|
Log-Analyse und Auswertung: Probleme mit PUP Virus-68 infizierte ObjekteWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.09.2013, 16:44 | #1 |
| Probleme mit PUP Virus-68 infizierte Objekte Hallo, ich habe heute einen Virenscan mit Malwarebytes durchgeführt und dabei wurden 68 infizierte Objekte gefunden! Da ich mich leider so gar nicht auskenne und jetzt etwas verzweifelt bin wollte ich fragen, ob mir hier jemand helfen kann? Ich habe diese 4 Schritte durchgeführt und würde jetzt hier die logfiles posten! Ich hoffe sehr, dass ihr mir weiterhelfen könnt und danke euch schon im voraus viel, vielmals!!!!!! Viele Grüße Lu Logfile Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.16.05 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16686 LU :: LU-VAIO [Administrator] 16.09.2013 17:10:33 MBAM-log-2013-09-16 (17-26-56).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 234134 Laufzeit: 15 Minute(n), 54 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 31 HKCR\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\escort.escortIEPane.1 (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\escort.escortIEPane (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\delta.deltaHlpr.1 (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\delta.deltaHlpr (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\esrv.deltaESrvc.1 (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\esrv.deltaESrvc (PUP.Optional.Delta) -> Keine Aktion durchgeführt. HKCR\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\delta.deltadskBnd.1 (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\delta.deltadskBnd (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\Typelib\{4599D05A-D545-4069-BB42-5895B4EAE05B} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\Interface\{1231839B-064E-4788-B865-465A1B5266FD} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\DELTA\DELTA (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCU\Software\BabSolution\Updater (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\delta.deltaappCore.1 (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\delta.deltaappCore (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKCR\d (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\delta (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. Infizierte Registrierungswerte: 4 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Daten: Delta Toolbar -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} (PUP.Optional.Delta.A) -> Daten: -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Delta\Delta|tlbrSrchUrl (PUP.Optional.Delta.A) -> Daten: -> Keine Aktion durchgeführt. HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0L1N1H2O1S -> Keine Aktion durchgeführt. Infizierte Dateiobjekte der Registrierung: 1 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.StartPage) -> Bösartig: (hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=54B3B2004EB6803E&affID=119357&tsp=5007) Gut: (hxxp://www.google.com) -> Keine Aktion durchgeführt. Infizierte Verzeichnisse: 9 C:\Users\LU\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\CR (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\bh (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 23 C:\Program Files\Delta\delta\1.8.24.6\bh\delta.dll (PUP.Optional.Delta) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\deltasrv.exe (PUP.Optional.Delta) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\deltaTlbr.dll (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared\BabMaint.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\DSearchLink.exe (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\is357113909\2038421_stp\DeltaTB.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\CR\Delta.crx (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared\BUSolution.dll (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared\Delta.ico (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared\GUninstaller.exe (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared\SetupParams.ini (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Roaming\BabSolution\Shared\sqlite3.dll (PUP.Optional.BabSolution.A) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\deltaApp.dll (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\deltaEng.dll (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\GUninstaller.exe (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Program Files\Delta\delta\1.8.24.6\uninstall.exe (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:46 on 16/09/2013 (LU) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 Ran by LU (administrator) on LU-VAIO on 16-09-2013 16:48:39 Running from C:\Users\LU\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (T-Systems Enterprise Services GmbH) C:\Program Files\DSL-Manager\DslMgr.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (T-Systems Enterprise Services GmbH) C:\Program Files\DSL-Manager\DslMgrSvc.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe () C:\Program Files\Opera\16.0.1196.73\opera_crashreporter.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe (Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-11-01] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-06] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1873192 2010-11-01] (Synaptics Incorporated) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM\...\Run: [] - [x] HKLM\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM\...\Runonce: [Del2051038] - cmd.exe /Q /D /c del "C:\Users\LU\AppData\Local\Temp\0.del" HKCU\...\Runonce: [Del2051038] - cmd.exe /Q /D /c del "C:\Users\LU\AppData\Local\Temp\0.del" MountPoints2: {4ecb6f37-63e1-11e1-bd57-001e101f1ed9} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {5939391b-63e0-11e1-ac1a-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {59393945-63e0-11e1-ac1a-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {d9a1b83d-c745-11e0-8bc0-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {d9a1b88b-c745-11e0-8bc0-9a004eb6803e} - D:\setup_vmc_lite.exe /checkApplicationPresence Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\LU\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=54B3B2004EB6803E&affID=119357&tsp=5007 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sony.eu/vaioportal URLSearchHook: (No Name) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No File SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {07DF276A-110B-424B-972A-18A3018F1359} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=54B3B2004EB6803E&affID=119357&tsp=5007 SearchScopes: HKCU - {5597BEDF-ACD2-416D-BDDE-AF4A1994DC47} URL = hxxp://de.shopping.com/?linkin_id=8056363 SearchScopes: HKCU - {C58A25CA-DFD9-450D-BE35-890D5EDA37BC} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-21/4?satitle={searchTerms} SearchScopes: