10.0.40303) Microsoft Works (Version: 08.05.0822) Microsoft XML Parser (Version: 8.0.7820.0) Microsoft XML Parser (Version: 8.20.8730.4) Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053) Microsoft_VC90_ATL_x86 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (Version: 1.00.0000) Move Networks Media Player for Internet Explorer Mozilla Firefox 22.0 (x86 de) (Version: 22.0) Mozilla Maintenance Service (Version: 22.0) MSXML 4.0 SP2 (KB925672) (Version: 4.20.9839.0) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MyPhoneExplorer (Version: 1.8.0) Nero 7 Essentials (Version: 7.02.5182) neroxml (Version: 1.0.0) NVIDIA Drivers QuickTime (Version: 7.73.80.64) Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (Version: 1.00.0000) Realtek High Definition Audio Driver (Version: 6.0.1.5374) REALTEK RTL8187B Wireless LAN Driver (Version: Package:1.00.0006 Driver:6.1095.705.2007) Skype™ 5.10 (Version: 5.10.116) SopCast 3.2.4 (Version: 3.2.4) Steuer 2010 (Version: 17.04.00.0019) Steuer 2011 (HKCU Version: 19.00.7304) Steuer 2012 (Version: 20.00.8137) Steuer-Hilfesammlung 2010 (Version: 17.10.0.0) Steuer-Spar-Erklärung 2009 (Version: 14.04.0000) Super Lyrics Suyin Live Camera (Version: 1.0.0.3) SUYIN webcam (Version: 1.0.1) Synaptics Pointing Device Driver (Version: 9.1.17.0) System Requirements Lab Ulead PhotoImpact 12 (Version: 12.0) Ulead VideoStudio SE DVD (Version: 10.0) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB2836940) (Version: 1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0) Veetle TV 0.9.17 (Version: 0.9.17) Videoload Manager 1.0.1514 (Version: 1.0.1514) VLC media player 1.0.3 (Version: 1.0.3) WebEx Windows Live Messenger (Version: 8.1.0178.00) Windows Media Encoder 9-Reihe Windows Media Encoder 9-Reihe (Version: 9.00.3374) Windows Media Player Firefox Plugin (Version: 1.0.0.8) WinZip (Version: 9.0 SR-1 (6224g)) XnView 2.03 (Version: 2.03) Zero-Buchhaltung ==================== Restore Points ========================= 12-07-2013 19:44:55 Removed QuickShare 13-07-2013 07:19:20 Installed SpyHunter 14-07-2013 11:23:58 Removed SpyHunter 14-07-2013 20:02:16 Windows Update 19-07-2013 12:58:45 Windows Update 23-07-2013 12:50:26 Geplanter Prüfpunkt 24-07-2013 07:13:37 Windows Update 24-07-2013 20:18:41 Removed AAVUpdateManager. 24-07-2013 20:20:47 Removed Steuer-Spar-Erklärung 2009. 24-07-2013 20:37:36 Wiederherstellungsvorgang 24-07-2013 20:55:21 Windows Update 28-07-2013 10:09:48 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 12:23 - 2012-03-27 17:17 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {047A5175-8EAD-4799-B96E-CF4F8A1846DD} - System32\Tasks\QtraxPlayer => C:\Program Files\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation) Task: {1C94954B-77ED-46C2-9F7D-126D0632B680} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - utti => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {257B0A14-4083-44E3-9533-D915C5B4AD4B} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation) Task: {2B858FBF-480E-4522-9E31-BD4AE063C011} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-977526049-4203851204-4170899763-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File Task: {371FB066-3EB0-4B56-975A-898F494A0EBC} - System32\Tasks\WPD\SqmUpload_S-1-5-21-977526049-4203851204-4170899763-1003 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {407CDE63-4211-437A-ADF3-DEFBF77DB5FB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {4305F06F-C663-47D4-9C1D-0EC494EA6D48} - System32\Tasks\Desk 365 RunAsStdUser => C:\Program Files\Desk 365\desk365.exe No File Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {471BA82A-6E01-48DD-85B8-722E994027A4} - System32\Tasks\{4A400E2B-79CE-491D-A834-987D09887DF1} => C:\Program Files\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.) Task: {50FB346A-FED6-45A9-9654-DDB4E57DDBB8} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {58145B5E-EFA2-45A8-9C24-D2B47E7581AA} - System32\Tasks\DSite => C:\Users\utti\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File Task: {5CB71C94-2BDE-45C6-AD0F-F778B128D52D} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-977526049-4203851204-4170899763-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File Task: {849D5560-0BC8-4C1E-BB90-7789A1B55940} - System32\Tasks\Microsoft\Windows\RestartManager\{16DB2EE3-7481-4bba-B747-BD68D5B22591} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {955C1DC6-5F8D-4192-99F9-B31D7353D756} - System32\Tasks\WPD\SqmUpload_S-1-5-21-977526049-4203851204-4170899763-1004 => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {A6B977AE-C906-4C64-BF1A-E3816DB2FC7E} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2006-11-02] (Microsoft Corporation) Task: {A6F344A9-A0B8-42DA-B4E7-58B708788665} - System32\Tasks\User_Feed_Synchronization-{4CF7B303-B8D7-4DAA-8373-9422F530950E} => C:\Windows\system32\msfeedssync.exe [2011-09-27] (Microsoft Corporation) Task: {AB8D1056-ABB7-46CA-AABA-B3F796340049} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-27] (Google Inc.) Task: {B3C00DD4-9488-4E3B-BDFD-F4A7C162506B} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation) Task: {BF327353-AAF3-4054-9244-92DD21D7A4D0} - System32\Tasks\Microsoft\Windows\RestartManager\{AFF05275-240A-4ddc-BB12-F0A5C1497708} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation) Task: {CBB00841-2CD3-421A-B4FB-3F69D09B92DE} - System32\Tasks\Super Lyrics Update => C:\Program Files\Super_Lyrics\SuperLupdater.exe No File Task: {D0FEF5DE-759D-45F2-80E7-BD330EDCD0FB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-27] (Google Inc.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: {F0E54844-CED4-42C3-AC9F-618A458E84DA} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-19] (Microsoft Corp.) Task: {F4FCE614-1D52-49F5-BF7B-5A46BB149B15} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation) Task: {F5EA3952-D5E1-4F55-8336-4E2C2C3F0CED} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {F6C66A96-FADC-4990-9530-59B8B064E016} - System32\Tasks\Microsoft\Windows\WindowsBackup\CheckFull => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Super Lyrics Update.job => C:\Program Files\Super_Lyrics\SuperLupdater.exe ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver ==================== Event log errors: ========================= Application errors: ================== Error: (07/29/2013 03:59:05 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\UTTI\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\38RJUA60.DEFAULT\SAFEBROWSING-TO_DELETE> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (07/29/2013 03:59:05 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\UTTI\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\38RJUA60.DEFAULT\SAFEBROWSING-BACKUP> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (07/29/2013 03:31:25 PM) (Source: Service Control Manager) (User: ) Description: Wsys Service%%3 Error: (07/29/2013 02:39:36 PM) (Source: Service Control Manager) (User: ) Description: Wsys Service%%3 Error: (07/29/2013 02:38:11 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 29.07.2013 um 13:41:13 unerwartet heruntergefahren. Error: (07/29/2013 11:59:50 AM) (Source: Service Control Manager) (User: ) Description: Wsys Service%%3 Error: (07/29/2013 11:55:47 AM) (Source: Service Control Manager) (User: ) Description: Adobe Acrobat Update Service1 Error: (07/29/2013 11:45:56 AM) (Source: Service Control Manager) (User: ) Description: Wsys Service%%3 Error: (07/29/2013 10:59:56 AM) (Source: Service Control Manager) (User: ) Description: Wsys Service%%3 Error: (07/29/2013 10:56:53 AM) (Source: DCOM) (User: ) Description: {C2BFE331-6739-4270-86C9-493D9A04CD38} Error: (07/29/2013 09:50:36 AM) (Source: Microsoft-Windows-Servicing) (User: NT-AUTORITÄT) Description: Windows-Wartung konnte das Paket KB2492386 (Update) nicht in den Status Nicht vorhanden(Absent) setzen. Error: (07/29/2013 09:50:36 AM) (Source: Microsoft-Windows-Servicing) (User: NT-AUTORITÄT) Description: Windows-Wartung konnte das Paket KB2492386 (Update) nicht in den Status Nicht vorhanden(Absent) setzen. Microsoft Office Sessions: ========================= Error: (06/17/2013 00:58:29 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2047 seconds with 300 seconds of active time. This session ended with a crash. Error: (12/31/2012 00:16:58 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 1315 seconds with 540 seconds of active time. This session ended with a crash. Error: (02/15/2011 00:31:12 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10466 seconds with 1500 seconds of active time. This session ended with a crash. Error: (12/24/2010 05:55:01 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 280 seconds with 240 seconds of active time. This session ended with a crash. Error: (08/23/2009 10:33:24 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash. Error: (08/22/2009 11:31:08 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5 seconds with 0 seconds of active time. This session ended with a crash. Error: (08/22/2009 11:29:59 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 16 seconds with 0 seconds of active time. This session ended with a crash. Error: (08/18/2009 00:09:27 PM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0 seconds with 0 seconds of active time. This session ended with a crash. Error: (08/18/2009 06:46:46 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10 seconds with 0 seconds of active time. This session ended with a crash. Error: (08/18/2009 06:46:04 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2013-06-04 08:44:07.087 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-04 08:44:05.745 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-02 16:23:05.775 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-02 16:23:05.019 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-02 16:07:32.236 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-02 16:07:31.467 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-23 06:44:30.029 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-23 06:44:29.071 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-09 10:28:34.008 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-09 10:28:32.717 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\igdumd32.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 81% Total physical RAM: 2037.45 MB Available physical RAM: 375.77 MB Total Pagefile: 4316.18 MB Available Pagefile: 2523.37 MB Total Virtual: 2047.88 MB Available Virtual: 1898.75 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:119 GB) (Free:12.4 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:30.04 GB) (Free:20.56 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: 74BEA0E1) Partition 1: (Not Active) - (Size=30 GB) - (Type=OF Extended) Partition 2: (Active) - (Size=119 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
29.07.2013, 15:42 | #4 |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - Coupon Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.07.2013, 16:15 | #5 |
| Unterstrichene Wörter mit Werbung - Coupon AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 29/07/2013 um 16:57:50 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # Benutzer : utti - UTTI-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\utti\Downloads\adwcleaner(1).exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16496 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default\prefs.js [OK] Die Datei ist sauber. Datei : C:\Users\madmax\AppData\Roaming\Mozilla\Firefox\Profiles\zhip3zj4.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1039 octets] - [27/07/2013 12:17:49] AdwCleaner[R2].txt - [1100 octets] - [27/07/2013 12:22:06] AdwCleaner[S1].txt - [5423 octets] - [14/07/2013 15:36:34] AdwCleaner[S2].txt - [1261 octets] - [27/07/2013 12:36:03] AdwCleaner[S3].txt - [1223 octets] - [29/07/2013 11:43:25] AdwCleaner[S4].txt - [1157 octets] - [29/07/2013 16:57:50] ########## EOF - C:\AdwCleaner[S4].txt - [1217 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.2.7 (07.29.2013:1) OS: Windows Vista (TM) Home Premium x86 Ran by utti on 29.07.2013 at 17:08:07,35 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] C:\Windows\tasks\Super Lyrics Update.job ~~~ Folders Successfully deleted: [Folder] "C:\Program Files\super_lyrics" ~~~ FireFox Emptied folder: C:\Users\utti\AppData\Roaming\mozilla\firefox\profiles\38rjua60.default\minidumps [2 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.07.2013 at 17:11:04,37 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-07-2013 Ran by utti (administrator) on 29-07-2013 17:12:18 Running from C:\Users\utti\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ACE GmbH) C:\Program Files\Videoload Manager\ContentManager.exe (Empolis GmbH) c:\program files\common files\gnab\service\servicecontroller.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe (Nalpeiron Ltd.) C:\Windows\system32\NLSSRV32.EXE (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Avira Operations GmbH & Co. KG) C:\program files\avira\antivir desktop\avcenter.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Farbar) C:\Users\utti\Downloads\FRST(1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4390912 2007-02-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-02-15] (Synaptics, Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [151552 2006-11-15] (Intel Corporation) HKLM\...\Run: [UVS10 Preload] - C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-10] (Ulead Systems, Inc.) HKLM\...\Run: [toolbar_eula_launcher] - C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\madmax\...\Run: [BullGuard] - "C:\Program Files\BullGuard Software\BullGuard\BullGuard.exe" [x] ==================== Internet (Whitelisted) ==================== ProxyServer: 192.168.2.1:80 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - DefaultScope value is missing. BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL (Protect Software GmbH) BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: fluxhttp - {8E2D00A0-82C6-4821-90BC-07F290841BB6} - C:\Program Files\Common Files\fluxDVD\Lib\XEB\xebnavigation.ax () Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: haufereader - No CLSID Value - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 45 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default FF Homepage: hxxp://www.comdirect.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @fluxdvd.com/NPAPIX - C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll () FF Plugin: @fluxdvd.com/NPFluxBrowserHelper - C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks) FF Plugin: @protectdisc.com/NPMPDRM - C:\Program Files\Common Files\mpDRM\NPMPDRM.dll () FF Plugin: @protectdisc.com/NPWMDRMWrapper - C:\Program Files\Common Files\mpDRM\NPWMDRMWrapper.