|
Plagegeister aller Art und deren Bekämpfung: SoftwareUpdater.UI.exe meldet sich nach StartWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.09.2013, 09:51 | #1 |
| SoftwareUpdater.UI.exe meldet sich nach Start Hallo zusammen, ich nutze Vista auf dem Notebook und habe mir nach einigen updates und downloads diesen -SoftwareUpdater.UI.exe- Schädling eingefangen. Das Virenprogramm habe ich drüber laufen lassen (Avira) der Updater meldet sich nach dem Rechnerstart jedoch beharrlich weiter. Versuche die SW zu löschen sind bislang gescheitert. Ich dachte, da bitte ich hier mal um Hilfe, wie's scheint, hat das für das beschriebene Problem ja auch schon gut geklappt. Danke im Voraus + Gruß, Timm |
11.09.2013, 09:53 | #2 |
/// the machine /// TB-Ausbilder | SoftwareUpdater.UI.exe meldet sich nach Start hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
11.09.2013, 10:43 | #3 |
| SoftwareUpdater.UI.exe meldet sich nach Start Danke schrauber für die schnelle Antwort,
__________________hier die erste Datei: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 Ran by Tim (administrator) on TIM-PC on 11-09-2013 11:21:26 Running from C:\Users\Tim\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Softex Inc.) C:\Program Files\Softex\OmniPass\OmniServ.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Agere Systems) C:\Windows\system32\agrsmsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Realtek Semiconductor) C:\Windows\RtHDVCpl.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe () C:\Program Files\Softex\OmniPass\opvapp.exe (Cyberlink Corp.) C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe () C:\Program Files\Softex\OmniPass\scureapp.exe (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (CyberLink) C:\Program Files\HomeCinema\Power2Go\CLMLSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe (GARMIN Corp.) C:\Program Files\Garmin\ANT Agent\ANT Agent.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) C:\Program Files\MyTomTom 3\MyTomTomSA.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Dropbox, Inc.) C:\Users\Tim\AppData\Roaming\Dropbox\bin\Dropbox.exe (Windows Net) C:\Users\Tim\AppData\Roaming\Windows Net Data\net.exe () C:\Program Files\CDBurnerXP\NMSAccessU.exe (Simplygen) C:\Program Files\HomeTab\ProtectedSearch.exe () C:\Program Files\CyberLink\Shared Files\RichVideo.exe (Buhl Data Service GmbH) C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Microsoft Corporation) C:\Windows\system32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-08-31] (Synaptics, Inc.) HKLM\...\Run: [snp2uvc] - C:\Windows\vsnp2uvc.exe HKLM\...\Run: [PLFSetL] - C:\Windows\PLFSetL.exe [94208 2007-07-05] (sonix) HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4702208 2007-10-31] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation) HKLM\...\Run: [Skytel] - C:\Windows\Skytel.exe [1826816 2007-10-11] (Realtek Semiconductor Corp.) HKLM\...\Run: [NvSvc] - RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [39792 2008-10-15] (Adobe Systems Incorporated) HKLM\...\Run: [UCam_Menu] - C:\Program Files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe [222504 2007-09-13] (CyberLink Corp.) HKLM\...\Run: [toolbar_eula_launcher] - C:\Program Files\GoogleEULA\EULALauncher.exe [16896 2007-02-09] ( ) HKLM\...\Run: [RemoteControl] - C:\Program Files\HomeCinema\PowerDVD\PDVDServ.exe [71216 2007-02-09] (Cyberlink Corp.) HKLM\...\Run: [OmniPass] - C:\Program Files\Softex\OmniPass\scureapp.exe [2564096 2007-11-02] () HKLM\...\Run: [NeroFilterCheck] - C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG) HKLM\...\Run: [LanguageShortcut] - C:\Program Files\HomeCinema\PowerDVD\Language\Language.exe [52256 2007-01-08] () HKLM\...\Run: [CLMLServer] - C:\Program Files\HomeCinema\Power2Go\CLMLSvc.exe [128296 2007-10-17] (CyberLink) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-07] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN) HKLM\...\Runonce: [Del3974203] - cmd.exe /Q /D /c del "C:\Users\Tim\AppData\Local\Temp\0.del" Winlogon\Notify\igfxcui: igfxdev.dll [X] HKCU\...\Run: [Skype] - C:\Program Files\Skype\\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-10-15] (Nero AG) HKCU\...\Run: [ANT Agent] - C:\Program Files\Garmin\ANT Agent\ANT Agent.exe [14731776 2013-02-15] (GARMIN Corp.) HKCU\...\Run: [TomTomHOME.exe] - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-07-02] (TomTom) HKCU\...\Run: [MyTomTomSA.exe] - C:\Program Files\MyTomTom 3\MyTomTomSA.exe [458680 2013-08-01] (TomTom) HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) HKCU\...\Run: [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe [135672 2013-06-07] (PC Utilities Pro) HKCU\...\Runonce: [Del3974203] - cmd.exe /Q /D /c del "C:\Users\Tim\AppData\Local\Temp\0.del" MountPoints2: {88255695-c57f-11de-98fb-0016d3898483} - G:\installer.exe HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Philips GoGear Spark Device Manager.lnk ShortcutTarget: Philips GoGear Spark Device Manager.lnk -> C:\Program Files\Philips\GoGear Spark Device Manager\main.exe (KeenHigh Tech.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files\WISO\Steuersoftware 2011\mshaktuell.exe () Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Tim\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Tim\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com/ SearchScopes: HKCU - DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&affID=121150&babsrc=SP_ss&mntrId=86570015AF7AF662 SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=78752bba-0d4b-4619-8eb8-3a4229c61f58&apn_sauid=BAC9688E-56FE-4812-B897-B944DAD95E3D SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus BHO: Plus-HD-3.8 - {11111111-1111-1111-1111-110311901130} - C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-bho.dll (Plus HD) BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.) BHO: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.) BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.5.0.2\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO: HomeTab - {a25e7121-3dd8-41b3-855b-756c5bc45449} - C:\Users\Tim\AppData\Roaming\HomeTab\HomeTab.dll (Simply Tech Ltd.) BHO: Web Check - {E155F23C-9931-47c6-A619-20E6FCA86D75} - C:\Program Files\Web Check\WebCheck.dll (Web Check) BHO: PricePeep - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - C:\Program Files\PricePeep\pricepeep.dll (PricePeep) Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.5.0.2\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKLM - No Name - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No File Toolbar: HKLM - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKLM - HomeTab - {a25e7121-3dd8-41b3-855b-756c5bc45449} - C:\Users\Tim\AppData\Roaming\HomeTab\HomeTab.dll (Simply Tech Ltd.) Toolbar: HKCU -No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU -No Name - {DFEFCDEE-CF1A-4FC8-88AD-129872198372} - No File DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll (AVG Secure Search) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [avg@toolbar] C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF HKCU\...\Thunderbird\Extensions: [{0E810812-F4BB-4309-942A-755587587A5E}] C:\Program Files\BullGuard Software\BullGuard\antispam\tbspamfilter Chrome: ======= CHR DefaultSearchURL: (ask) - hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=AVR-3&o=APN10395&locale=de_DE&apn_uid=&apn_ptnrs=%5EABT&apn_sauid=&apn_dtid=%5EYYYYYY%5EYY%5EDE&psv=&q={searchTerms} CHR DefaultSuggestURL: (ask) - hxxp://ss.websearch.ask.com/query?qsrc={qsrc}&li=ff&sstype=prefix&q={searchTerms} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll (AVG Technologies) CHR Plugin: (DivX Player Netscape Plugin) - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\20.53263_0 CHR Extension: (HomeTab) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddpogknpjlgfpbboediomaiiaecfajn\4.4_1 CHR Extension: (YouTube) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Web Check) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\dacechnliklhcacondhhkkfobapdopee\0.1_0 CHR Extension: (PricePeep) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\licjnkifamhpbaefhdpacpmihicfbomb\2.2.0.3_0 CHR Extension: (AVG Secure Search) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\15.5.0.2_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0 CHR Extension: (Plus-HD-3.8) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjgnhihlklpobkaloamkankaaoclfjh\1.23.19_0 CHR Extension: (Gmail) - C:\Users\Tim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM\...