HKCU - {F1931C3C-1C14-41C9-8718-454578148D9E} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2613550 BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files\Delta\delta\1.8.24.6\bh\delta.dll (Delta-search.com) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files\Delta\delta\1.8.24.6\deltaTlbr.dll (Delta-search.com) Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @checkpoint.com/FFApi - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll No File FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} ========================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [284160 2011-01-06] (Advanced Micro Devices, Inc.) R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [140224 2010-06-17] (Advanced Micro Devices) R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-09] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [189048 2011-01-29] (Sony Corporation) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) R3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [64704 2011-03-05] (Sony Corporation) S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [652016 2011-05-24] (Sony Corporation) S3 VcmINSMgr; C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [385336 2011-02-18] (Sony Corporation) R3 VCService; C:\Program Files\Sony\VAIO Care\VCService.exe [44736 2011-02-14] (Sony Corporation) R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [869304 2011-08-12] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1013808 2013-03-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R0 amd_sata; C:\Windows\System32\drivers\amd_sata.sys [64128 2011-02-17] (Advanced Micro Devices) R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [32384 2011-02-17] (Advanced Micro Devices) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17408 2009-05-26] (ArcSoft, Inc.) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [102416 2011-02-15] (ATI Technologies, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-16] (Avira Operations GmbH & Co. KG) R3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [297000 2010-11-01] (Broadcom Corporation.) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [102912 2009-06-29] (Huawei Technologies Co., Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-16] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-16 16:48 - 2013-09-16 16:48 - 00000000 ____D C:\FRST 2013-09-16 16:46 - 2013-09-16 16:47 - 00000466 _____ C:\Users\LU\Desktop\defogger_disable.log 2013-09-16 16:46 - 2013-09-16 16:46 - 00000000 _____ C:\Users\LU\defogger_reenable 2013-09-16 16:44 - 2013-09-16 16:45 - 01084083 _____ (Farbar) C:\Users\LU\Desktop\FRST.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00377856 _____ C:\Users\LU\Desktop\gmer_2.1.19163.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00050477 _____ C:\Users\LU\Desktop\Defogger.exe 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\Users\LU\AppData\Roaming\Babylon 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\Users\LU\AppData\Roaming\BabSolution 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\ProgramData\Babylon 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\Program Files\Delta 2013-09-16 16:41 - 2013-09-16 16:41 - 00678784 _____ C:\Users\LU\Downloads\ZipOpenerSetup.exe 2013-09-16 16:41 - 2013-09-16 16:41 - 00000280 _____ C:\Windows\Tasks\DigitalSite.job 2013-09-16 16:41 - 2013-09-16 16:41 - 00000000 ____D C:\Users\LU\AppData\Roaming\DigitalSite 2013-09-16 15:58 - 2013-09-16 15:58 - 97787879 _____ C:\Windows\system32\랅觴ᰴ] 2013-09-13 12:11 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-13 12:11 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-13 12:11 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-13 12:11 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-13 12:11 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-13 12:11 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-13 09:35 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-13 09:35 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-13 09:35 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-13 09:34 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-13 09:34 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-13 09:34 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-13 09:34 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-13 09:34 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 23:36 - 2013-09-12 23:36 - 97412816 _____ C:\Windows\system32\圄抒ᰴ` 2013-09-11 00:29 - 2013-09-11 00:29 - 97004533 _____ C:\Windows\system32\冐ᰴi 2013-09-10 20:04 - 2013-09-10 20:04 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe_Systems_Incorporate 2013-09-10 19:52 - 2013-09-10 20:36 - 00000000 ____D C:\Users\LU\Documents\My Digital Editions 2013-09-10 19:52 - 2013-09-10 19:52 - 00002162 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk 2013-09-10 19:50 - 2013-09-10 19:50 - 05889712 _____ (Adobe Systems Incorporated) C:\Users\LU\Downloads\ADE_2.0_Installer.exe 2013-09-10 19:46 - 2013-09-10 19:46 - 00001196 _____ C:\Users\LU\Downloads\Russendisko.acsm 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\ProgramData\T-Online 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\Program Files\Common Files\T-Com 2013-09-09 12:05 - 2007-09-12 17:24 - 00026816 _____ (Printing Communications Assoc., Inc. (PCAUSA)) C:\Windows\system32\Drivers\DslTestSp5.sys 2013-09-09 12:03 - 2013-09-09 12:03 - 00000000 ____D C:\Program Files\DSL-Manager 2013-09-09 12:03 - 2007-08-01 14:49 - 00016448 _____ (T-Systems Enterprise Services GmbH) C:\Windows\system32\Drivers\dslmnlwf.sys 2013-09-09 12:02 - 2013-09-09 12:02 - 04118552 _____ (T-Online ) C:\Users\LU\Downloads\DSL-Manager_6.9.exe 2013-08-31 23:47 - 2013-08-31 23:47 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular (1).xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020892 _____ C:\Users\LU\Downloads\Marathonstaffeln Wechselpunktformular.xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular.xlsx 2013-08-30 10:10 - 2013-09-09 11:12 - 00000000 ____D C:\Program Files\Opera 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Roaming\Opera Software 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Local\Opera Software 2013-08-30 10:07 - 2013-08-30 10:09 - 32058408 _____ (Opera Software ASA) C:\Users\LU\Downloads\Opera_16.0.1196.62_Setup.exe 2013-08-30 10:06 - 2013-08-30 10:06 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-29 12:22 - 2013-08-29 14:59 - 94605346 _____ C:\Windows\system32\旹柳ᰴ] 2013-08-20 17:16 - 2013-08-20 17:16 - 99562272 _____ C:\Windows\system32\髦ᇣᰴg 2013-08-20 16:58 - 2013-08-20 16:58 - 06663848 _____ C:\Users\LU\Downloads\Niederschlag.zip 2013-08-18 17:01 - 2013-08-18 17:03 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung(1).zip 2013-08-18 17:00 - 2013-08-18 17:01 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung.zip 2013-08-18 13:17 - 2013-09-16 16:42 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-16 16:48 - 2013-09-16 16:48 - 00000000 ____D C:\FRST 2013-09-16 16:47 - 2013-09-16 16:46 - 00000466 _____ C:\Users\LU\Desktop\defogger_disable.log 2013-09-16 16:46 - 2013-09-16 16:46 - 00000000 _____ C:\Users\LU\defogger_reenable 2013-09-16 16:46 - 2011-08-12 13:31 - 00000000 ____D C:\Users\LU 2013-09-16 16:45 - 2013-09-16 16:44 - 01084083 _____ (Farbar) C:\Users\LU\Desktop\FRST.