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @veetle.com/vbp;version=0.9.17 - C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.17 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.17 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\utti\AppData\Local\Citrix\Plugins\94\npappdetector.dll (Citrix Online) FF Extension: No Name - C:\Users\utti\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: DownloadHelper - C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{400F0BDB-6C49-43A4-BE1F-76D7327A604D}] C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla FF Extension: fluxDVD Download Manager - C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG) R2 ContentMgrService; C:\Program Files\Videoload Manager\ContentManager.exe [508928 2008-03-12] (ACE GmbH) S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Sued Foto Service\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-13] (Empolis GmbH) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) S4 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.) S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc. ) S3 hitmanpro35; C:\Windows\system32\drivers\hitmanpro36.sys [25888 2012-03-28] () S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51088 2004-03-18] (HP) S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-03-18] (HP) S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-03-18] (HP) R3 Iviaspi; C:\Windows\System32\drivers\iviaspi.sys [16024 2006-11-22] (InterVideo, Inc.) S3 LTXMD_VAC; C:\Windows\System32\drivers\lmvac.sys [18912 2008-06-30] (Windows (R) Codename Longhorn DDK provider) R1 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2010-01-24] (microOLAP Technologies LTD) R1 PSSDKLBF; C:\Windows\system32\Drivers\pssdklbf.sys [53312 2010-01-24] (microOLAP Technologies LTD) R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [277504 2007-07-05] (Realtek Semiconductor Corporation ) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1729152 2007-02-07] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH) S3 w810bus; C:\Windows\System32\DRIVERS\w810bus.sys [58288 2006-02-20] (MCCI) S3 w810mdfl; C:\Windows\System32\DRIVERS\w810mdfl.sys [8336 2006-02-20] (MCCI) S3 w810mdm; C:\Windows\System32\DRIVERS\w810mdm.sys [94064 2006-02-20] (MCCI) S3 w810mgmt; C:\Windows\System32\DRIVERS\w810mgmt.sys [85408 2006-02-20] (MCCI) S3 w810obex; C:\Windows\System32\DRIVERS\w810obex.sys [83344 2006-02-20] (MCCI) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-29 17:12 - 2013-07-29 17:12 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST(1).exe 2013-07-29 17:11 - 2013-07-29 17:11 - 00000902 _____ C:\Users\utti\Desktop\JRT.txt 2013-07-29 17:07 - 2013-07-29 17:07 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT(1).exe 2013-07-29 17:04 - 2013-07-29 17:04 - 00001286 _____ C:\Users\utti\Desktop\AdwCleaner[S4].txt 2013-07-29 16:57 - 2013-07-29 16:58 - 00001286 _____ C:\AdwCleaner[S4].txt 2013-07-29 16:56 - 2013-07-29 16:56 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner(1).exe 2013-07-29 16:04 - 2013-07-29 16:04 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST.exe 2013-07-29 16:04 - 2013-07-29 16:04 - 00000000 ____D C:\FRST 2013-07-29 14:57 - 2013-07-29 14:57 - 00000000 _____ C:\Users\utti\defogger_reenable 2013-07-29 12:14 - 2013-07-29 12:14 - 00000000 ____D C:\Program Files\ESET 2013-07-29 12:13 - 2013-07-29 12:14 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu.exe 2013-07-29 12:01 - 2013-07-29 12:01 - 00700783 ____R (Swearware) C:\Users\utti\Downloads\dds+.exe 2013-07-29 11:56 - 2013-07-29 11:56 - 00000000 ____D C:\Users\utti\AppData\Roaming\Avira 2013-07-29 11:54 - 2013-07-29 11:55 - 00448512 _____ (OldTimer Tools) C:\Users\utti\Downloads\TFC.exe 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:49 - 2013-07-29 11:14 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:49 - 2013-07-29 11:14 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:49 - 2013-07-29 11:14 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:43 - 2013-07-29 11:43 - 00001223 _____ C:\AdwCleaner[S3].txt 2013-07-29 10:58 - 2013-07-29 15:29 - 00090648 _____ C:\Windows\PFRO.log 2013-07-27 12:36 - 2013-07-27 12:36 - 00001261 _____ C:\AdwCleaner[S2].txt 2013-07-27 12:22 - 2013-07-27 12:22 - 00001100 _____ C:\AdwCleaner[R2].txt 2013-07-27 12:17 - 2013-07-27 12:18 - 00001039 _____ C:\AdwCleaner[R1].txt 2013-07-27 12:17 - 2013-07-27 12:17 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner.exe 2013-07-27 12:11 - 2013-07-29 16:10 - 00024951 _____ C:\Users\utti\Downloads\Addition.txt 2013-07-24 23:10 - 2013-07-24 23:10 - 00000810 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-24 22:50 - 2013-07-24 22:50 - 00280368 _____ (Mozilla) C:\Users\utti\Downloads\Firefox Setup Stub 22.0.exe 2013-07-14 22:07 - 2013-07-14 22:12 - 00000000 ____D C:\Windows\system32\MRT 2013-07-14 15:36 - 2013-07-14 15:37 - 00005423 _____ C:\AdwCleaner[S1].txt 2013-07-14 15:25 - 2013-07-14 15:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-14 15:24 - 2013-07-14 15:24 - 00559441 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT.exe 2013-07-14 06:09 - 2013-07-14 06:09 - 00000393 _____ C:\zoek-results.log 2013-07-14 06:09 - 2013-07-14 06:09 - 00000000 ____D C:\Users\utti\Qtrax 2013-07-14 06:08 - 2013-07-14 06:08 - 01274079 _____ C:\Users\utti\Downloads\zoek.exe 2013-07-14 06:05 - 2013-07-29 17:01 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-14 06:05 - 2013-07-14 13:17 - 00000000 ____D C:\Users\utti\AppData\Roaming\Zip Opener Packages 2013-07-14 06:04 - 2013-07-14 06:04 - 00793536 _____ C:\Users\utti\Downloads\ZipOpenerSetup.exe 2013-07-14 05:30 - 2013-07-14 05:30 - 00591904 _____ C:\Users\utti\Downloads\VuuPC_Setup.exe 2013-07-13 09:18 - 2013-07-13 09:19 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-13 09:17 - 2013-07-13 09:17 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\utti\Downloads\SpyHunter-Installer.exe 2013-07-12 18:33 - 2013-07-15 10:28 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-12 18:30 - 2013-07-12 18:31 - 25326392 _____ (DVDVideoSoft Ltd. ) C:\Users\utti\Downloads\FreeYouTubeToMP3Converter.exe 2013-07-12 11:58 - 2013-07-12 11:59 - 00000000 ____D C:\Users\utti\AppData\Roaming\XnView 2013-07-12 11:57 - 2013-07-12 11:58 - 00000732 _____ C:\Users\utti\Desktop\XnView.lnk 2013-07-12 11:57 - 2013-07-12 11:57 - 00000000 ____D C:\Program Files\XnView 2013-07-12 11:53 - 2013-07-12 11:54 - 15188720 _____ (Gougelet Pierre-e ) C:\Users\utti\Downloads\XnView-win-full_2.03.exe 2013-07-12 11:45 - 2013-07-12 11:45 - 00000000 ____D C:\Users\utti\AppData\Roaming\WinZipper 2013-07-12 11:39 - 2013-07-12 11:39 - 00291760 _____ C:\Users\utti\Desktop\hafner kreis schwarz.eps 2013-07-12 11:33 - 2013-07-12 11:33 - 00000000 ____D C:\Users\utti\AppData\Local\emaze 2013-07-12 09:26 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 09:26 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-12 09:26 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 09:26 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-12 09:26 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 09:26 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 09:26 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-12 09:26 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 09:26 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-12 09:26 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-12 09:26 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-12 09:26 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 09:26 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 09:26 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 09:26 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-12 09:26 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 08:48 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-12 08:48 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-12 08:48 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-12 08:48 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-12 08:48 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-12 08:48 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-12 08:48 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-12 08:47 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 05:56 - 2013-07-10 05:59 - 534746810 _____ C:\Users\utti\Dokumente\Image.nrg 2013-07-09 17:08 - 2013-07-09 17:08 - 00002513 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00002003 _____ C:\Users\Public\Desktop\Nero Online-Upgrade.