\Chrome\Extension: [bddpogknpjlgfpbboediomaiiaecfajn] - C:\Program Files\HomeTab\chrome\HomeTab.crx CHR HKLM\...\Chrome\Extension: [dacechnliklhcacondhhkkfobapdopee] - C:\Program Files\Web Check\WebCheck.crx CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\15.5.0.2\avg.crx ========================== Services (Whitelisted) ================= R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-07] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-07] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-07] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.) S3 FirebirdServerMAGIXInstance; C:\Program Files\ALDI Foto Service Nord\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) R2 NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] () R2 omniserv; C:\Program Files\Softex\OmniPass\OmniServ.exe [40960 2007-11-02] (Softex Inc.) R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] () R2 srvcPVR; C:\Program Files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe [1681408 2007-08-16] (Buhl Data Service GmbH) S2 SystemStoreService; C:\Program Files\SoftwareUpdater\SystemStore.exe [296448 2013-09-10] () S4 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-15] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== R3 ATSWPDRV; C:\Windows\System32\DRIVERS\ATSwpDrv.sys [146560 2007-08-28] (AuthenTec, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-07] (Avira Operations GmbH & Co. KG) S4 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-15] (AVG Technologies) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-07] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-05] (Avira Operations GmbH & Co. KG) S3 Cam5607; C:\Windows\System32\Drivers\BisonC07.sys [805416 2007-08-30] (Bison Electronics. Inc. ) R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation) S3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd5.sys [45568 2006-11-02] (VIA Technologies, Inc. ) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [35776 2011-05-17] (hxxp://libusb-win32.sourceforge.net) S3 PhilCap; C:\Windows\System32\DRIVERS\PhilCap.sys [908896 2007-07-31] (NXP Semiconductors Germany GmbH) R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [210736 2007-06-01] (Silicon Image, Inc) R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17328 2007-05-25] (Silicon Image, Inc.) R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12464 2007-05-25] (Silicon Image, Inc.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1749760 2007-08-22] () R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] () S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x] S3 igfx; system32\DRIVERS\igdkmd32.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] S3 XUIF; System32\Drivers\x10ufx2.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-11 11:18 - 2013-09-11 11:19 - 01082455 _____ (Farbar) C:\Users\Tim\Downloads\FRST.exe 2013-09-11 11:09 - 2013-09-11 11:09 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Optimizer Pro 2013-09-11 11:04 - 2013-09-11 11:04 - 00000907 _____ C:\Users\Public\Desktop\Open It!.lnk 2013-09-11 11:04 - 2013-09-11 11:04 - 00000863 _____ C:\Users\Tim\Desktop\Optimizer Pro.lnk 2013-09-11 11:04 - 2013-09-11 11:04 - 00000416 _____ C:\Windows\Tasks\At1.job 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Users\Tim\AppData\Roaming\DSite 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Program Files\PricePeep 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Program Files\Optimizer Pro 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Program Files\OpenIt 2013-09-11 11:02 - 2013-09-11 11:02 - 00745328 _____ C:\Users\Tim\Downloads\ZipOpenerSetup.exe 2013-09-11 10:16 - 2013-09-11 10:16 - 97063418 _____ C:\Windows\system32\傒魼ᨼ 2013-09-10 23:58 - 2013-09-11 00:09 - 00000000 ____D C:\Windows\system32\MRT 2013-09-10 23:32 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-10 23:32 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-10 23:32 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-10 23:32 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-10 23:32 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-10 23:32 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-09-10 23:32 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-09-10 23:32 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-10 23:32 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-10 23:32 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-10 23:32 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-10 23:32 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-09-10 23:32 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-09-10 23:32 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-10 23:32 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-10 23:32 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-09-10 23:15 - 2013-08-02 06:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-09-10 23:15 - 2013-07-10 11:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-09-10 23:15 - 2013-07-09 14:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-09-10 23:15 - 2013-07-08 06:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-09-10 23:15 - 2013-07-08 06:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-09-10 23:15 - 2013-07-05 06:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-09-10 23:15 - 2013-06-15 15:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll 2013-09-10 23:15 - 2013-06-15 13:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-09-10 23:15 - 2013-04-24 06:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-09-10 23:15 - 2013-04-24 03:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-09-10 23:15 - 2013-04-17 13:28 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-09-10 23:15 - 2013-04-17 13:28 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-09-10 23:15 - 2013-04-17 13:28 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-09-10 23:15 - 2013-04-17 13:28 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-09-10 23:15 - 2013-04-17 12:34 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-09-10 23:15 - 2013-04-17 12:33 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-09-10 23:15 - 2013-04-17 12:14 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-09-10 23:15 - 2013-04-17 12:10 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-09-10 23:15 - 2013-04-17 12:10 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-09-10 23:15 - 2013-04-15 16:20 - 00638328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-09-10 23:15 - 2013-04-13 12:56 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2013-09-10 23:14 - 2013-07-17 21:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-09-10 23:14 - 2013-07-08 06:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-09-10 23:14 - 2013-07-08 06:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-09-10 23:14 - 2013-07-08 06:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-09-10 23:14 - 2013-07-08 06:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-09-10 23:14 - 2013-06-04 03:50 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-10 23:14 - 2013-05-02 06:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-09-10 23:14 - 2013-05-02 06:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll 2013-09-10 23:14 - 2013-04-17 14:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-09-10 23:12 - 2013-06-01 06:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-09-10 15:15 - 2013-09-10 15:22 - 00000000 ____D C:\Users\Tim\Downloads\cdex_151 2013-09-10 15:14 - 2013-09-10 15:15 - 01923290 _____ C:\Users\Tim\Downloads\cdex_151.zip 2013-09-10 14:45 - 2013-09-10 14:46 - 00000000 ____D C:\Users\Tim\AppData\Local\DownloadGuide 2013-09-10 14:31 - 2013-09-11 09:59 - 00001274 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job 2013-09-10 14:31 - 2013-09-11 09:59 - 00001180 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job 2013-09-10 14:31 - 2013-09-11 09:59 - 00001078 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job 2013-09-10 14:31 - 2013-09-10 15:00 - 00000000 ____D C:\Users\Tim\Documents\TubeBox 2013-09-10 14:31 - 2013-09-10 14:31 - 00000000 ____D C:\Users\Tim\AppData\Local\Freetec 2013-09-10 14:30 - 2013-09-11 09:59 - 00001876 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job 2013-09-10 14:30 - 2013-09-11 09:59 - 00001800 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job 2013-09-10 14:30 - 2013-09-10 14:31 - 00000000 ____D C:\Program Files\Plus-HD-3.8 2013-09-10 14:29 - 2013-09-10 14:47 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Windows Net Data 2013-09-10 14:27 - 2013-09-10 14:27 - 00000000 ____D C:\Users\Tim\AppData\Roaming\SimplyTech 2013-09-10 14:27 - 2013-09-10 14:27 - 00000000 ____D C:\Users\Tim\AppData\Roaming\HomeTab 2013-09-10 14:27 - 2013-09-10 14:27 - 00000000 ____D C:\Program Files\HomeTab 2013-09-10 14:27 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-10 14:24 - 2013-09-10 14:26 - 00000000 ____D C:\Program Files\SoftwareUpdater 2013-09-10 14:23 - 2013-09-10 14:23 - 00000000 ____D C:\Program Files\Web Check 2013-09-10 14:21 - 2013-09-10 14:21 - 00445448 _____ C:\Users\Tim\Downloads\TubeBox_Setup (2).exe 2013-09-10 14:21 - 2013-09-10 14:21 - 00445448 _____ C:\Users\Tim\Downloads\TubeBox_Setup (1).exe 2013-09-10 14:18 - 2013-09-10 14:18 - 00445448 _____ C:\Users\Tim\Downloads\TubeBox_Setup.exe 2013-09-10 10:44 - 2013-09-10 10:44 - 00000000 ____D C:\Program Files\MyTomTom 3 2013-09-10 10:43 - 2013-09-10 10:43 - 06701152 _____ (TomTom International B.V.) C:\Users\Tim\Downloads\InstallMyTomTomSA.exe 2013-09-10 10:26 - 2013-09-10 10:44 - 00000000 ____D C:\Users\Tim\AppData\Local\TomTom 2013-09-10 10:26 - 2013-09-10 10:26 - 00000000 ____D C:\Users\Tim\Documents\TomTom 2013-09-10 10:26 - 2013-09-10 10:26 - 00000000 ____D C:\Users\Tim\AppData\Roaming\TomTom 2013-09-10 10:25 - 2013-09-10 10:25 - 00000000 ____D C:\Program Files\TomTom HOME 2 2013-09-10 10:23 - 2013-09-10 10:44 - 00000000 ____D C:\Program Files\TomTom International B.V 2013-09-10 10:22 - 2013-09-10 10:22 - 00000000 ____D C:\Users\Tim\AppData\Local\Downloaded Installations 2013-09-10 10:21 - 2013-09-10 10:22 - 30914760 _____ C:\Users\Tim\Downloads\TomTomHOME2winlatest.exe ==================== One Month Modified Files and Folders ======= 2013-09-11 11:20 - 2012-12-02 14:15 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-11 11:19 - 2013-09-11 11:19 - 00000000 ____D C:\FRST 2013-09-11 11:19 - 2013-09-11 11:18 - 01082455 _____ (Farbar) C:\Users\Tim\Downloads\FRST.exe 2013-09-11 11:09 - 2013-09-11 11:09 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Optimizer Pro 2013-09-11 11:05 - 2013-04-30 22:16 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Babylon 2013-09-11 11:04 - 2013-09-11 11:04 - 00000907 _____ C:\Users\Public\Desktop\Open It!.lnk 2013-09-11 11:04 - 2013-09-11 11:04 - 00000863 _____ C:\Users\Tim\Desktop\Optimizer Pro.lnk 2013-09-11 11:04 - 2013-09-11 11:04 - 00000416 _____ C:\Windows\Tasks\At1.job 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Users\Tim\AppData\Roaming\DSite 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Program Files\PricePeep 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Program Files\Optimizer Pro 2013-09-11 11:04 - 2013-09-11 11:04 - 00000000 ____D C:\Program Files\OpenIt 2013-09-11 11:02 - 2013-09-11 11:02 - 00745328 _____ C:\Users\Tim\Downloads\ZipOpenerSetup.exe 2013-09-11 10:59 - 2006-11-02 14:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-11 10:59 - 2006-11-02 14:47 - 00003168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-11 10:24 - 2012-09-29 10:25 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-11 10:16 - 2013-09-11 10:16 - 97063418 _____ C:\Windows\system32\傒魼ᨼ 2013-09-11 10:08 - 2008-03-16 22:06 - 01281029 _____ C:\Windows\WindowsUpdate.log 2013-09-11 10:02 - 2012-10-14 21:13 - 00000000 ___RD C:\Users\Tim\Dropbox 2013-09-11 10:02 - 2012-10-14 21:09 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Dropbox 2013-09-11 10:00 - 2009-09-13 17:21 - 00027649 _____ C:\Users\Tim\AppData\Roaming\nvModes.001 2013-09-11 09:59 - 2013-09-10 14:31 - 00001274 _____ C:\Windows\Tasks\Plus-HD-3.8-updater.job 2013-09-11 09:59 - 2013-09-10 14:31 - 00001180 _____ C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job 2013-09-11 09:59 - 2013-09-10 14:31 - 00001078 _____ C:\Windows\Tasks\Plus-HD-3.8-enabler.job 2013-09-11 09:59 - 2013-09-10 14:30 - 00001876 _____ C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job 2013-09-11 09:59 - 2013-09-10 14:30 - 00001800 _____ C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job 2013-09-11 09:59 - 2013-06-07 19:53 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job 2013-09-11 09:59 - 2013-06-04 21:44 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2013-09-11 09:59 - 2012-12-02 14:15 - 00001088 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-11 09:59 - 2008-03-16 22:12 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Home Cinema 2013-09-11 09:59 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-11 09:49 - 2006-11-02 15:01 - 00032510 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-11 09:45 - 2007-09-18 09:02 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-09-11 09:33 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-11 09:24 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\rescache 2013-09-11 09:06 - 2006-11-02 12:33 - 01472290 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-11 08:56 - 2006-11-02 14:47 - 00387200 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-11 08:54 - 2008-04-26 11:06 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-09-11 08:53 - 2006-11-02 14:37 - 00000000 ____D C:\Windows\system32\XPSViewer 2013-09-11 08:53 - 2006-11-02 14:37 - 00000000 ____D C:\Program Files\Windows Journal 2013-09-11 08:53 - 2006-11-02 13:18 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-11 00:24 - 2012-07-15 16:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-11 00:24 - 2012-07-15 16:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-11 00:09 - 2013-09-10 23:58 - 00000000 ____D C:\Windows\system32\MRT 2013-09-10 15:35 - 2006-11-02 14:52 - 00083255 _____ C:\Windows\setupact.log 2013-09-10 15:22 - 2013-09-10 15:15 - 00000000 ____D C:\Users\Tim\Downloads\cdex_151 2013-09-10 15:15 - 2013-09-10 15:14 - 01923290 _____ C:\Users\Tim\Downloads\cdex_151.zip 2013-09-10 15:00 - 2013-09-10 14:31 - 00000000 ____D C:\Users\Tim\Documents\TubeBox 2013-09-10 14:47 - 2013-09-10 14:29 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Windows Net Data 2013-09-10 14:46 - 2013-09-10 14:45 - 00000000 ____D C:\Users\Tim\AppData\Local\DownloadGuide 2013-09-10 14:31 - 2013-09-10 14:31 - 00000000 ____D C:\Users\Tim\AppData\Local\Freetec 2013-09-10 14:31 - 2013-09-10 14:30 - 00000000 ____D C:\Program Files\Plus-HD-3.8 2013-09-10 14:27 - 2013-09-10 14:27 - 00000000 ____D C:\Users\Tim\AppData\Roaming\SimplyTech 2013-09-10 14:27 - 2013-09-10 14:27 - 00000000 ____D C:\Users\Tim\AppData\Roaming\HomeTab 2013-09-10 14:27 - 2013-09-10 14:27 - 00000000 ____D C:\Program Files\HomeTab 2013-09-10 14:26 - 2013-09-10 14:24 - 00000000 ____D