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00377856 _____ C:\Users\LU\Desktop\gmer_2.1.19163.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00050477 _____ C:\Users\LU\Desktop\Defogger.exe 2013-09-16 16:44 - 2013-07-11 19:06 - 00002856 _____ C:\Windows\setupact.log 2013-09-16 16:44 - 2011-04-28 19:03 - 02014276 _____ C:\Windows\WindowsUpdate.log 2013-09-16 16:44 - 2009-07-14 06:34 - 00020400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-16 16:44 - 2009-07-14 06:34 - 00020400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\Users\LU\AppData\Roaming\Babylon 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\Users\LU\AppData\Roaming\BabSolution 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\ProgramData\Babylon 2013-09-16 16:42 - 2013-09-16 16:42 - 00000000 ____D C:\Program Files\Delta 2013-09-16 16:42 - 2013-08-18 13:17 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-16 16:41 - 2013-09-16 16:41 - 00678784 _____ C:\Users\LU\Downloads\ZipOpenerSetup.exe 2013-09-16 16:41 - 2013-09-16 16:41 - 00000280 _____ C:\Windows\Tasks\DigitalSite.job 2013-09-16 16:41 - 2013-09-16 16:41 - 00000000 ____D C:\Users\LU\AppData\Roaming\DigitalSite 2013-09-16 16:37 - 2013-01-20 13:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-16 16:25 - 2011-08-12 15:34 - 00000000 ____D C:\Users\LU\AppData\Roaming\Mozilla 2013-09-16 16:16 - 2010-11-20 23:01 - 01684336 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-16 16:08 - 2012-06-10 10:39 - 00001086 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-16 16:08 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-16 16:06 - 2011-08-12 13:38 - 00000000 ____D C:\Windows\pss 2013-09-16 15:58 - 2013-09-16 15:58 - 97787879 _____ C:\Windows\system32\랅觴ᰴ] 2013-09-16 15:57 - 2013-04-01 16:57 - 00000000 ___RD C:\Users\LU\Dropbox 2013-09-16 15:57 - 2013-04-01 16:45 - 00000000 ____D C:\Users\LU\AppData\Roaming\Dropbox 2013-09-15 20:51 - 2012-06-10 10:39 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-15 15:18 - 2011-11-05 12:00 - 00079548 _____ C:\test.xml 2013-09-13 16:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-13 14:36 - 2009-07-14 06:33 - 00435144 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-13 14:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-13 12:27 - 2011-08-12 15:20 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-13 12:04 - 2013-07-24 17:10 - 00000000 ____D C:\Windows\system32\MRT 2013-09-13 12:00 - 2011-10-06 11:55 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-13 11:37 - 2012-05-26 09:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-13 11:37 - 2011-08-28 10:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-12 23:36 - 2013-09-12 23:36 - 97412816 _____ C:\Windows\system32\圄抒ᰴ` 2013-09-11 00:29 - 2013-09-11 00:29 - 97004533 _____ C:\Windows\system32\冐ᰴi 2013-09-10 20:36 - 2013-09-10 19:52 - 00000000 ____D C:\Users\LU\Documents\My Digital Editions 2013-09-10 20:04 - 2013-09-10 20:04 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe_Systems_Incorporate 2013-09-10 19:52 - 2013-09-10 19:52 - 00002162 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk 2013-09-10 19:52 - 2011-04-28 20:01 - 00000000 ____D C:\Program Files\Adobe 2013-09-10 19:50 - 2013-09-10 19:50 - 05889712 _____ (Adobe Systems Incorporated) C:\Users\LU\Downloads\ADE_2.0_Installer.exe 2013-09-10 19:46 - 2013-09-10 19:46 - 00001196 _____ C:\Users\LU\Downloads\Russendisko.acsm 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\ProgramData\T-Online 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\Program Files\Common Files\T-Com 2013-09-09 12:03 - 2013-09-09 12:03 - 00000000 ____D C:\Program Files\DSL-Manager 2013-09-09 12:03 - 2011-04-28 19:15 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-09-09 12:02 - 2013-09-09 12:02 - 04118552 _____ (T-Online ) C:\Users\LU\Downloads\DSL-Manager_6.9.exe 2013-09-09 11:12 - 2013-08-30 10:10 - 00000000 ____D C:\Program Files\Opera 2013-09-09 11:07 - 2013-08-16 16:31 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-03 09:20 - 2013-06-24 10:38 - 00000000 ____D C:\Users\LU\Desktop\Dokumente 2013-08-31 23:47 - 2013-08-31 23:47 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular (1).xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020892 _____ C:\Users\LU\Downloads\Marathonstaffeln Wechselpunktformular.xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular.xlsx 2013-08-30 10:42 - 2013-07-11 19:05 - 00086294 _____ C:\Windows\PFRO.log 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Roaming\Opera Software 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Local\Opera Software 2013-08-30 10:09 - 2013-08-30 10:07 - 32058408 _____ (Opera Software ASA) C:\Users\LU\Downloads\Opera_16.0.1196.62_Setup.exe 2013-08-30 10:07 - 2011-08-13 18:18 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe 2013-08-30 10:06 - 2013-08-30 10:06 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-30 10:06 - 2011-10-07 14:05 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-08-30 10:06 - 2011-04-28 20:01 - 00000000 ____D C:\ProgramData\Adobe 2013-08-29 14:59 - 2013-08-29 12:22 - 94605346 _____ C:\Windows\system32\旹柳ᰴ] 2013-08-20 17:16 - 2013-08-20 17:16 - 99562272 _____ C:\Windows\system32\髦ᇣᰴg 2013-08-20 16:58 - 2013-08-20 16:58 - 06663848 _____ C:\Users\LU\Downloads\Niederschlag.zip 2013-08-20 11:27 - 2013-08-16 16:35 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 11:27 - 2013-08-16 16:31 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-18 18:02 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-08-18 17:56 - 2010-11-20 22:57 - 00000000 ____D C:\Users\Administrator 2013-08-18 17:56 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-08-18 17:03 - 2013-08-18 17:01 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung(1).zip 2013-08-18 17:01 - 2013-08-18 17:00 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung.zip 2013-08-18 12:25 - 2011-02-11 02:15 - 00000000 ____D C:\Windows\Panther ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-31 21:49 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-09-2013 Ran by LU at 2013-09-16 16:50:09 Running from C:\Users\LU\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= ActiveX