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00001919 _____ C:\Users\Public\Desktop\Nero - BurnSupportDisc.lnk 2013-07-05 14:41 - 2013-07-05 14:42 - 00000000 ____D C:\Users\utti\AppData\Roaming\Nero 2013-07-05 13:35 - 2013-07-05 13:37 - 101706760 _____ (Nero AG) C:\Users\utti\Downloads\Nero_BurningROM-12.5.01300_trial.exe ==================== One Month Modified Files and Folders ======= 2013-07-29 17:12 - 2013-07-29 17:12 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST(1).exe 2013-07-29 17:11 - 2013-07-29 17:11 - 00000902 _____ C:\Users\utti\Desktop\JRT.txt 2013-07-29 17:07 - 2013-07-29 17:07 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT(1).exe 2013-07-29 17:04 - 2013-07-29 17:04 - 00001286 _____ C:\Users\utti\Desktop\AdwCleaner[S4].txt 2013-07-29 17:01 - 2013-07-14 06:05 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-29 17:01 - 2011-09-27 07:57 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 17:00 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-29 17:00 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-29 17:00 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-29 16:59 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-29 16:58 - 2013-07-29 16:57 - 00001286 _____ C:\AdwCleaner[S4].txt 2013-07-29 16:58 - 2013-06-21 05:55 - 01053180 _____ C:\Windows\WindowsUpdate.log 2013-07-29 16:56 - 2013-07-29 16:56 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner(1).exe 2013-07-29 16:47 - 2012-07-09 21:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-29 16:21 - 2011-09-27 07:57 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 16:10 - 2013-07-27 12:11 - 00024951 _____ C:\Users\utti\Downloads\Addition.txt 2013-07-29 16:04 - 2013-07-29 16:04 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST.exe 2013-07-29 16:04 - 2013-07-29 16:04 - 00000000 ____D C:\FRST 2013-07-29 15:36 - 2007-09-06 13:49 - 00131424 _____ C:\Users\utti\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-29 15:30 - 2006-11-02 14:47 - 03790920 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-29 15:29 - 2013-07-29 10:58 - 00090648 _____ C:\Windows\PFRO.log 2013-07-29 14:57 - 2013-07-29 14:57 - 00000000 _____ C:\Users\utti\defogger_reenable 2013-07-29 14:57 - 2007-09-06 13:49 - 00000000 ____D C:\Users\utti 2013-07-29 12:27 - 2007-11-20 19:32 - 00000000 ____D C:\Users\utti\Dokumente\SV Motzing 2013-07-29 12:14 - 2013-07-29 12:14 - 00000000 ____D C:\Program Files\ESET 2013-07-29 12:14 - 2013-07-29 12:13 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu.exe 2013-07-29 12:01 - 2013-07-29 12:01 - 00700783 ____R (Swearware) C:\Users\utti\Downloads\dds+.exe 2013-07-29 11:56 - 2013-07-29 11:56 - 00000000 ____D C:\Users\utti\AppData\Roaming\Avira 2013-07-29 11:55 - 2013-07-29 11:54 - 00448512 _____ (OldTimer Tools) C:\Users\utti\Downloads\TFC.exe 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:43 - 2013-07-29 11:43 - 00001223 _____ C:\AdwCleaner[S3].txt 2013-07-29 11:30 - 2010-01-24 23:04 - 00000000 ____D C:\Users\utti\AppData\Roaming\vlc 2013-07-29 11:14 - 2013-07-29 11:49 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:14 - 2013-07-29 11:49 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:14 - 2013-07-29 11:49 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:14 - 2007-12-11 07:51 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-29 09:59 - 2012-12-31 12:07 - 00072850 _____ C:\Users\utti\Dokumente\Konto + Aktien 2011-2012.xlsx 2013-07-29 09:59 - 2012-01-03 18:57 - 00000000 ___RD C:\Users\utti\Dokumente 2013-07-28 14:03 - 2006-11-02 12:33 - 01481126 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-27 12:36 - 2013-07-27 12:36 - 00001261 _____ C:\AdwCleaner[S2].txt 2013-07-27 12:22 - 2013-07-27 12:22 - 00001100 _____ C:\AdwCleaner[R2].txt 2013-07-27 12:18 - 2013-07-27 12:17 - 00001039 _____ C:\AdwCleaner[R1].txt 2013-07-27 12:17 - 2013-07-27 12:17 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner.exe 2013-07-25 07:57 - 2010-01-25 07:57 - 00000000 ____D C:\Users\utti\dwhelper 2013-07-25 07:11 - 2011-09-13 14:38 - 00000000 ____D C:\Users\utti\Desktop\Neuer Ordner 2013-07-25 06:56 - 2011-09-27 07:56 - 00000000 ____D C:\Users\utti\AppData\Local\Deployment 2013-07-25 06:56 - 2011-09-27 07:56 - 00000000 ____D C:\Users\utti\AppData\Local\Apps\2.0 2013-07-25 06:20 - 2012-05-03 17:48 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-24 23:10 - 2013-07-24 23:10 - 00000810 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-24 23:10 - 2013-06-28 08:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-24 22:50 - 2013-07-24 22:50 - 00280368 _____ (Mozilla) C:\Users\utti\Downloads\Firefox Setup Stub 22.0.exe 2013-07-24 22:42 - 2007-11-12 18:59 - 00000000 ____D C:\Users\madmax 2013-07-24 22:42 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\Msdtc 2013-07-24 22:42 - 2006-11-02 12:22 - 61603840 _____ C:\Windows\system32\config\software_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 42205184 _____ C:\Windows\system32\config\components_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 31195136 _____ C:\Windows\system32\config\system_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\default_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00094208 _____ C:\Windows\system32\config\sam_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00024576 _____ C:\Windows\system32\config\security_previous 2013-07-24 22:41 - 2011-09-11 22:29 - 00000000 ____D C:\Program Files\Grips 2013-07-24 22:41 - 2009-07-13 11:50 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-07-24 22:41 - 2007-09-19 18:13 - 00000000 ____D C:\Program Files\Azureus 2013-07-24 22:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-07-24 22:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration 2013-07-22 16:15 - 2007-09-19 18:39 - 00098816 _____ C:\Users\utti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-22 13:45 - 2008-01-10 13:35 - 00000000 ____D C:\Users\utti\Dokumente\Donnervögel 2013-07-15 13:23 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-15 10:28 - 2013-07-12 18:33 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-15 10:28 - 2011-03-18 12:18 - 00000000 ____D C:\Users\utti\AppData\Roaming\DVDVideoSoft 2013-07-14 22:12 - 2013-07-14 22:07 - 00000000 ____D C:\Windows\system32\MRT 2013-07-14 22:06 - 2006-11-02 13:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-14 15:37 - 2013-07-14 15:36 - 00005423 _____ C:\AdwCleaner[S1].txt 2013-07-14 15:30 - 2008-05-25 21:56 - 00000913 _____ C:\Users\utti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-14 15:25 - 2013-07-14 15:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-14 15:24 - 2013-07-14 15:24 - 00559441 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT.exe 2013-07-14 13:17 - 2013-07-14 06:05 - 00000000 ____D C:\Users\utti\AppData\Roaming\Zip Opener Packages 2013-07-14 06:09 - 2013-07-14 06:09 - 00000393 _____ C:\zoek-results.log 2013-07-14 06:09 - 2013-07-14 06:09 - 00000000 ____D C:\Users\utti\Qtrax 2013-07-14 06:08 - 2013-07-14 06:08 - 01274079 _____ C:\Users\utti\Downloads\zoek.exe 2013-07-14 06:04 - 2013-07-14 06:04 - 00793536 _____ C:\Users\utti\Downloads\ZipOpenerSetup.exe 2013-07-14 05:30 - 2013-07-14 05:30 - 00591904 _____ C:\Users\utti\Downloads\VuuPC_Setup.exe 2013-07-13 09:19 - 2013-07-13 09:18 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-13 09:17 - 2013-07-13 09:17 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\utti\Downloads\SpyHunter-Installer.exe 2013-07-12 21:42 - 2007-09-06 13:50 - 00000000 ____D C:\Users\utti\AppData\Roaming\Ulead Systems 2013-07-12 21:30 - 2007-06-19 15:16 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-07-12 21:23 - 2007-06-20 13:20 - 00000000 ____D C:\Program Files\InterVideo 2013-07-12 21:22 - 2007-07-09 17:31 - 00000000 ____D C:\Program Files\Common Files\InterVideo 2013-07-12 21:21 - 2012-03-26 17:25 - 00000000 ____D C:\Users\utti\AppData\Roaming\TeamViewer 2013-07-12 21:21 - 2011-11-22 23:52 - 00000000 ____D C:\Users\utti\AppData\Roaming\TuneUp Software 2013-07-12 21:21 - 2010-07-01 15:17 - 00000000 ____D C:\Users\utti\AppData\Roaming\Uniblue 2013-07-12 21:21 - 2007-09-09 14:24 - 00000000 ____D C:\Users\utti\AppData\Roaming\Sun 2013-07-12 18:31 - 2013-07-12 18:30 - 25326392 _____ (DVDVideoSoft Ltd. ) C:\Users\utti\Downloads\FreeYouTubeToMP3Converter.exe 2013-07-12 16:12 - 2007-06-20 13:06 - 00000000 ____D C:\ProgramData\Nero 2013-07-12 16:11 - 2007-06-20 13:06 - 00000000 ____D C:\Program Files\Nero 2013-07-12 11:59 - 2013-07-12 11:58 - 00000000 ____D C:\Users\utti\AppData\Roaming\XnView 2013-07-12 11:58 - 2013-07-12 11:57 - 00000732 _____ C:\Users\utti\Desktop\XnView.lnk 2013-07-12 11:57 - 2013-07-12 11:57 - 00000000 ____D C:\Program Files\XnView 2013-07-12 11:54 - 2013-07-12 11:53 - 15188720 _____ (Gougelet Pierre-e ) C:\Users\utti\Downloads\XnView-win-full_2.03.exe 2013-07-12 11:45 - 2013-07-12 11:45 - 00000000 ____D C:\Users\utti\AppData\Roaming\WinZipper 2013-07-12 11:39 - 2013-07-12 11:39 - 00291760 _____ C:\Users\utti\Desktop\hafner kreis schwarz.eps 2013-07-12 11:33 - 2013-07-12 11:33 - 00000000 ____D C:\Users\utti\AppData\Local\emaze 2013-07-12 10:01 - 2011-03-12 12:34 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-12 09:59 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-12 09:37 - 2007-06-20 14:02 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-12 09:13 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 05:59 - 2013-07-10 05:56 - 534746810 _____ C:\Users\utti\Dokumente\Image.nrg 2013-07-09 17:08 - 2013-07-09 17:08 - 00002513 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00002003 _____ C:\Users\Public\Desktop\Nero Online-Upgrade.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00001919 _____ C:\Users\Public\Desktop\Nero - BurnSupportDisc.lnk 2013-07-09 17:06 - 2007-06-20 13:06 - 00000000 ____D C:\Program Files\Common Files\Ahead 2013-07-08 13:14 - 2008-12-31 09:51 - 00042023 _____ C:\Users\utti\Dokumente\Abrechnung 2009-2012.xlsx 2013-07-05 14:42 - 2013-07-05 14:41 - 00000000 ____D C:\Users\utti\AppData\Roaming\Nero 2013-07-05 13:37 - 2013-07-05 13:35 - 101706760 _____ (Nero AG) C:\Users\utti\Downloads\Nero_BurningROM-12.5.01300_trial.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-29 17:07 ==================== End Of Log ============================ |
29.07.2013, 19:37 | #6 |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - CouponESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST Log bitte. Noch Probleme?
__________________ --> Unterstrichene Wörter mit Werbung - Coupon |
30.07.2013, 16:07 | #7 |
| Unterstrichene Wörter mit Werbung - Coupon FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 03 Ran by utti (administrator) on 30-07-2013 16:56:54 Running from C:\Users\utti\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ACE GmbH) C:\Program Files\Videoload Manager\ContentManager.exe (Empolis GmbH) c:\program files\common files\gnab\service\servicecontroller.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (InterVideo) C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Empolis GmbH) C:\Program Files\Medion\MEDIONbox\Program\GCS.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Nalpeiron Ltd.) C:\Windows\system32\NLSSRV32.EXE (Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\jp2launcher.exe (Oracle Corporation) C:\Program Files\Java\jre7\bin\java.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Microsoft Corporation) C:\Program Files\Windows Mail\WinMail.exe (Google) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Farbar) C:\Users\utti\Downloads\FRST(2).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4390912 2007-02-15] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-02-15] (Synaptics, Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [151552 2006-11-15] (Intel Corporation) HKLM\...\Run: [UVS10 Preload] - C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-10] (Ulead Systems, Inc.) HKLM\...\Run: [toolbar_eula_launcher] - C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [LexwareInfoService] - C:\Program Files\Common Files\Lexware\Update Manager\LxUpdateManager.exe [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [155648 2006-01-12] (Nero AG) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG) HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION! HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\System32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation) HKU\madmax\...\Run: [BullGuard] - "C:\Program Files\BullGuard Software\BullGuard\BullGuard.exe" [x] ==================== Internet (Whitelisted) ==================== ProxyServer: 192.168.2.1:80 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL (Protect Software GmbH) BHO: Super Lyrics - {30B87EBD-E91B-498B-B25D-DF116AF00393} - C:\Program Files\Super_Lyrics\125.dll No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} https://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} https://as.photoprintit.de/ips-opdata/layout/default_cms01/activex/IPSUploader4.cab DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_13-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: fluxhttp - {8E2D00A0-82C6-4821-90BC-07F290841BB6} - C:\Program Files\Common Files\fluxDVD\Lib\XEB\xebnavigation.ax () Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: haufereader - No CLSID Value - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 45 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default FF Homepage: hxxp://www.comdirect.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @fluxdvd.com/NPAPIX - C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll () FF Plugin: @fluxdvd.com/NPFluxBrowserHelper - C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pages.tvunetworks.com/WebPlayer - C:\Windows\system32\TVUAx\npTVUAx.dll (TVU networks) FF Plugin: @protectdisc.com/NPMPDRM - C:\Program Files\Common Files\mpDRM\NPMPDRM.dll () FF Plugin: @protectdisc.com/NPWMDRMWrapper - C:\Program Files\Common Files\mpDRM\NPWMDRMWrapper.dll () FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @veetle.com/vbp;version=0.9.17 - C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc) FF Plugin: @veetle.com/veetleCorePlugin,version=0.9.17 - C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin: @veetle.com/veetlePlayerPlugin,version=0.9.17 - C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @citrixonline.com/appdetectorplugin - C:\Users\utti\AppData\Local\Citrix\Plugins\94\npappdetector.dll (Citrix Online) FF Extension: No Name - C:\Users\utti\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: DownloadHelper - C:\Users\utti\AppData\Roaming\Mozilla\Firefox\Profiles\38rjua60.