C:\Program Files\SoftwareUpdater 2013-09-10 14:23 - 2013-09-10 14:23 - 00000000 ____D C:\Program Files\Web Check 2013-09-10 14:21 - 2013-09-10 14:21 - 00445448 _____ C:\Users\Tim\Downloads\TubeBox_Setup (2).exe 2013-09-10 14:21 - 2013-09-10 14:21 - 00445448 _____ C:\Users\Tim\Downloads\TubeBox_Setup (1).exe 2013-09-10 14:18 - 2013-09-10 14:18 - 00445448 _____ C:\Users\Tim\Downloads\TubeBox_Setup.exe 2013-09-10 10:44 - 2013-09-10 10:44 - 00000000 ____D C:\Program Files\MyTomTom 3 2013-09-10 10:44 - 2013-09-10 10:26 - 00000000 ____D C:\Users\Tim\AppData\Local\TomTom 2013-09-10 10:44 - 2013-09-10 10:23 - 00000000 ____D C:\Program Files\TomTom International B.V 2013-09-10 10:43 - 2013-09-10 10:43 - 06701152 _____ (TomTom International B.V.) C:\Users\Tim\Downloads\InstallMyTomTomSA.exe 2013-09-10 10:26 - 2013-09-10 10:26 - 00000000 ____D C:\Users\Tim\Documents\TomTom 2013-09-10 10:26 - 2013-09-10 10:26 - 00000000 ____D C:\Users\Tim\AppData\Roaming\TomTom 2013-09-10 10:26 - 2009-12-31 21:36 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Mozilla 2013-09-10 10:25 - 2013-09-10 10:25 - 00000000 ____D C:\Program Files\TomTom HOME 2 2013-09-10 10:22 - 2013-09-10 10:22 - 00000000 ____D C:\Users\Tim\AppData\Local\Downloaded Installations 2013-09-10 10:22 - 2013-09-10 10:21 - 30914760 _____ C:\Users\Tim\Downloads\TomTomHOME2winlatest.exe 2013-09-10 10:06 - 2008-03-16 22:12 - 00000000 ____D C:\Users\Tim 2013-09-07 10:35 - 2012-12-02 14:16 - 00001975 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-07 10:13 - 2013-08-05 21:28 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-09-07 10:13 - 2013-08-05 21:28 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-08-23 19:41 - 2012-10-14 21:13 - 00000917 _____ C:\Users\Tim\Desktop\Dropbox.lnk 2013-08-23 19:41 - 2012-10-14 21:10 - 00000000 ____D C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-08-15 20:09 - 2012-08-30 22:16 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2013-08-15 20:09 - 2012-08-30 22:16 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-08-13 08:38 - 2013-09-10 14:27 - 00032328 _____ C:\Windows\Launcher.exe 2013-08-12 21:43 - 2009-09-13 16:07 - 00027649 _____ C:\Users\Tim\AppData\Roaming\nvModes.dat Files to move or delete: ==================== C:\Users\Tim\AppData\Local\Temp\AntDriver_AMI.exe C:\Users\Tim\AppData\Local\Temp\AskSLib.dll C:\Users\Tim\AppData\Local\Temp\avguidx.dll C:\Users\Tim\AppData\Local\Temp\CommonInstaller.exe C:\Users\Tim\AppData\Local\Temp\dotNetFx40_Client_setup.exe C:\Users\Tim\AppData\Local\Temp\FlashPlayerUpdate.exe C:\Users\Tim\AppData\Local\Temp\FlashPlayerUpdate01.exe C:\Users\Tim\AppData\Local\Temp\FlashPlayerUpdate02.exe C:\Users\Tim\AppData\Local\Temp\FlashPlayerUpdate03.exe C:\Users\Tim\AppData\Local\Temp\FlashPlayerUpdate04.exe C:\Users\Tim\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Tim\AppData\Local\Temp\GDM2FCC.exe C:\Users\Tim\AppData\Local\Temp\GDM95AF.exe C:\Users\Tim\AppData\Local\Temp\MachineIdCreator.exe C:\Users\Tim\AppData\Local\Temp\mgsqlite3.dll C:\Users\Tim\AppData\Local\Temp\oi_{7AD97D65-6A09-48DD-B85E-109360666B28}.exe C:\Users\Tim\AppData\Local\Temp\Shortcut_SweetIMSetup.exe C:\Users\Tim\AppData\Local\Temp\SIMEEI2Installer.exe C:\Users\Tim\AppData\Local\Temp\SIMEEIInstaller.exe C:\Users\Tim\AppData\Local\Temp\SkypeSetup.exe C:\Users\Tim\AppData\Local\Temp\ToolbarInstaller.exe C:\Users\Tim\AppData\Local\Temp\uninst1.exe C:\Users\Tim\AppData\Local\Temp\unwise.exe C:\Users\Tim\AppData\Local\Temp\_is4B04.exe C:\Users\Tim\AppData\Local\Temp\{AFFE2B32-40BE-494C-A9B4-8E44BA8B6EB0}-GoogleUpdateSetup.exe C:\Windows\Tasks\At1.job ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-11 10:05 ==================== End Of Log ============================ --- --- --- und hier die nächste: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-09-2013 Ran by Tim at 2013-09-11 11:24:00 Running from C:\Users\Tim\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= AAC Decoder (Version: 7.1.0) Activation Assistant for the 2007 Microsoft Office suites Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0) Adobe Flash Player 11 ActiveX (Version: 11.8.800.168) Adobe Flash Player 11 Plugin (Version: 11.8.800.168) Adobe Reader 8.1.4 - Deutsch (Version: 8.1.4) Adobe Shockwave Player 11.5 (Version: 11.5) Agere Systems HDA Modem AuthenTec Fingerprint Sensor Minimum Install (Version: 7.9.2) AutoUpdate (Version: 1.1) AVG Security Toolbar (Version: 15.5.0.2) Avira Antivirus Premium (Version: 13.0.0.4052) Avira SearchFree Toolbar plus Web Protection (Version: 12.2.2.663) CanoScan Toolbox Ver4.1 CDBurnerXP (Version: 4.3.2.2212) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000) CyberLink Power2Go (Version: 6.0.1109a) CyberLink YouCam (Version: 1.0.1205) CyberLink YouCam (Version: 1.00.0000) DivX Codec (Version: 6.9.1) DivX Converter (Version: 7.1.0) DivX Player (Version: 7.2.0) DivX Plus DirectShow Filters DivX Version Checker (Version: 7.1.0.9) DivX Web Player (Version: 1.5.0) Dropbox (HKCU Version: 2.2.13) Firebird SQL Server - MAGIX Edition (Version: 2.0.1.8) Garmin ANT Agent (Version: 2.3.4) Garmin Communicator Plugin (Version: 4.0.4) Garmin USB Drivers (Version: 2.3.1.0) GoGear Spark Device Manager (Version: 0.1) Google Chrome (Version: 29.0.1547.66) Google Update Helper (Version: 1.3.21.153) H.264 Decoder (Version: 1.1.0) HomeTab 4.4 (Version: 4.4) Inst5657 (Version: 5.00.91) Intel(R) Matrix Storage Manager IrfanView (remove only) (Version: 4.27) Java(TM) 6 Update 3 (Version: 1.6.0.30) Letstrade (Version: 1.00.0000) MakeDisc (Version: 3.0.2320) MediaShow (Version: 3.0.4325) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MKV Splitter (Version: 1.0.1) MSXML 4.0 SP2 (KB925672) (Version: 4.20.9839.0) MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MyTomTom 3.2.0.1220 (Version: 3.2.0.1220) Nero 8 Essentials (Version: 8.10.124) neroxml (Version: 1.0.0) NVIDIA Drivers OmniPass 5.00.91 (Version: 5.00.91) Open It! (Version: 1.1.1) OpenOffice.org 3.4 (Version: 3.4.9590) Optimizer Pro v3.1 (Version: 3.1) Paint.NET v3.5.10 (Version: 3.60.0) PDFCreator (Version: 1.5.0) PhotoNow! (Version: 1.0.4310) Plus-HD-3.8 (Version: 1.27.153.11) PowerDirector (Version: 6.5.2209a) PowerDVD (Version: 7.0.3118.0) PowerProducer (Version: 4.2.2219) PricePeep (Version: 2.2.0.3) Ralink Wireless LAN (Version: 1.00.0000) Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista (Version: 1.00.0000) Realtek High Definition Audio Driver (Version: 6.0.1.5506) Realtek USB 2.0 Card Reader (Version: ) Sceneo AbsolutTV Skype web features (Version: 1.0.3971) Skype™ 5.10 (Version: 5.10.116) Synaptics Pointing Device Driver (Version: 10.0.14.0) TomTom HOME (Version: 2.9.6) TomTom HOME Visual Studio Merge Modules (Version: 1.0.2) Ulead PhotoImpact 12 (Version: 12.0) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Zip Opener VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0) VCRedistSetup (Version: 1.0.0) Visual Studio C++ 10.0 Runtime (Version: 10.0.0) Web Check Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (Version: 04/19/2012 2.3.1.0) Windows-Treiberpaket - Dynastream Innovations (libusb0) LibUsbDevices (07/07/2009 1.12.2) (Version: 07/07/2009 1.12.2) Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (Version: 02/06/2007 3.1) WISO Sparbuch 2010 (Version: 17.00.6531) WISO Steuer-Sparbuch 2011 (Version: 18.06.7056) ==================== Restore Points ========================= 16-06-2013 07:12:32 Geplanter Prüfpunkt 17-06-2013 20:02:00 Geplanter Prüfpunkt 20-06-2013 18:52:59 Geplanter Prüfpunkt 23-06-2013 20:42:18 Geplanter Prüfpunkt 14-07-2013 09:06:51 Geplanter Prüfpunkt 10-09-2013 08:05:07 Gerätetreiber-Paketinstallation: TomTom Netzwerkadapter 10-09-2013 08:23:49 Installed TomTom HOME. 10-09-2013 12:22:45 TubeBox 10-09-2013 12:28:22 TubeBox 10-09-2013 12:46:37 TubeBox 10-09-2013 20:28:55 Windows Update 10-09-2013 21:16:09 Windows Update 