контрола на Windows Live Mesh за отдалечени връзки (Version: 15.4.5722.2) ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (Version: 15.4.5722.2) Adobe AIR (Version: 2.5.1.17730) Adobe Digital Editions 2.0 (Version: 2.0.1) Adobe Flash Player 11 ActiveX (Version: 11.8.800.174) Adobe Flash Player 11 Plugin (Version: 11.8.800.168) Adobe Reader XI (11.0.04) - Deutsch (Version: 11.0.04) Amazon MP3-Downloader 1.0.17 (Version: 1.0.17) AMD Fuel (Version: 2011.0106.1408.25281) ArcSoft Magic-i Visual Effects 2 (Version: 2.0.1.142) ArcSoft WebCam Companion 4 (Version: 4.0.21.392) Atheros WiFi Driver Installation (Version: 3.0) ATI Catalyst Install Manager (Version: 3.0.804.0) Avira Antivirus Premium (Version: 13.0.0.4052) Catalyst Control Center - Branding (Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (Version: 2011.0106.1408.25281) Catalyst Control Center Localization All (Version: 2011.0106.1408.25281) Catalyst Control Center Profiles Mobile (Version: 2011.0106.1408.25281) CCC Help Chinese Standard (Version: 2011.0106.1407.25281) CCC Help Chinese Traditional (Version: 2011.0106.1407.25281) CCC Help Czech (Version: 2011.0106.1407.25281) CCC Help Danish (Version: 2011.0106.1407.25281) CCC Help Dutch (Version: 2011.0106.1407.25281) CCC Help English (Version: 2011.0106.1407.25281) CCC Help Finnish (Version: 2011.0106.1407.25281) CCC Help French (Version: 2011.0106.1407.25281) CCC Help German (Version: 2011.0106.1407.25281) CCC Help Greek (Version: 2011.0106.1407.25281) CCC Help Hungarian (Version: 2011.0106.1407.25281) CCC Help Italian (Version: 2011.0106.1407.25281) CCC Help Japanese (Version: 2011.0106.1407.25281) CCC Help Korean (Version: 2011.0106.1407.25281) CCC Help Norwegian (Version: 2011.0106.1407.25281) CCC Help Polish (Version: 2011.0106.1407.25281) CCC Help Portuguese (Version: 2011.0106.1407.25281) CCC Help Russian (Version: 2011.0106.1407.25281) CCC Help Spanish (Version: 2011.0106.1407.25281) CCC Help Swedish (Version: 2011.0106.1407.25281) CCC Help Thai (Version: 2011.0106.1407.25281) ccc-core-static (Version: 2011.0106.1408.25281) ccc-utility (Version: 2011.0106.1408.25281) CCleaner (Version: 4.03) Control ActiveX Windows Live Mesh pentru conexiuni la distanță (Version: 15.4.5722.2) Contrôle ActiveX Windows Live Mesh pour connexions à distance (Version: 15.4.5722.2) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (Version: 15.4.5722.2) D3DX10 (Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Delta Chrome Toolbar Delta toolbar (Version: 1.8.24.6) Dropbox (HKCU Version: 2.0.22) DSL-Manager Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (Version: 15.4.5722.2) Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922) Galeria fotografii usługi Windows Live (Version: 15.4.3502.0922) Galerie de photos Windows Live (Version: 15.4.3502.0922) Galerie foto Windows Live (Version: 15.4.3502.0922) Google Earth Plug-in (Version: 7.1.1.1888) Google Update Helper (Version: 1.3.21.153) HP Officejet 6500 E710n-z - Grundlegende Software für das Gerät (Version: 22.50.231.0) HP Officejet 6500 E710n-z Hilfe (Version: 140.0.2.2) HP Update (Version: 5.002.006.003) I.R.I.S. OCR (Version: 12.3.4.0) Java Auto Updater (Version: 2.0.2.4) Java(TM) 6 Update 22 (Version: 6.0.220) Junk Mail filter update (Version: 15.4.3502.0922) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Media Gallery (Version: 1.5.0.16020) Mesh Runtime (Version: 15.4.5722.2) MFC RunTime files (Version: 1.0.0) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MIKSOFT Mobile AMR converter MSVCRT (Version: 15.4.2862.0708) MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) Opera Stable 16.0.1196.73 (Version: 16.0.1196.73) Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (Version: 15.4.5722.2) Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (Version: 15.4.5722.2) PDF24 Creator 5.4.0 PMB (Version: 5.5.02.12220) PMB VAIO Edition Plug-in (Version: 1.5.00.02250) PMB VAIO Edition Plug-in (Version: 1.5.00.04010) Poczta usługi Windows Live (Version: 15.4.3502.0922) Podstawowe programy Windows Live (Version: 15.4.3502.0922) Qualcomm Atheros Direct Connect (Version: 3.0) Raccolta foto di Windows Live (Version: 15.4.3502.0922) Realtek High Definition Audio Driver (Version: 6.0.1.6167) Realtek USB 2.0 Card Reader (Version: 6.1.7600.30127) Remote Keyboard (Version: 1.1.1.03020) Remote Play with PlayStation 3 (Version: 1.1.0.15070) Skype Click to Call (Version: 6.3.11079) Skype™ 5.10 (Version: 5.10.116) SSLx86 (Version: 1.0.0) Synaptics Pointing Device Driver (Version: 15.1.9.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (Version: 1) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition Update for Zip Opener Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (Version: 15.4.5722.2) VAIO - Media Gallery (Version: 1.5.0.16020) VAIO - PMB VAIO Edition Guide (Version: 1.5.00.02250) VAIO - PMB VAIO Edition Plug-in (Version: 1.5.00.04060) VAIO - Remote Play mit PlayStation®3 (Version: 1.1.0.15070) VAIO - Remote-Tastatur (Version: 1.0.1.03020) VAIO Care (Version: 6.4.1.05290) VAIO Control Center (Version: 4.5.0.03040) VAIO Data Restore Tool (Version: 1.6.0.13140) VAIO Easy Connect (Version: 1.1.2.01120) VAIO Event Service (Version: 5.5.0.03040) VAIO Gate (Version: 2.4.1.09230) VAIO Gate Default (Version: 2.4.0.03240) VAIO Hardware Diagnostics (Version: 4.2.0.14280) VAIO Hero Screensaver - Summer 2011 Screensaver VAIO Improvement (Version: 1.0.0.14150) VAIO Improvement Validation (Version: 1.0.4.01190) VAIO Sample Contents (Version: 1.4.2.09010) VAIO Smart Network (Version: 3.8.0.08120) VAIO Update (Version: 6.1.1.10250) VAIO-Handbuch (Version: 1.3.0.02180) VAIO-Support für Übertragungen (Version: 1.4.0.14230) VC 9.0 Runtime (Version: 1.0.0) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0) VCCx86 (Version: 1.0.0) VESx86 (Version: 1.0.0) VIx86 (Version: 1.0.0) VLC media player 1.1.11 (Version: 1.1.11) VSNx86 (Version: 1.0.0) VU5x86 (Version: 1.1.0) VWSTx86 (Version: 1.0.0) WIDCOMM Bluetooth Software (Version: 6.3.0.6300) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3508.1109) Windows Live Fotogaléria (Version: 15.4.3502.0922) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live Fotogalleri (Version: 15.4.3502.0922) Windows Live Fotoğraf Galerisi (Version: 15.4.3502.0922) Windows Live Fotótár (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Mail (Version: 15.4.3502.0922) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (Version: 15.4.5722.2) Windows Live Mesh (Version: 15.4.3502.0922) Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2) Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (Version: 15.4.5722.2) Windows Live Mesh ActiveX-objekt til fjernforbindelser (Version: 15.4.5722.2) Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (Version: 