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{400F0BDB-6C49-43A4-BE1F-76D7327A604D}] C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla FF Extension: fluxDVD Download Manager - C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKCU\...\Firefox\Extensions: [{F7EC2BAD-F77B-4020-B3C6-58B97D0859E5}] C:\Program Files\Super_Lyrics\125.xpi ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG) R2 ContentMgrService; C:\Program Files\Videoload Manager\ContentManager.exe [508928 2008-03-12] (ACE GmbH) S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Sued Foto Service\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) R2 GnabService; c:\program files\common files\gnab\service\servicecontroller.exe [36864 2007-04-13] (Empolis GmbH) R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [84744 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135136 2013-07-29] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-07-29] (Avira Operations GmbH & Co. KG) S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.) S4 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [125328 2008-03-29] (Deterministic Networks, Inc.) S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc. ) S3 hitmanpro35; C:\Windows\system32\drivers\hitmanpro36.sys [25888 2012-03-28] () S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51088 2004-03-18] (HP) S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-03-18] (HP) S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-03-18] (HP) R3 Iviaspi; C:\Windows\System32\drivers\iviaspi.sys [16024 2006-11-22] (InterVideo, Inc.) S3 LTXMD_VAC; C:\Windows\System32\drivers\lmvac.sys [18912 2008-06-30] (Windows (R) Codename Longhorn DDK provider) R1 PSSDK42; C:\Windows\system32\Drivers\pssdk42.sys [38976 2010-01-24] (microOLAP Technologies LTD) R1 PSSDKLBF; C:\Windows\system32\Drivers\pssdklbf.sys [53312 2010-01-24] (microOLAP Technologies LTD) R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [277504 2007-07-05] (Realtek Semiconductor Corporation ) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1729152 2007-02-07] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-07-29] (Avira GmbH) S3 w810bus; C:\Windows\System32\DRIVERS\w810bus.sys [58288 2006-02-20] (MCCI) S3 w810mdfl; C:\Windows\System32\DRIVERS\w810mdfl.sys [8336 2006-02-20] (MCCI) S3 w810mdm; C:\Windows\System32\DRIVERS\w810mdm.sys [94064 2006-02-20] (MCCI) S3 w810mgmt; C:\Windows\System32\DRIVERS\w810mgmt.sys [85408 2006-02-20] (MCCI) S3 w810obex; C:\Windows\System32\DRIVERS\w810obex.sys [83344 2006-02-20] (MCCI) S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-30 16:55 - 2013-07-30 16:55 - 01222114 _____ (Farbar) C:\Users\utti\Downloads\FRST(2).exe 2013-07-30 16:52 - 2013-07-30 16:52 - 00000930 _____ C:\Users\utti\Desktop\checkup.txt 2013-07-30 16:44 - 2013-07-30 16:44 - 00891098 _____ C:\Users\utti\Downloads\SecurityCheck.exe 2013-07-30 11:24 - 2013-07-30 11:24 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu(1).exe 2013-07-29 17:12 - 2013-07-29 17:12 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST(1).exe 2013-07-29 17:07 - 2013-07-29 17:07 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT(1).exe 2013-07-29 16:57 - 2013-07-29 16:58 - 00001286 _____ C:\AdwCleaner[S4].txt 2013-07-29 16:56 - 2013-07-29 16:56 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner(1).exe 2013-07-29 16:04 - 2013-07-29 16:04 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST.exe 2013-07-29 16:04 - 2013-07-29 16:04 - 00000000 ____D C:\FRST 2013-07-29 14:57 - 2013-07-29 14:57 - 00000000 _____ C:\Users\utti\defogger_reenable 2013-07-29 12:14 - 2013-07-29 12:14 - 00000000 ____D C:\Program Files\ESET 2013-07-29 12:13 - 2013-07-29 12:14 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu.exe 2013-07-29 12:01 - 2013-07-29 12:01 - 00700783 ____R (Swearware) C:\Users\utti\Downloads\dds+.exe 2013-07-29 11:56 - 2013-07-29 11:56 - 00000000 ____D C:\Users\utti\AppData\Roaming\Avira 2013-07-29 11:54 - 2013-07-29 11:55 - 00448512 _____ (OldTimer Tools) C:\Users\utti\Downloads\TFC.exe 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:49 - 2013-07-29 11:14 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:49 - 2013-07-29 11:14 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:49 - 2013-07-29 11:14 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:43 - 2013-07-29 11:43 - 00001223 _____ C:\AdwCleaner[S3].txt 2013-07-29 10:58 - 2013-07-29 15:29 - 00090648 _____ C:\Windows\PFRO.log 2013-07-27 12:36 - 2013-07-27 12:36 - 00001261 _____ C:\AdwCleaner[S2].txt 2013-07-27 12:22 - 2013-07-27 12:22 - 00001100 _____ C:\AdwCleaner[R2].txt 2013-07-27 12:17 - 2013-07-27 12:18 - 00001039 _____ C:\AdwCleaner[R1].txt 2013-07-27 12:17 - 2013-07-27 12:17 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner.exe 2013-07-27 12:11 - 2013-07-29 16:10 - 00024951 _____ C:\Users\utti\Downloads\Addition.txt 2013-07-24 23:10 - 2013-07-24 23:10 - 00000810 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-24 22:50 - 2013-07-24 22:50 - 00280368 _____ (Mozilla) C:\Users\utti\Downloads\Firefox Setup Stub 22.0.exe 2013-07-14 22:07 - 2013-07-14 22:12 - 00000000 ____D C:\Windows\system32\MRT 2013-07-14 15:36 - 2013-07-14 15:37 - 00005423 _____ C:\AdwCleaner[S1].txt 2013-07-14 15:25 - 2013-07-14 15:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-14 15:24 - 2013-07-14 15:24 - 00559441 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT.exe 2013-07-14 06:09 - 2013-07-14 06:09 - 00000393 _____ C:\zoek-results.log 2013-07-14 06:09 - 2013-07-14 06:09 - 00000000 ____D C:\Users\utti\Qtrax 2013-07-14 06:08 - 2013-07-14 06:08 - 01274079 _____ C:\Users\utti\Downloads\zoek.exe 2013-07-14 06:05 - 2013-07-30 08:29 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-14 06:05 - 2013-07-14 13:17 - 00000000 ____D C:\Users\utti\AppData\Roaming\Zip Opener Packages 2013-07-14 06:04 - 2013-07-14 06:04 - 00793536 _____ C:\Users\utti\Downloads\ZipOpenerSetup.exe 2013-07-14 05:30 - 2013-07-14 05:30 - 00591904 _____ C:\Users\utti\Downloads\VuuPC_Setup.exe 2013-07-13 09:18 - 2013-07-13 09:19 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-13 09:17 - 2013-07-13 09:17 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\utti\Downloads\SpyHunter-Installer.exe 2013-07-12 18:33 - 2013-07-15 10:28 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-12 18:30 - 2013-07-12 18:31 - 25326392 _____ (DVDVideoSoft Ltd. ) C:\Users\utti\Downloads\FreeYouTubeToMP3Converter.exe 2013-07-12 11:58 - 2013-07-12 11:59 - 00000000 ____D C:\Users\utti\AppData\Roaming\XnView 2013-07-12 11:57 - 2013-07-12 11:58 - 00000732 _____ C:\Users\utti\Desktop\XnView.lnk 2013-07-12 11:57 - 2013-07-12 11:57 - 00000000 ____D C:\Program Files\XnView 2013-07-12 11:53 - 2013-07-12 11:54 - 15188720 _____ (Gougelet Pierre-e ) C:\Users\utti\Downloads\XnView-win-full_2.03.exe 2013-07-12 11:45 - 2013-07-12 11:45 - 00000000 ____D C:\Users\utti\AppData\Roaming\WinZipper 2013-07-12 11:39 - 2013-07-12 11:39 - 00291760 _____ C:\Users\utti\Desktop\hafner kreis schwarz.eps 2013-07-12 11:33 - 2013-07-12 11:33 - 00000000 ____D C:\Users\utti\AppData\Local\emaze 2013-07-12 09:26 