11-09-2013 07:40:58 TubeBox 11-09-2013 07:45:27 Entfernt Launch Manager V1.4.9 11-09-2013 07:46:16 TVsweeper wird entfernt ==================== Hosts content: ========================== 2006-11-02 12:23 - 2006-09-18 23:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0B40F94D-29F9-4FD0-BBE0-CA5D682162D0} - System32\Tasks\Plus-HD-3.8-updater => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe [2013-09-10] (Plus HD) Task: {0F16AEEC-A823-4EC2-9BE8-C0DB99609633} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv => C:\Windows\TEMP\{8105C3F2-3726-47BC-8A94-FAB01E9BE307}.exe Task: {0FE233B5-666B-4358-A4F6-0A13D7DDD97A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-02] (Google Inc.) Task: {13033466-BD0B-4BB4-8484-88CC2807B41B} - System32\Tasks\{E4DF56B1-6792-429A-B56F-E8ED65D2CC74} => C:\Program Files\Skype\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.) Task: {185E3983-3090-4869-897A-A92B4AE0DF0A} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {1A406441-36D5-4E7A-AEB8-E4C06B56FC80} - System32\Tasks\At1 => C:\Users\Tim\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [2013-09-11] () Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {305822C3-FBD7-418E-8A4B-AD5C4A548525} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation) Task: {3AE0655A-40B8-46F0-BD44-551B11475B85} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Tim => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation) Task: {47C46436-575A-4BA1-884F-549A7CE2432D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-12-02] (Google Inc.) Task: {53CA99FB-5199-4BC6-A29D-AEEF1D451B4D} - System32\Tasks\Browser Updater\Browser Updater => C:\Program Files\HomeTab\TBUpdater.dll [2013-07-08] (Simply Tech Ltd.) Task: {56A4726B-A602-48B5-9344-AFCE78C6190B} - System32\Tasks\Software Updater Ui => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Ui.exe [2013-09-11] () Task: {64F3DC5A-30A2-42A2-87D6-EE561EF9F054} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1262487600-2457452054-1344347814-1003 => C:\Windows\System32\portabledeviceapi.dll [2009-10-01] (Microsoft Corporation) Task: {654B41A9-4951-4B5D-B32D-D7CB1B14FDDD} - System32\Tasks\Plus-HD-3.8-firefoxinstaller => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe [2013-09-10] (Plus HD) Task: {65BB3F11-164B-4533-B922-CFCDD04E53C1} - System32\Tasks\Plus-HD-3.8-codedownloader => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe [2013-09-10] (Plus HD) Task: {69383281-E741-4E89-BF77-1888D9596C3E} - System32\Tasks\Plus-HD-3.8-chromeinstaller => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe [2013-09-10] (Plus HD) Task: {7D801D62-6807-4350-8956-50DDE3642933} - System32\Tasks\Microsoft\Windows\WindowsBackup\CheckFull => C:\Windows\System32\sdclt.exe [2010-12-14] (Microsoft Corporation) Task: {9AC1140C-D736-4ED3-BBC2-72EE7E3F39B6} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation) Task: {A32949A8-6CAB-4427-8EAA-B36472426A80} - System32\Tasks\Software Updater => C:\Program Files\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2013-08-22] () Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation) Task: {B604910B-3170-4421-95C7-09E0BC33E6DC} - System32\Tasks\Plus-HD-3.8-enabler => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe [2013-09-10] (Plus HD) Task: {B68BE59C-86D9-46E7-A801-039DD5D43FB6} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation) Task: {BCCC4BCE-B10D-452C-A095-517A78A783D9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-11] (Adobe Systems Incorporated) Task: {C40C8C17-647D-4F16-9658-0CE1B6417BCE} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-19] (Microsoft Corp.) Task: {D049D84B-A8EB-4D42-834E-2BBFAEFFC9C0} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2008-01-19] (Microsoft Corporation) Task: {D3EC0383-B081-4F8A-80C6-9CA06DCCDE98} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files\HomeTab\ProtectedSearch.exe [2013-08-13] (Simplygen) Task: {D3F100C9-89A5-4970-9D06-70F53A5AF500} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{E45B73E3-F65C-4065-8CB1-9842E017A373}.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] () Task: {F6E58B79-90A8-40D4-B83C-2B98795CEBA3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\At1.job => C:\Users\Tim\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_HP_rmv.job => C:\Windows\TEMP\{8105C3F2-3726-47BC-8A94-FAB01E9BE307}.exe Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{E45B73E3-F65C-4065-8CB1-9842E017A373}.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Plus-HD-3.8-chromeinstaller.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe Task: C:\Windows\Tasks\Plus-HD-3.8-codedownloader.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe Task: C:\Windows\Tasks\Plus-HD-3.8-enabler.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe Task: C:\Windows\Tasks\Plus-HD-3.8-firefoxinstaller.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe Task: C:\Windows\Tasks\Plus-HD-3.8-updater.job => C:\Program Files\Plus-HD-3.8\Plus-HD-3.8-updater.exe ==================== Loaded Modules (whitelisted) ============= 2008-01-01 06:27 - 2007-12-18 12:31 - 04943872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2007-12-15 10:49 - 2007-11-02 13:27 - 00061440 _____ () C:\Program Files\Softex\OmniPass\SCUREDLL.dll 2013-05-25 02:36 - 2013-05-25 02:36 - 00130736 _____ (Dropbox, Inc.) C:\Users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll 2007-12-15 10:49 - 2007-11-02 13:27 - 00016896 _____ () C:\Program Files\Softex\OmniPass\cryptodll.dll 2007-12-15 10:49 - 2007-11-02 13:36 - 00146512 _____ (Softex Incorporated.) C:\Program Files\Softex\OmniPass\ldapdrv.dll 2007-09-20 15:33 - 2007-09-20 15:33 - 00255272 _____ (Nero AG) C:\Program Files\Nero\Nero8\Nero BackItUp\NBShell.dll 2007-12-15 10:49 - 2007-11-02 13:31 - 01798144 _____ (Softex Inc.) C:\Program Files\Softex\OmniPass\opfolderext.dll 2007-12-15 10:49 - 2007-11-02 13:27 - 00065536 _____ () C:\Program Files\Softex\OmniPass\opfsdll.dll 2007-12-15 10:49 - 2007-11-02 13:28 - 00434176 _____ () C:\Program Files\Softex\OmniPass\userdata.dll 2007-12-15 10:49 - 2007-11-02 13:28 - 01077248 _____ () C:\Program Files\Softex\OmniPass\autheng.dll 2007-12-15 10:49 - 2007-11-02 13:27 - 00013824 _____ () C:\Program Files\Softex\OmniPass\ssplogon.dll 2007-12-15 10:49 - 2007-11-02 13:27 - 00532480 _____ () C:\Program Files\Softex\OmniPass\storeng.dll 2007-09-24 09:10 - 2007-09-24 09:10 - 02106664 _____ (Nero AG) C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll 2007-10-15 10:35 - 2007-10-15 10:35 - 03949864 _____ (Nero AG) C:\Program Files\Common Files\Nero\Shared\NL3\AdvrCntr3.dll 2008-01-01 06:27 - 2007-12-18 12:31 - 00368640 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2008-01-01 06:27 - 2007-12-18 12:31 - 00081920 _____ (NVIDIA Corporation) C:\Windows\system32\NvMcTray.dll 2008-01-01 06:27 - 2007-12-18 12:31 - 00368640 _____ (NVIDIA Corporation) C:\Windows\System32\nvapi.dll 2007-12-15 10:49 - 2007-11-02 13:36 - 00048208 _____ () C:\Program Files\Softex\OmniPass\hdddrv.dll 2007-12-15 10:49 - 2007-11-02 13:30 - 00061440 _____ (Softex Incorporated) C:\Program Files\Softex\OmniPass\cachedrv.dll 2007-12-15 10:49 - 2007-11-02 11:41 - 00042928 _____ (Softex Incorporated) C:\Program Files\Softex\OmniPass\sftxtgp.dll 2007-10-19 07:36 - 2007-10-19 07:36 - 01201152 _____ (AuthenTec, Inc.) C:\Windows\system32\ATSC70.dll 2007-12-15 10:49 - 2007-11-02 13:36 - 00138320 _____ (Softex, Inc.) C:\Program Files\Softex\OmniPass\mstrpwd.dll 2007-11-02 13:36 - 2007-11-02 13:36 - 00625744 _____ (Softex, Inc.) C:\Program Files\Softex\OmniPass\authntec.dll 2007-12-15 10:49 - 2007-11-02 11:40 - 00143420 _____ (Softex Inc.) C:\Program Files\Softex\OmniPass\explorer.ocx 2007-10-17 16:42 - 2007-10-17 16:42 - 00636200 ____N () C:\Program Files\HomeCinema\Power2Go\CLMediaLibrary.dll 2007-10-17 16:42 - 2007-10-17 16:42 - 00013096 ____N () C:\Program