15.4.5722.2) Windows Live Meshin etäyhteyksien ActiveX-komponentti (Version: 15.4.5722.2) Windows Live Messenger (Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live Remote Client (Version: 15.4.5722.2) Windows Live Remote Client Resources (Version: 15.4.5722.2) Windows Live Remote Service (Version: 15.4.5722.2) Windows Live Remote Service Resources (Version: 15.4.5722.2) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live Temel Parçalar (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) Windows Live Writer (Version: 15.4.3502.0922) Windows Live Writer Resources (Version: 15.4.3502.0922) Windows Liven asennustyökalu (Version: 15.4.3502.0922) Windows Liven sähköposti (Version: 15.4.3502.0922) Windows Liven valokuvavalikoima (Version: 15.4.3502.0922) WMV9/VC-1 Video Playback (Version: 1.0.60106.1413) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (Version: 15.4.5722.2) Συλλογή φωτογραφιών του Windows Live (Version: 15.4.3502.0922) Елемент керування Windows Live Mesh ActiveX для віддалених підключень (Version: 15.4.5722.2) Основи Windows Live (Version: 15.4.3502.0922) Основные компоненты Windows Live (Version: 15.4.3502.0922) Почта Windows Live (Version: 15.4.3502.0922) Фотоальбом Windows Live (Version: 15.4.3502.0922) Фотогалерия на Windows Live (Version: 15.4.3502.0922) Фотоколекція Windows Live (Version: 15.4.3502.0922) Элемент управления Windows Live Mesh ActiveX для удаленных подключений (Version: 15.4.5722.2) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started Task: {0EE0B7FD-C3A5-47F9-A36C-9751289BDD86} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {31D74C35-8013-4896-B3A7-003220E89ABD} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation) Task: {3A8A5F5C-C09D-47DB-8456-0CD0796EF2C7} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2013-03-26] (Sony Corporation) Task: {3B6F73C4-AFBB-49C1-ADD5-5D8CC8C4A545} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {3D3E7530-CD97-495A-B792-668123010A2A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-13] (Adobe Systems Incorporated) Task: {43ADBC07-F761-4C93-AEDB-BD9E029C1060} - System32\Tasks\Sony Corporation\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2011-09-23] (Sony Corporation) Task: {633CB9C9-49C0-439F-B027-695262749CEA} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2013-03-26] (Sony Corporation) Task: {66753F9C-0FBE-496D-B26C-783C590CB421} - System32\Tasks\User_Feed_Synchronization-{B76945DF-72EF-4988-9332-2D50101B113A} => C:\Windows\system32\msfeedssync.exe [2013-04-01] (Microsoft Corporation) Task: {87B7DFC6-458E-451B-9386-4BE0AEC375EF} - System32\Tasks\EPUpdater => C:\Users\LU\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [2013-08-04] () Task: {8C06FA6D-CA53-4A1A-BCE0-45056075F8A7} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient Task: {97FC5A0D-6815-48AE-8582-F1B7F72A9D55} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {A1B0C339-6F74-4DA6-9747-5C8ED7B3F542} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation) Task: {A3270F97-8631-4277-A948-AD4E57789083} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation) Task: {A61A81C5-DE95-40AA-B699-EB0A7430BECA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-10] (Google Inc.) Task: {BAABAB14-EA7B-4CC8-8DE6-B0075CCF98A8} - System32\Tasks\Sony Corporation\VAIO Gate\VAIO Gate Restart => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2011-09-23] (Sony Corporation) Task: {BD67FAC4-A9C5-40C7-A6A8-F43620ECED4F} - System32\Tasks\DigitalSite => C:\Users\LU\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE [2013-04-12] () Task: {BF3EF496-B7BF-4929-AEBA-758D80F0928C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-06-10] (Google Inc.) Task: {D1761E84-282D-4B5D-A436-1743C0D7B4EE} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation) Task: {DE3367C4-DC24-48CF-89F2-D274273AA631} - System32\Tasks\Sony Corporation\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2011-09-23] (Sony Corporation) Task: {E307FF7E-C0D3-4DFE-A5A5-EB7BF7E65595} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\LU\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-05 00:12 - 2013-04-05 00:12 - 00130736 _____ (Dropbox, Inc.) C:\Users\LU\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll 2011-04-28 19:25 - 2011-02-15 09:26 - 00034816 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Improvement\viaggregator.dll 2011-04-28 20:34 - 2011-09-23 15:11 - 00397472 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Gate\NotificationWrapper.dll 2012-01-24 17:14 - 2011-09-23 15:11 - 00361120 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VGDam.dll 2013-06-13 11:21 - 2013-03-26 15:16 - 00027200 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgentPS.dll 2010-11-01 15:21 - 2010-11-01 05:03 - 00173352 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2010-11-01 15:21 - 2010-11-01 05:04 - 00169256 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2011-04-28 19:25 - 2011-01-22 15:15 - 00096768 _____ (Sony Corporation) C:\Program Files\Common Files\Sony Shared\Sony Utilities\SnyUtils.dll 2010-11-27 00:25 - 2010-11-27 00:25 - 00013312 _____ (Sony Corporation) C:\Program Files\Sony\PMB\XpStorageDevice_WinXp2k.dll 2010-10-28 22:50 - 2010-10-28 22:50 - 00303616 _____ (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcherLOC.DLL 2013-01-01 15:20 - 2013-03-26 15:16 - 00017472 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Update\InternetWrapperPS.dll 2011-08-23 18:20 - 2011-04-29 17:23 - 00083080 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCUtility.dll 2011-08-23 18:20 - 2011-05-27 10:57 - 00059528 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Care\KeyUtilities.dll 2011-08-23 18:20 - 2011-02-14 13:23 - 00022720 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Care\Metrics.dll 2012-01-24 17:14 - 2011-09-23 15:11 - 00059040 _____ (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIOGateNotifications.dll 2013-09-09 11:12 - 2013-09-05 07:28 - 00868704 _____ () C:\Program Files\Opera\16.0.1196.73\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========== ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (09/16/2013 04:09:40 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/16/2013 03:59:19 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: DslMgrSvc.exe, Version: 6.91.8434.1, Zeitstempel: 0x4900aa18 Name des fehlerhaften Moduls: DslMgrSvc.exe, Version: 6.91.8434.1, Zeitstempel: 0x4900aa18 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000c41a ID des fehlerhaften Prozesses: 0xf40 Startzeit der fehlerhaften Anwendung: 0xDslMgrSvc.exe0 Pfad der fehlerhaften Anwendung: DslMgrSvc.exe1 Pfad des fehlerhaften Moduls: DslMgrSvc.exe2 Berichtskennung: DslMgrSvc.exe3 Error: (09/16/2013 03:58:01 