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-12 09:26 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-12 09:26 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-12 09:26 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-12 09:26 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-12 09:26 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-12 09:26 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-12 09:26 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-12 09:26 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-12 09:26 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-12 09:26 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-12 09:26 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-12 09:26 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-12 09:26 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-12 09:26 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-12 09:26 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-12 08:48 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-12 08:48 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-12 08:48 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-12 08:48 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-12 08:48 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-12 08:48 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-12 08:48 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-12 08:48 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-12 08:47 - 2013-05-08 06:04 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 05:56 - 2013-07-10 05:59 - 534746810 _____ C:\Users\utti\Dokumente\Image.nrg 2013-07-09 17:08 - 2013-07-09 17:08 - 00002513 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00002003 _____ C:\Users\Public\Desktop\Nero Online-Upgrade.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00001919 _____ C:\Users\Public\Desktop\Nero - BurnSupportDisc.lnk 2013-07-05 14:41 - 2013-07-05 14:42 - 00000000 ____D C:\Users\utti\AppData\Roaming\Nero 2013-07-05 13:35 - 2013-07-05 13:37 - 101706760 _____ (Nero AG) C:\Users\utti\Downloads\Nero_BurningROM-12.5.01300_trial.exe ==================== One Month Modified Files and Folders ======= 2013-07-30 16:55 - 2013-07-30 16:55 - 01222114 _____ (Farbar) C:\Users\utti\Downloads\FRST(2).exe 2013-07-30 16:52 - 2013-07-30 16:52 - 00000930 _____ C:\Users\utti\Desktop\checkup.txt 2013-07-30 16:47 - 2012-07-09 21:52 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-30 16:44 - 2013-07-30 16:44 - 00891098 _____ C:\Users\utti\Downloads\SecurityCheck.exe 2013-07-30 16:30 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-30 16:30 - 2006-11-02 14:47 - 00003696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-30 16:21 - 2011-09-27 07:57 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-30 11:28 - 2006-11-02 12:33 - 01481126 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-30 11:24 - 2013-07-30 11:24 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu(1).exe 2013-07-30 11:10 - 2013-06-21 05:55 - 01088077 _____ C:\Windows\WindowsUpdate.log 2013-07-30 08:29 - 2013-07-14 06:05 - 00000374 _____ C:\Windows\Tasks\Super Lyrics Update.job 2013-07-30 08:29 - 2011-09-27 07:57 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-30 08:29 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-29 22:09 - 2006-11-02 15:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-29 20:18 - 2010-01-24 23:04 - 00000000 ____D C:\Users\utti\AppData\Roaming\vlc 2013-07-29 17:12 - 2013-07-29 17:12 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST(1).exe 2013-07-29 17:07 - 2013-07-29 17:07 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT(1).exe 2013-07-29 16:58 - 2013-07-29 16:57 - 00001286 _____ C:\AdwCleaner[S4].txt 2013-07-29 16:56 - 2013-07-29 16:56 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner(1).exe 2013-07-29 16:10 - 2013-07-27 12:11 - 00024951 _____ C:\Users\utti\Downloads\Addition.txt 2013-07-29 16:04 - 2013-07-29 16:04 - 01221130 _____ (Farbar) C:\Users\utti\Downloads\FRST.exe 2013-07-29 16:04 - 2013-07-29 16:04 - 00000000 ____D C:\FRST 2013-07-29 15:36 - 2007-09-06 13:49 - 00131424 _____ C:\Users\utti\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-29 15:30 - 2006-11-02 14:47 - 03790920 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-29 15:29 - 2013-07-29 10:58 - 00090648 _____ C:\Windows\PFRO.log 2013-07-29 14:57 - 2013-07-29 14:57 - 00000000 _____ C:\Users\utti\defogger_reenable 2013-07-29 14:57 - 2007-09-06 13:49 - 00000000 ____D C:\Users\utti 2013-07-29 12:27 - 2007-11-20 19:32 - 00000000 ____D C:\Users\utti\Dokumente\SV Motzing 2013-07-29 12:14 - 2013-07-29 12:14 - 00000000 ____D C:\Program Files\ESET 2013-07-29 12:14 - 2013-07-29 12:13 - 02347384 _____ (ESET) C:\Users\utti\Downloads\esetsmartinstaller_enu.exe 2013-07-29 12:01 - 2013-07-29 12:01 - 00700783 ____R (Swearware) C:\Users\utti\Downloads\dds+.exe 2013-07-29 11:56 - 2013-07-29 11:56 - 00000000 ____D C:\Users\utti\AppData\Roaming\Avira 2013-07-29 11:55 - 2013-07-29 11:54 - 00448512 _____ (OldTimer Tools) C:\Users\utti\Downloads\TFC.exe 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\ProgramData\Avira 2013-07-29 11:49 - 2013-07-29 11:49 - 00000000 ____D C:\Program Files\Avira 2013-07-29 11:43 - 2013-07-29 11:43 - 00001223 _____ C:\AdwCleaner[S3].txt 2013-07-29 11:14 - 2013-07-29 11:49 - 00135136 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-07-29 11:14 - 2013-07-29 11:49 - 00084744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-07-29 11:14 - 2013-07-29 11:49 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2013-07-29 11:14 - 2007-12-11 07:51 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys 2013-07-29 09:59 - 2012-12-31 12:07 - 00072850 _____ C:\Users\utti\Dokumente\Konto + Aktien 2011-2012.xlsx 2013-07-29 09:59 - 2012-01-03 18:57 - 00000000 ___RD C:\Users\utti\Dokumente 2013-07-27 12:36 - 2013-07-27 12:36 - 00001261 _____ C:\AdwCleaner[S2].txt 2013-07-27 12:22 - 2013-07-27 12:22 - 00001100 _____ C:\AdwCleaner[R2].txt 2013-07-27 12:18 - 2013-07-27 12:17 - 00001039 _____ C:\AdwCleaner[R1].txt 2013-07-27 12:17 - 2013-07-27 12:17 - 00666633 _____ C:\Users\utti\Downloads\adwcleaner.exe 2013-07-25 07:57 - 2010-01-25 07:57 - 00000000 ____D C:\Users\utti\dwhelper 2013-07-25 07:11 - 2011-09-13 14:38 - 00000000 ____D C:\Users\utti\Desktop\Neuer Ordner 2013-07-25 06:56 - 2011-09-27 07:56 - 00000000 ____D C:\Users\utti\AppData\Local\Deployment 2013-07-25 06:56 - 2011-09-27 07:56 - 00000000 ____D C:\Users\utti\AppData\Local\Apps\2.0 2013-07-25 06:20 - 2012-05-03 17:48 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-24 23:10 - 2013-07-24 23:10 - 00000810 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-07-24 23:10 - 2013-06-28 08:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-24 22:50 - 2013-07-24 22:50 - 00280368 _____ (Mozilla) C:\Users\utti\Downloads\Firefox Setup Stub 22.0.exe 2013-07-24 22:42 - 2007-11-12 18:59 - 00000000 ____D C:\Users\madmax 2013-07-24 22:42 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\Msdtc 2013-07-24 22:42 - 2006-11-02 12:22 - 61603840 _____ C:\Windows\system32\config\software_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 42205184 _____ C:\Windows\system32\config\components_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 31195136 _____ C:\Windows\system32\config\system_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00262144 _____ C:\Windows\system32\config\default_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00094208 _____ C:\Windows\system32\config\sam_previous 2013-07-24 22:42 - 2006-11-02 12:22 - 00024576 _____ C:\Windows\system32\config\security_previous 2013-07-24 22:41 - 2011-09-11 22:29 - 00000000 ____D C:\Program Files\Grips 2013-07-24 22:41 - 2009-07-13 11:50 - 00000000 ____D C:\Program Files\Akademische Arbeitsgemeinschaft 2013-07-24 22:41 - 2007-09-19 18:13 - 00000000 ____D C:\Program Files\Azureus 2013-07-24 22:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\spool 2013-07-24 22:41 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\registration 2013-07-22 16:15 - 2007-09-19 18:39 - 00098816 _____ C:\Users\utti\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-07-22 13:45 - 2008-01-10 13:35 - 00000000 ____D C:\Users\utti\Dokumente\Donnervögel 2013-07-15 13:23 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-15 10:28 - 2013-07-12 18:33 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-07-15 10:28 - 2011-03-18 12:18 - 00000000 ____D C:\Users\utti\AppData\Roaming\DVDVideoSoft 2013-07-14 22:12 - 2013-07-14 22:07 - 00000000 ____D C:\Windows\system32\MRT 2013-07-14 22:06 - 2006-11-02 13:18 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-14 15:37 - 2013-07-14 15:36 - 00005423 _____ C:\AdwCleaner[S1].txt 2013-07-14 15:30 - 2008-05-25 21:56 - 00000913 _____ C:\Users\utti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-07-14 15:25 - 2013-07-14 15:25 - 00000000 ____D C:\Windows\ERUNT 2013-07-14 15:24 - 2013-07-14 15:24 - 00559441 _____ (Oleg N. Scherbakov) C:\Users\utti\Downloads\JRT.exe 2013-07-14 13:17 - 2013-07-14 06:05 - 00000000 ____D C:\Users\utti\AppData\Roaming\Zip Opener Packages 2013-07-14 06:09 - 2013-07-14 06:09 - 00000393 _____ C:\zoek-results.log 2013-07-14 06:09 - 2013-07-14 06:09 - 00000000 ____D C:\Users\utti\Qtrax 2013-07-14 06:08 - 2013-07-14 06:08 - 01274079 _____ C:\Users\utti\Downloads\zoek.exe 2013-07-14 06:04 - 2013-07-14 06:04 - 00793536 _____ C:\Users\utti\Downloads\ZipOpenerSetup.exe 2013-07-14 05:30 - 2013-07-14 05:30 - 00591904 _____ C:\Users\utti\Downloads\VuuPC_Setup.exe 2013-07-13 09:19 - 2013-07-13 09:18 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-07-13 09:17 - 2013-07-13 09:17 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\utti\Downloads\SpyHunter-Installer.exe 2013-07-12 21:42 - 2007-09-06 13:50 - 00000000 ____D C:\Users\utti\AppData\Roaming\Ulead Systems 2013-07-12 21:30 - 2007-06-19 15:16 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-07-12 21:23 - 2007-06-20 13:20 - 00000000 ____D C:\Program Files\InterVideo 2013-07-12 21:22 - 2007-07-09 17:31 - 00000000 ____D C:\Program Files\Common Files\InterVideo 2013-07-12 21:21 - 2012-03-26 17:25 - 00000000 ____D C:\Users\utti\AppData\Roaming\TeamViewer 2013-07-12 21:21 - 2011-11-22 23:52 - 00000000 ____D C:\Users\utti\AppData\Roaming\TuneUp Software 2013-07-12 21:21 - 2010-07-01 15:17 - 00000000 ____D C:\Users\utti\AppData\Roaming\Uniblue 2013-07-12 21:21 - 2007-09-09 14:24 - 00000000 ____D C:\Users\utti\AppData\Roaming\Sun 2013-07-12 18:31 - 2013-07-12 18:30 - 25326392 _____ (DVDVideoSoft Ltd. ) C:\Users\utti\Downloads\FreeYouTubeToMP3Converter.exe 2013-07-12 16:12 - 2007-06-20 13:06 - 00000000 ____D C:\ProgramData\Nero 2013-07-12 16:11 - 2007-06-20 13:06 - 00000000 ____D C:\Program Files\Nero 2013-07-12 11:59 - 2013-07-12 11:58 - 00000000 ____D C:\Users\utti\AppData\Roaming\XnView 2013-07-12 11:58 - 2013-07-12 11:57 - 00000732 _____ C:\Users\utti\Desktop\XnView.lnk 2013-07-12 11:57 - 2013-07-12 11:57 - 00000000 ____D C:\Program Files\XnView 2013-07-12 11:54 - 2013-07-12 11:53 - 15188720 _____ (Gougelet Pierre-e ) C:\Users\utti\Downloads\XnView-win-full_2.03.exe 2013-07-12 11:45 - 2013-07-12 11:45 - 00000000 ____D C:\Users\utti\AppData\Roaming\WinZipper 2013-07-12 11:39 - 2013-07-12 11:39 - 00291760 _____ C:\Users\utti\Desktop\hafner kreis schwarz.eps 2013-07-12 11:33 - 2013-07-12 11:33 - 00000000 ____D C:\Users\utti\AppData\Local\emaze 2013-07-12 10:01 - 2011-03-12 12:34 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-12 09:59 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-07-12 09:37 - 2007-06-20 14:02 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-12 09:13 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 05:59 - 2013-07-10 05:56 - 534746810 _____ C:\Users\utti\Dokumente\Image.nrg 2013-07-09 17:08 - 2013-07-09 17:08 - 00002513 _____ C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00002003 _____ C:\Users\Public\Desktop\Nero Online-Upgrade.lnk 2013-07-09 17:08 - 2013-07-09 17:08 - 00001919 _____ C:\Users\Public\Desktop\Nero - BurnSupportDisc.lnk 2013-07-09 17:06 - 2007-06-20 13:06 - 00000000 ____D C:\Program Files\Common Files\Ahead 2013-07-08 13:14 - 2008-12-31 09:51 - 00042023 _____ C:\Users\utti\Dokumente\Abrechnung 2009-2012.xlsx 2013-07-05 14:42 - 2013-07-05 14:41 - 00000000 ____D C:\Users\utti\AppData\Roaming\Nero 2013-07-05 13:37 - 2013-07-05 13:35 - 101706760 _____ (Nero AG) C:\Users\utti\Downloads\Nero_BurningROM-12.5.01300_trial.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-30 08:38 ==================== End Of Log ============================ --- --- --- ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a96b0c7fe7a37644b4a3ad9996b58e8b # engine=14584 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-30 02:25:30 # local_time=2013-07-30 04:25:30 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 95 28241 120964814 20964 0 # compatibility_mode=5892 16776573 100 100 27491 212727058 0 0 # scanned=214668 # found=0 # cleaned=0 # scan_time=17886 ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a96b0c7fe7a37644b4a3ad9996b58e8b # engine=14584 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-30 02:25:30 # local_time=2013-07-30 04:25:30 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1799 16775165 100 95 28241 120964814 20964 0 # compatibility_mode=5892 16776573 100 100 27491 212727058 0 0 # scanned=214668 # found=0 # cleaned=0 # scan_time=17886 Jetzt keine Probleme mehr. Danke |
31.07.2013, 07:30 | #8 |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - Coupon Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION! ProxyServer: 192.168.2.1:80 S2 WsysSvc; C:\ProgramData\eSafe\eGdpSvc.exe [x] C:\ProgramData\eSafe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.07.2013, 07:38 | #9 |
| Unterstrichene Wörter mit Werbung - Coupon Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 28-07-2013 Ran by utti at 2013-07-31 08:37:02 Run:1 Running from C:\Users\utti\Downloads Boot Mode: Normal ============================================== HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. WsysSvc => Service deleted successfully. "C:\ProgramData\eSafe" => File/Directory not found. ==== End of Fixlog ==== |
31.07.2013, 09:54 | #10 |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - Coupon Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.07.2013, 11:57 | #12 | |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - CouponZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
31.07.2013, 12:07 | #13 |
| Unterstrichene Wörter mit Werbung - Coupon Gut, vielen Dank schrauber!!!! |
31.07.2013, 15:19 | #14 |
/// the machine /// TB-Ausbilder | Unterstrichene Wörter mit Werbung - Coupon Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Unterstrichene Wörter mit Werbung - Coupon |
adwcleaner, ausprobiert, board, certified, erschein, erscheine, erscheinen, firefox, helft, logfile, microsoft, popups, poste, posten, problem, rechts, seite, seiten, unterstrichene wörter, werbung, woche, wochen, wörter |