Files\HomeCinema\Power2Go\CLMLSvcPS.dll 2006-11-02 14:35 - 2006-11-02 14:35 - 00116736 _____ (Microsoft Corporation) C:\Windows\eHome\ehProxy.dll 2007-10-15 10:15 - 2007-10-15 10:15 - 00064808 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexingServicePS.dll 2007-10-15 10:15 - 2007-10-15 10:15 - 00027432 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvrPS.dll 2007-10-15 10:14 - 2007-10-15 10:14 - 03118376 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMDataServices.dll 2013-02-15 18:19 - 2013-02-15 18:19 - 00204800 _____ (GARMIN Corp.) C:\Program Files\Garmin\ANT Agent\ANT AgentDEU.dll 2013-01-25 16:00 - 2013-01-25 16:00 - 00090112 _____ (Silicon Laboratories, Inc.) C:\Program Files\Garmin\ANT Agent\DSI_SiUSBXp_3_1.DLL 2011-05-17 16:44 - 2011-05-17 16:44 - 00067008 _____ (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusb0.dll 2013-08-01 12:47 - 2013-08-01 12:47 - 00026040 _____ () C:\Program Files\MyTomTom 3\DeviceDetection.dll 2013-08-01 12:47 - 2013-08-01 12:47 - 00074680 _____ () C:\Program Files\MyTomTom 3\TomTomSupporterBase.dll 2012-12-07 11:50 - 2012-12-07 11:50 - 02555392 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Program Files\MyTomTom 3\QtCore4.dll 2013-08-01 12:47 - 2013-08-01 12:47 - 00317880 _____ () C:\Program Files\MyTomTom 3\TomTomSupporterProxy.dll 2012-12-07 11:52 - 2012-12-07 11:52 - 01028096 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Program Files\MyTomTom 3\QtNetwork4.dll 2012-12-07 11:50 - 2012-12-07 11:50 - 00355840 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Program Files\MyTomTom 3\QtXml4.dll 2012-12-07 12:08 - 2012-12-07 12:08 - 08090112 _____ (Digia Plc and/or its subsidiary(-ies)) C:\Program Files\MyTomTom 3\QtGui4.dll 2012-11-14 01:32 - 2012-11-14 01:32 - 03558400 _____ (wxWidgets development team) C:\Users\Tim\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 24978944 _____ () C:\Users\Tim\AppData\Roaming\Dropbox\bin\libcef.dll 2013-03-13 22:48 - 2013-03-13 22:48 - 09956864 _____ (The ICU Project) C:\Users\Tim\AppData\Roaming\Dropbox\bin\icudt.dll 2013-09-10 14:27 - 2013-08-13 08:38 - 00100352 _____ () C:\Program Files\HomeTab\InstallHelper.dll 2013-09-10 14:27 - 2013-08-13 08:38 - 00152136 _____ (Simply Tech Ltd.) C:\Program Files\HomeTab\cinshlpr.dll 2013-09-10 14:27 - 2013-06-27 07:14 - 00923720 _____ () C:\Program Files\HomeTab\System.Data.SQLite.dll 2008-01-01 06:27 - 2007-12-18 12:31 - 00086016 _____ (NVIDIA Corporation) C:\Windows\System32\NVSVC.DLL 2007-10-15 10:15 - 2007-10-15 10:15 - 00279848 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMSQLDB.dll 2007-10-15 10:15 - 2007-10-15 10:15 - 00075048 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMLogCxx.dll 2007-10-23 18:29 - 2007-10-23 18:29 - 00828712 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\log4cxx.dll 2007-10-15 10:14 - 2007-10-15 10:14 - 00738600 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMCoFoundation.dll 2007-10-15 10:15 - 2007-10-15 10:15 - 00173352 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMPluginBase.dll 2007-10-15 10:15 - 2007-10-15 10:15 - 00222504 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMFullTextExtraction.dll 2007-10-15 10:15 - 2007-10-15 10:15 - 00234792 _____ (Nero AG) C:\Program Files\Common Files\Nero\Lib\NMSearchPluginSimilarImages.dll 2007-09-12 09:36 - 2007-08-31 10:18 - 00163840 _____ (Synaptics, Inc.) C:\Windows\system32\SynCOM.dll 2007-09-12 09:36 - 2007-08-31 10:36 - 00147456 _____ (Synaptics, Inc.) C:\Windows\system32\SynTPAPI.dll 2013-09-07 10:35 - 2013-09-02 22:35 - 04053456 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll 2013-09-07 10:35 - 2013-09-02 22:35 - 00410576 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll 2013-09-07 10:34 - 2013-09-02 22:35 - 01604560 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\ffmpegsumo.dll 2013-09-07 10:35 - 2013-09-02 22:35 - 13599184 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (09/11/2013 09:45:24 AM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {ac13bbe9-23ae-4759-bac8-ec99030e7c49} Error: (09/10/2013 11:05:23 PM) (Source: Application Error) (User: ) Description: Fehlerhafte Anwendung helppane.exe, Version 6.0.6001.18000, Zeitstempel 0x4791945e, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x004a4978, Prozess-ID 0x106c, Anwendungsstartzeit helppane.exe0. Error: (07/05/2013 06:53:12 PM) (Source: Application Error) (User: ) Description: Fehlerhafte Anwendung WButton.exe, Version 1.0.8.6, Zeitstempel 0x46e0a8dc, fehlerhaftes Modul kernel32.dll, Version 6.0.6002.18704, Zeitstempel 0x5065ccb6, Ausnahmecode 0xe06d7363, Fehleroffset 0x0003fc16, Prozess-ID 0x260, Anwendungsstartzeit WButton.exe0. Error: (06/30/2013 09:29:53 AM) (Source: Application Error) (User: ) Description: Fehlerhafte Anwendung WinMail.exe, Version 6.0.6001.18000, Zeitstempel 0x47918ed8, fehlerhaftes Modul mshtml.dll, Version 9.0.8112.16476, Zeitstempel 0x5126ee6c, Ausnahmecode 0xc0000005, Fehleroffset 0x001de739, Prozess-ID 0x13c4, Anwendungsstartzeit WinMail.exe0. Error: (06/29/2013 09:50:25 PM) (Source: Microsoft-Windows-RestartManager) (User: Tim-PC) Description: 0C:\Windows\explorer.exeWindows-Explorer041172280 Error: (05/26/2013 08:05:54 PM) (Source: Application Hang) (User: ) Description: Programm PaintDotNet.exe, Version 3.510.4297.28970 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: e38 Anfangszeit: 01ce5a3b76910970 Zeitpunkt der Beendigung: 133 Error: (05/02/2013 07:13:08 PM) (Source: Application Error) (User: ) Description: Fehlerhafte Anwendung Updater.exe, Version 5.10.1.44067, Zeitstempel 0x5000146c, fehlerhaftes Modul unknown, Version 0.0.0.0, Zeitstempel 0x00000000, Ausnahmecode 0xc0000005, Fehleroffset 0x009900c4, Prozess-ID 0xf08, Anwendungsstartzeit Updater.exe0. Error: (05/01/2013 09:53:12 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\TIM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME CINEMA\POWERDVD\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (05/01/2013 09:53:12 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\TIM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME CINEMA\POWERDVD\README.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (05/01/2013 09:53:12 PM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\TIM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME CINEMA\POWERDVD\ONLINE-REGISTRIERUNG.LNK> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (09/11/2013 10:00:15 AM) (Source: Service Control Manager) (User: ) Description: Treiber für parallelen Anschluss%%1058 Error: (09/11/2013 08:58:31 AM) (Source: Service Control Manager) (User: ) Description: Treiber für parallelen Anschluss%%1058 Error: (09/10/2013 10:17:50 PM) (Source: Service Control Manager) (User: ) Description: 30000Microsoft .NET Framework NGEN v4.0.30319_X86 Error: (09/10/2013 10:14:38 PM) (Source: Service Control Manager) (User: ) Description: Treiber für parallelen Anschluss%%1058 Error: (09/10/2013 02:27:33 PM) (Source: Service Control Manager) (User: ) Description: vToolbarUpdater15.5.01 Error: (09/10/2013 10:40:26 AM) (Source: Service Control Manager) (User: ) Description: Treiber für parallelen Anschluss%%1058 Error: (09/10/2013 10:25:17 AM) (Source: Service Control Manager) (User: ) Description: TomTomHOMEService Error: (09/10/2013 09:57:17 AM) (Source: Service Control Manager) (User: ) Description: 30000Microsoft .NET Framework NGEN v4.0.30319_X86 Error: (09/10/2013 09:54:24 AM) (Source: Service Control Manager) (User: ) Description: Treiber für parallelen Anschluss%%1058 Error: (09/09/2013 10:52:09 PM) (Source: Service Control Manager) (User: ) Description: Treiber für parallelen Anschluss%%1058 Microsoft Office Sessions: ========================= Error: (09/11/2013 09:45:24 AM) (Source: VSS)(User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {ac13bbe9-23ae-4759-bac8-ec99030e7c49} Error: (09/10/2013 11:05:23 