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/14/2013 08:52:13 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: DslMgrSvc.exe, Version: 6.91.8434.1, Zeitstempel: 0x4900aa18 Name des fehlerhaften Moduls: DslMgrSvc.exe, Version: 6.91.8434.1, Zeitstempel: 0x4900aa18 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000c41a ID des fehlerhaften Prozesses: 0xa38 Startzeit der fehlerhaften Anwendung: 0xDslMgrSvc.exe0 Pfad der fehlerhaften Anwendung: DslMgrSvc.exe1 Pfad des fehlerhaften Moduls: DslMgrSvc.exe2 Berichtskennung: DslMgrSvc.exe3 Error: (09/14/2013 08:51:07 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 02:37:01 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 02:33:21 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 00:00:19 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden. Fehlerkontext: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2 - 00000170,0x00560038,0011E6E0,0,0011D6D8,4096,[0]). Vorgang: PostFinalCommitSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (09/13/2013 09:20:59 AM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Volume bzw. Datenträger ist nicht richtig angeschlossen oder wurde nicht gefunden. Fehlerkontext: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1 - 000000B8,0x00560038,0059E6E0,0,0059D6D8,4096,[0]). Vorgang: PostFinalCommitSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (09/12/2013 03:02:42 PM) (Source: MsiInstaller) (User: LU-VAIO) Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011004}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127 System errors: ============= Error: (09/16/2013 04:09:14 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (09/16/2013 04:09:03 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (09/16/2013 04:01:10 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{296C03D7-85E6-409B-8525-CD1443A1F4-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (09/16/2013 03:59:28 PM) (Source: Service Control Manager) (User: ) Description: Dienst "DSL-Manager" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (09/16/2013 03:58:57 PM) (Source: DCOM) (User: ) Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (09/16/2013 03:58:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (09/16/2013 03:58:56 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (09/16/2013 03:57:58 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (09/16/2013 03:57:39 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (09/15/2013 08:16:45 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht. Microsoft Office Sessions: ========================= Error: (09/16/2013 04:09:40 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/16/2013 03:59:19 PM) (Source: Application Error)(User: ) Description: DslMgrSvc.exe6.91.8434.14900aa18DslMgrSvc.exe6.91.8434.14900aa18c00000050000c41af4001ceb2e4cfe2139bC:\Program Files\DSL-Manager\DslMgrSvc.exeC:\Program Files\DSL-Manager\DslMgrSvc.exe2e01dd77-1ed8-11e3-b129-c0f8daeeae8d Error: (09/16/2013 03:58:01 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/14/2013 08:52:13 AM) (Source: Application Error)(User: ) Description: DslMgrSvc.exe6.91.8434.14900aa18DslMgrSvc.exe6.91.8434.14900aa18c00000050000c41aa3801ceb116cb17ea81C:\Program Files\DSL-Manager\DslMgrSvc.exeC:\Program Files\DSL-Manager\DslMgrSvc.exe2ec04a99-1d0a-11e3-b3bb-c0f8daeeae8d Error: (09/14/2013 08:51:07 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 02:37:01 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 02:33:21 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 00:00:19 PM) (Source: VSS)(User: ) Description: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2 - 00000170,0x00560038,0011E6E0,0,0011D6D8,4096,[0]) Vorgang: PostFinalCommitSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (09/13/2013 09:20:59 AM) (Source: VSS)(User: ) Description: DeviceIoControl(\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1 - 000000B8,0x00560038,0059E6E0,0,0059D6D8,4096,[0]) Vorgang: PostFinalCommitSnapshots wird verarbeitet Kontext: Ausführungskontext: System Provider Error: (09/12/2013 03:02:42 PM) (Source: MsiInstaller)(User: LU-VAIO) Description: Adobe Reader XI - Deutsch{AC76BA86-7AD7-0000-2550-7A8C40011004}1625(NULL)(NULL)(NULL) CodeIntegrity Errors: =================================== Date: 2012-02-03 17:27:56.694 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-03 16:33:18.545 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-03 16:14:47.746 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-03 15:54:57.396 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-03 15:31:54.992 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-03 15:17:33.224 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-03 14:58:35.012 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-02 21:05:39.852 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-02 20:18:54.714 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2012-02-02 19:57:41.789 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 33% Total physical RAM: 3578.9 MB Available physical RAM: 2386.13 MB Total Pagefile: 7156.09 MB Available Pagefile: 5571.39 MB Total Virtual: 2047.88 MB Available Virtual: 1902.59 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:286.13 GB) (Free:225.33 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 507B7076) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=286 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-09-16 17:06:39 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\0000006b WDC_WD32 rev.01.0 298,09GB Running: gmer_2.1.19163.exe; Driver: C:\Users\LU\AppData\Local\Temp\uxtdapob.sys ---- System - GMER 2.1 ---- SSDT 92108076 ZwCreateSection SSDT 9210804E ZwCreateSymbolicLinkObject SSDT 92108053 ZwLoadDriver SSDT 92108049 ZwOpenSection SSDT 92108080 ZwRequestWaitReplyPort SSDT 9210807B ZwSetContextThread SSDT 92108085 ZwSetSecurityObject SSDT 92108058 ZwSetSystemInformation SSDT 9210808A ZwSystemDebugControl SSDT 92108017 ZwTerminateProcess SSDT 92108012 ZwWriteVirtualMemory ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 83289A15 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 832C3212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 832CA58C 4 Bytes [76, 80, 10, 92] .text ntkrnlpa.exe!KeRemoveQueueEx + 11FF 832CA594 4 Bytes [4E, 80, 10, 92] {DEC ESI; ADC BYTE [EAX], 0x92} .text ntkrnlpa.exe!KeRemoveQueueEx + 1313 832CA6A8 4 Bytes [53, 80, 10, 92] {PUSH EBX; ADC BYTE [EAX], 0x92} .text ntkrnlpa.exe!KeRemoveQueueEx + 13AF 832CA744 4 Bytes [49, 80, 10, 92] {DEC ECX; ADC BYTE [EAX], 0x92} .text ntkrnlpa.exe!KeRemoveQueueEx + 1553 832CA8E8 4 Bytes [80, 80, 10, 92] .text ... .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9300A000, 0x35356D, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtCreateFile + 6 76E1560E 4 Bytes [28, 8C, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtCreateFile + B 76E15613 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtMapViewOfSection + 6 76E15C6E 4 Bytes [28, 8F, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtMapViewOfSection + B 76E15C73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenFile + 6 76E15D1E 4 Bytes [68, 8C, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenFile + B 76E15D23 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenProcess + 6 76E15DCE 4 Bytes [A8, 8D, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenProcess + B 76E15DD3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenProcessToken + 6 76E15DDE 4 Bytes CALL 75E40870 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenProcessToken + B 76E15DE3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenProcessTokenEx + 6 76E15DEE 4 Bytes [A8, 8E, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenProcessTokenEx + B 76E15DF3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenThread + 6 76E15E4E 4 Bytes [68, 8D, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenThread + B 76E15E53 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenThreadToken + 6 76E15E5E 4 Bytes [68, 8E, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenThreadToken + B 76E15E63 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenThreadTokenEx + 6 76E15E6E 4 Bytes CALL 75E40901 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtOpenThreadTokenEx + B 76E15E73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtQueryAttributesFile + 6 76E15F7E 4 Bytes [A8, 8C, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtQueryAttributesFile + B 76E15F83 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtQueryFullAttributesFile + 6 76E1602E 4 Bytes CALL 75E40ABF C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtQueryFullAttributesFile + B 76E16033 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtSetInformationFile + 6 76E1667E 4 Bytes [28, 8D, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtSetInformationFile + B 76E16683 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtSetInformationThread + 6 76E166DE 4 Bytes [28, 8E, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtSetInformationThread + B 76E166E3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtUnmapViewOfSection + 6 76E169FE 4 Bytes [68, 8F, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4148] ntdll.dll!NtUnmapViewOfSection + B 76E16A03 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtCreateFile + 6 76E1560E 4 Bytes [28, A0, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtCreateFile + B 76E15613 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtMapViewOfSection + 6 76E15C6E 4 Bytes [28, A3, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtMapViewOfSection + B 76E15C73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenFile + 6 76E15D1E 4 Bytes [68, A0, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenFile + B 76E15D23 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenProcess + 6 76E15DCE 4 Bytes [A8, A1, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenProcess + B 76E15DD3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenProcessToken + 6 76E15DDE 4 Bytes CALL 75E41884 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenProcessToken + B 76E15DE3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenProcessTokenEx + 6 76E15DEE 4 Bytes [A8, A2, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenProcessTokenEx + B 76E15DF3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenThread + 6 76E15E4E 4 Bytes [68, A1, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenThread + B 76E15E53 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenThreadToken + 6 76E15E5E 4 Bytes [68, A2, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenThreadToken + B 76E15E63 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenThreadTokenEx + 6 76E15E6E 4 Bytes CALL 75E41915 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtOpenThreadTokenEx + B 76E15E73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtQueryAttributesFile + 6 76E15F7E 4 Bytes [A8, A0, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtQueryAttributesFile + B 76E15F83 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtQueryFullAttributesFile + 6 76E1602E 4 Bytes CALL 75E41AD3 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtQueryFullAttributesFile + B 76E16033 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtSetInformationFile + 6 76E1667E 4 Bytes [28, A1, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtSetInformationFile + B 76E16683 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtSetInformationThread + 6 76E166DE 4 Bytes [28, A2, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtSetInformationThread + B 76E166E3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtUnmapViewOfSection + 6 76E169FE 4 Bytes [68, A3, BA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4584] ntdll.dll!NtUnmapViewOfSection + B 76E16A03 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtCreateFile + 6 76E1560E 4 Bytes [28, 98, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtCreateFile + B 76E15613 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtMapViewOfSection + 6 76E15C6E 4 Bytes [28, 9B, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtMapViewOfSection + B 76E15C73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenFile + 6 76E15D1E 4 Bytes [68, 98, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenFile + B 76E15D23 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenProcess + 6 76E15DCE 4 Bytes [A8, 99, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenProcess + B 76E15DD3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenProcessToken + 6 76E15DDE 4 Bytes CALL 75E1847C C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenProcessToken + B 76E15DE3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenProcessTokenEx + 6 76E15DEE 4 Bytes [A8, 9A, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenProcessTokenEx + B 76E15DF3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenThread + 6 76E15E4E 4 Bytes [68, 99, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenThread + B 76E15E53 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenThreadToken + 6 76E15E5E 4 Bytes [68, 9A, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenThreadToken + B 76E15E63 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenThreadTokenEx + 6 76E15E6E 4 Bytes CALL 75E1850D C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtOpenThreadTokenEx + B 76E15E73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtQueryAttributesFile + 6 76E15F7E 4 Bytes [A8, 98, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtQueryAttributesFile + B 76E15F83 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtQueryFullAttributesFile + 6 76E1602E 4 Bytes CALL 75E186CB C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtQueryFullAttributesFile + B 76E16033 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtSetInformationFile + 6 76E1667E 4 Bytes [28, 99, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtSetInformationFile + B 76E16683 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtSetInformationThread + 6 76E166DE 4 Bytes [28, 9A, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtSetInformationThread + B 76E166E3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtUnmapViewOfSection + 6 76E169FE 4 Bytes [68, 9B, 26, 00] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4848] ntdll.dll!NtUnmapViewOfSection + B 76E16A03 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtCreateFile + 6 76E1560E 4 Bytes CALL 59E058BD .