PM) (Source: Application Error)(User: ) Description: helppane.exe6.0.6001.180004791945eunknown0.0.0.000000000c0000005004a4978106c01ceae694dc6d330 Error: (07/05/2013 06:53:12 PM) (Source: Application Error)(User: ) Description: WButton.exe1.0.8.646e0a8dckernel32.dll6.0.6002.187045065ccb6e06d73630003fc1626001ce799fecf8468b Error: (06/30/2013 09:29:53 AM) (Source: Application Error)(User: ) Description: WinMail.exe6.0.6001.1800047918ed8mshtml.dll9.0.8112.164765126ee6cc0000005001de73913c401ce7563224f7d90 Error: (06/29/2013 09:50:25 PM) (Source: Microsoft-Windows-RestartManager)(User: Tim-PC) Description: 0C:\Windows\explorer.exeWindows-Explorer041172280 Error: (05/26/2013 08:05:54 PM) (Source: Application Hang)(User: ) Description: PaintDotNet.exe3.510.4297.28970e3801ce5a3b76910970133 Error: (05/02/2013 07:13:08 PM) (Source: Application Error)(User: ) Description: Updater.exe5.10.1.440675000146cunknown0.0.0.000000000c0000005009900c4f0801ce4757e6ec74d0 Error: (05/01/2013 09:53:12 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\TIM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME CINEMA\POWERDVD\README.LNK Error: (05/01/2013 09:53:12 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\TIM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME CINEMA\POWERDVD\README.LNK Error: (05/01/2013 09:53:12 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) C:\USERS\TIM\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOME CINEMA\POWERDVD\ONLINE-REGISTRIERUNG.LNK CodeIntegrity Errors: =================================== Date: 2013-01-28 10:35:22.471 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:21.729 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:20.980 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:20.231 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:19.484 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:18.690 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:17.934 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:17.080 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:16.327 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-01-28 10:35:15.526 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Program Files\Softex\OmniPass\scuredll.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 43% Total physical RAM: 3069.69 MB Available physical RAM: 1740.57 MB Total Pagefile: 6345.65 MB Available Pagefile: 4693.42 MB Total Virtual: 2047.88 MB Available Virtual: 1905 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:126.37 GB) (Free:43.12 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:22.66 GB) (Free:12.62 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: 08DB956A) Partition 1: (Not Active) - (Size=23 GB) - (Type=OF Extended) Partition 2: (Active) - (Size=126 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Gruß, Timm |
11.09.2013, 13:06 | #4 | |
/// the machine /// TB-Ausbilder | SoftwareUpdater.UI.exe meldet sich nach StartSo funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.09.2013, 17:12 | #5 |
| SoftwareUpdater.UI.exe meldet sich nach Start Hallo, nach der combofix-Ausführung und dem Neustart meldete sich das Fenster mit der -SoftwareUpdater.UI.exe- wieder. Unter C:/combofix habe ich folgendes gefunden: Code:
ATTFilter ComboFix 13-09-10.03 - Tim 11.09.2013 14:19:53.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1573 [GMT 2:00] ausgeführt von:: C:\Users\Tim\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ich glaube, das vorherige log-file war nicht korrekt, noch einmal probiert, sehe ich jetzt auf dem Bildschirm nach dem Neustart folgendes: Code:
ATTFilter ComboFix 13-09-10.03 - Tim 11.09.2013 17:34:17.2.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.3070.1940 [GMT 2:00] ausgeführt von:: c:\users\Tim\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Vorheriger Suchlauf ------- . C:\install.exe c:\users\Tim\AppData\Local\Google\Chrome\User Data\Default\Preferences c:\users\Tim\AppData\Roaming\convert\convert.exe . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-11 bis 2013-09-11 )))))))))))))))))))))))))))))) . . 2013-09-11 15:48 . 2013-09-11 15:48 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-11 09:54 . 2013-09-11 09:54 -------- d-----w- C:\SoloApp 2013-09-11 09:19 . 2013-09-11 09:19 -------- d-----w- C:\FRST 2013-09-11 09:04 . 2013-09-11 09:52 -------- d-----w- c:\program files\Optimizer Pro 2013-09-11 09:04 . 2013-09-11 09:04 -------- d-----w- c:\users\Tim\AppData\Roaming\DSite 2013-09-10 21:15 . 2013-04-24 01:46 812544 ----a-w- c:\windows\system32\certutil.exe 2013-09-10 21:14 . 2013-04-17 12:30 24576 ----a-w- c:\windows\system32\cryptdlg.dll 2013-09-10 21:14 . 2013-07-08 04:16 992768 ----a-w- c:\windows\system32\crypt32.dll 2013-09-10 21:14 . 2013-07-08 04:16 98304 ----a-w- c:\windows\system32\cryptnet.dll 2013-09-10 21:14 . 2013-07-08 04:16 133120 ----a-w- c:\windows\system32\cryptsvc.dll 2013-09-10 21:05 . 2013-04-09 03:51 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-09-10 21:04 . 2013-04-09 03:52 1218048 ----a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-09-10 21:04 . 2013-04-09 03:51 983552 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-09-10 21:04 . 2013-04-09 03:51 964608 ----a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-09-10 20:29 . 2013-08-19 22:47 7166848 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A69CDF14-9131-479C-976D-07970A675B00}\mpengine.dll 2013-09-10 12:45 . 2013-09-10 12:46 -------- d-----w- c:\users\Tim\AppData\Local\DownloadGuide 2013-09-10 12:31 . 2013-09-10 12:31 -------- d-----w- c:\users\Tim\AppData\Local\Freetec 2013-09-10 12:30 . 2013-09-10 12:31 -------- d-----w- c:\program files\Plus-HD-3.8 2013-09-10 12:29 . 2013-09-10 12:47 -------- d-----w- c:\users\Tim\AppData\Roaming\Windows Net Data 2013-09-10 12:27 . 2013-09-10 12:27 -------- d-----w- c:\users\Tim\AppData\Roaming\SimplyTech 2013-09-10 12:27 . 2013-08-13 06:38 32328 ----a-w- c:\windows\Launcher.exe 2013-09-10 12:27 . 2013-09-10 12:27 -------- d-----w- c:\program files\HomeTab 2013-09-10 12:27 . 2013-09-10 12:27 -------- d-----w- c:\users\Tim\AppData\Roaming\HomeTab 2013-09-10 12:24 . 2013-09-10 12:26 -------- d-----w- c:\program files\SoftwareUpdater 2013-09-10 08:44 . 2013-09-10 08:44 -------- d-----w- c:\program files\MyTomTom 3 2013-09-10 08:26 . 2013-09-10 08:44 -------- d-----w- c:\users\Tim\AppData\Local\TomTom 2013-09-10 08:26 . 2013-09-10 08:26 -------- d-----w- c:\users\Tim\AppData\Roaming\TomTom 2013-09-10 08:25 . 2013-09-10 08:25 -------- d-----w- c:\program files\TomTom HOME 2 2013-09-10 08:23 . 2013-09-10 08:44 -------- d-----w- c:\program files\TomTom International B.V 2013-09-10 08:22 . 2013-09-10 08:22 -------- d-----w- c:\users\Tim\AppData\Local\Downloaded Installations . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-10 22:24 . 2012-07-15 14:42 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-09-10 22:24 . 2012-07-15 14:42 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-09-07 08:13 . 2013-08-05 19:28 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-09-07 08:13 . 2013-08-05 19:28 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2013-08-15 18:09 . 2012-08-30 20:16 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-08-07 02:22 . 2009-10-23 09:33 238872 ------w- c:\windows\system32\MpSigStub.exe 2013-08-05 19:22 . 2013-08-05 19:28 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-08-02 04:09 . 2013-09-10 21:15 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-25 02:26 . 2013-09-10 21:32 1129472 ----a-w- c:\windows\system32\wininet.dll 2013-07-25 02:23 . 2013-09-10 21:32 420864 ----a-w- c:\windows\system32\vbscript.dll 2013-07-25 02:22 . 2013-09-10 21:32 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2013-07-17 19:41 . 2013-09-10 21:14 2048 ----a-w- c:\windows\system32\tzres.dll 2013-07-10 09:47 . 2013-09-10 21:15 783360 ----a-w- c:\windows\system32\rpcrt4.dll 2013-07-09 12:10 . 2013-09-10 21:15 1205168 ----a-w- c:\windows\system32\ntdll.dll 2013-07-08 04:55 . 2013-09-10 21:15 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-07-08 04:55 . 2013-09-10 21:15 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-07-08 04:20 . 2013-09-10 21:14 172544 ----a-w- c:\windows\system32\wintrust.dll 2009-09-25 16:41 . 2012-09-07 23:06 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-09-25 16:41 . 2012-09-07 23:06 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-07-26 20:30 12240 ----a-w- c:\program files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2013-08-15 18:09 3122864 ----a-w- c:\program files\AVG Secure Search\15.5.0.2\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\15.5.0.2\AVG Secure Search_toolbar.dll" [2013-08-15 3122864] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-07-26 12240] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2012-07-13 17418928] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-15 202024] "ANT Agent"="c:\program files\Garmin\ANT Agent\ANT Agent.exe" [2013-02-15 14731776] "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2013-07-02 248208] "MyTomTomSA.exe"="c:\program files\MyTomTom 3\MyTomTomSA.exe" [2013-08-01 458680] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-08-31 102400] "PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208] "RtHDVCpl"="RtHDVCpl.exe" [2007-10-31 4702208] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712] "Skytel"="Skytel.exe" [2007-10-11 1826816] "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-18 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-18 8501792] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-18 81920] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "UCam_Menu"="c:\program files\HomeCinema\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504] "toolbar_eula_launcher"="c:\program files\GoogleEULA\EULALauncher.exe" [2007-02-09 16896] "RemoteControl"="c:\program files\HomeCinema\PowerDVD\PDVDServ.exe" [2007-02-09 71216] "OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-11-02 2564096] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "LanguageShortcut"="c:\program files\HomeCinema\PowerDVD\Language\Language.exe" [2007-01-08 52256] "CLMLServer"="c:\program files\HomeCinema\Power2Go\CLMLSvc.exe" [2007-10-17 128296] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-07 347192] "ApnTBMon"="c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-07-26 1558480] . c:\users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Tim\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-8-3 28057256] net.lnk - c:\users\Tim\AppData\Roaming\Windows Net Data\net.exe [2013-9-10 709120] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Philips GoGear Spark Device Manager.lnk - c:\program files\Philips\GoGear Spark Device Manager\main.exe [2009-10-31 7975489] WISO Mein Steuer-Sparbuch heute.lnk - c:\program files\WISO\Steuersoftware 2011\mshaktuell.exe [2012-7-17 1302680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-09-07 08:21 1177552 ----a-w- c:\program files\Google\Chrome\Application\29.0.1547.66\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 22:24] . 2013-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-02 12:15] . 2013-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-12-02 12:15] . 2013-09-11 c:\windows\Tasks\Plus-HD-3.8-chromeinstaller.job - c:\program files\Plus-HD-3.8\Plus-HD-3.8-chromeinstaller.exe [2013-09-10 12:30] . 2013-09-11 c:\windows\Tasks\Plus-HD-3.8-codedownloader.job - c:\program files\Plus-HD-3.8\Plus-HD-3.8-codedownloader.exe [2013-09-10 12:30] . 2013-09-11 c:\windows\Tasks\Plus-HD-3.8-enabler.job - c:\program files\Plus-HD-3.8\Plus-HD-3.8-enabler.exe [2013-09-10 12:31] . 2013-09-11 c:\windows\Tasks\Plus-HD-3.8-firefoxinstaller.job - c:\program files\Plus-HD-3.8\Plus-HD-3.8-firefoxinstaller.exe [2013-09-10 12:30] . 2013-09-11 c:\windows\Tasks\Plus-HD-3.8-updater.job - c:\program files\Plus-HD-3.8\Plus-HD-3.8-updater.exe [2013-09-10 12:31] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = about:newtab mStart Page = about:newtab IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-25/4 LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 192.168.178.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.3.0/GarminAxControl_32.CAB . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM-Run-HotKeysCmds - c:\windows\system32\hkcmd.exe HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe SafeBoot-WudfPf SafeBoot-WudfRd . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net Rootkit scan 2013-09-11 17:55 Windows 6.0.6002 Service Pack 2 NTFS . Scanne versteckte Prozesse... . Scanne versteckte Autostarteinträge... . Scanne versteckte Dateien... . Scan erfolgreich abgeschlossen versteckte Dateien: 0 . ************************************************************************** . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1262487600-2457452054-1344347814-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{a25e7121-3dd8-41b3-855b-756c5bc45449}] @Denied: (A 2) (Administrators) @Denied: (A 2) (S-1-5-21-1262487600-2457452054-1344347814-1003) "Flags"=dword:00000400 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000001 "MSCurrentCountry"=dword:000000b5 . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- . - - - - - - - > 'Explorer.exe'(6016) c:\users\Tim\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files\Softex\OmniPass\OmniServ.exe c:\program files\Avira\AntiVir Desktop\sched.exe c:\windows\system32\agrsmsvc.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\AskPartnerNetwork\Toolbar\apnmcp.exe c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe c:\program files\HomeTab\ProtectedSearch.exe c:\program files\CDBurnerXP\NMSAccessU.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Sceneo\AbsolutTV\Services\PVR\PVRService.exe c:\program files\TomTom HOME 2\TomTomHOMEService.exe c:\windows\System32\WUDFHost.exe c:\program files\Softex\OmniPass\opvapp.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\program files\Avira\AntiVir Desktop\avmailc.exe c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE c:\windows\system32\conime.exe c:\windows\RtHDVCpl.exe c:\windows\System32\rundll32.exe c:\program files\Synaptics\SynTP\SynTPEnh.exe c:\windows\System32\rundll32.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\ehome\ehmsas.exe c:\program files\Common Files\Nero\Lib\NMIndexingService.exe c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe c:\users\Tim\AppData\Roaming\Dropbox\bin\Dropbox.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Zeit der Fertigstellung: 2013-09-11 18:03:41 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2013-09-11 16:03 . Vor Suchlauf: 12 Verzeichnis(se), 52.158.664.704 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 51.765.899.264 Bytes frei . - - End Of File - - A2977F90B734DD82B93A9CEE63AFA41B 5C616939100B85E558DA92B899A0FC36 |
11.09.2013, 20:04 | #6 |
/// the machine /// TB-Ausbilder | SoftwareUpdater.UI.exe meldet sich nach Start Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> SoftwareUpdater.UI.exe meldet sich nach Start |
11.09.2013, 22:00 | #7 |
| SoftwareUpdater.UI.exe meldet sich nach Start Dankeschön Schrauber für die Anleitung, ich mache erst mal 2 Wo. Urlaub und werde mich dann wieder mit diesem Klapperkasten auseinandersetzen. :-) Gruß, Timm |
12.09.2013, 09:53 | #8 |
/// the machine /// TB-Ausbilder | SoftwareUpdater.UI.exe meldet sich nach Start ok.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu SoftwareUpdater.UI.exe meldet sich nach Start |
avira, downloads, ebook, hallo zusammen, hilfe, laufe, laufen, löschen, melde, meldet, nach start, notebook, nutze, problem, programm, rechners, rechnerstart, schädling, softwareupdater.ui.exe, start, updates, versuche, virenprogramm, vista, zusammen |