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtCreateFile + B 76E15613 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtMapViewOfSection + 6 76E15C6E 4 Bytes [28, EB, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtMapViewOfSection + B 76E15C73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenFile + 6 76E15D1E 4 Bytes CALL 59E05FCD .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenFile + B 76E15D23 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenProcess + 6 76E15DCE 4 Bytes JMP 59E0607D .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenProcess + B 76E15DD3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenProcessToken + 6 76E15DDE 4 Bytes CALL 75E408CC C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenProcessToken + B 76E15DE3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenProcessTokenEx + 6 76E15DEE 4 Bytes JMP E2FF02AA .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenProcessTokenEx + B 76E15DF3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenThread + 6 76E15E4E 4 Bytes JMP 59E060FD .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenThread + B 76E15E53 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenThreadToken + 6 76E15E5E 4 Bytes JMP E2FF02AA .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenThreadToken + B 76E15E63 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenThreadTokenEx + 6 76E15E6E 4 Bytes CALL 75E4095D C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtOpenThreadTokenEx + B 76E15E73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtQueryAttributesFile + 6 76E15F7E 4 Bytes CALL 59E0622D .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtQueryAttributesFile + B 76E15F83 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtQueryFullAttributesFile + 6 76E1602E 4 Bytes CALL 75E40B1B C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtQueryFullAttributesFile + B 76E16033 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtSetInformationFile + 6 76E1667E 4 Bytes JMP 59E0692D .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtSetInformationFile + B 76E16683 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtSetInformationThread + 6 76E166DE 4 Bytes JMP E2FF02AA .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtSetInformationThread + B 76E166E3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtUnmapViewOfSection + 6 76E169FE 4 Bytes [68, EB, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[4852] ntdll.dll!NtUnmapViewOfSection + B 76E16A03 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtCreateFile + 6 76E1560E 4 Bytes [28, 5C, AA, 02] {SUB [EDX+EBP*4+0x2], BL} .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtCreateFile + B 76E15613 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtMapViewOfSection + 6 76E15C6E 4 Bytes [28, 5F, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtMapViewOfSection + B 76E15C73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenFile + 6 76E15D1E 4 Bytes [68, 5C, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenFile + B 76E15D23 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenProcess + 6 76E15DCE 4 Bytes [A8, 5D, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenProcess + B 76E15DD3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenProcessToken + 6 76E15DDE 4 Bytes CALL 75E40840 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenProcessToken + B 76E15DE3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenProcessTokenEx + 6 76E15DEE 4 Bytes [A8, 5E, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenProcessTokenEx + B 76E15DF3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenThread + 6 76E15E4E 4 Bytes [68, 5D, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenThread + B 76E15E53 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenThreadToken + 6 76E15E5E 4 Bytes [68, 5E, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenThreadToken + B 76E15E63 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenThreadTokenEx + 6 76E15E6E 4 Bytes CALL 75E408D1 C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtOpenThreadTokenEx + B 76E15E73 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtQueryAttributesFile + 6 76E15F7E 4 Bytes [A8, 5C, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtQueryAttributesFile + B 76E15F83 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtQueryFullAttributesFile + 6 76E1602E 4 Bytes CALL 75E40A8F C:\Windows\system32\SHELL32.dll .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtQueryFullAttributesFile + B 76E16033 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtSetInformationFile + 6 76E1667E 4 Bytes [28, 5D, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtSetInformationFile + B 76E16683 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtSetInformationThread + 6 76E166DE 4 Bytes [28, 5E, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtSetInformationThread + B 76E166E3 1 Byte [E2] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtUnmapViewOfSection + 6 76E169FE 4 Bytes [68, 5F, AA, 02] .text C:\Program Files\Opera\16.0.1196.73\opera.exe[5892] ntdll.dll!NtUnmapViewOfSection + B 76E16A03 1 Byte [E2] ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@58b035748831 0x89 0x2E 0x2E 0x58 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@001d28571943 0x31 0xA1 0x5A 0xC7 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@58170c526a2a 0xBD 0x37 0x25 0x71 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@fcc7348610cc 0x09 0x78 0x05 0x3A ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@68a86d2a9931 0x4A 0x4E 0xCD 0xE6 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@9463d1bbe2cc 0x58 0x5D 0x24 0x9E ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@0808c2fad68c 0xF1 0xC7 0xA3 0x5A ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@a0821f3d904f 0x5C 0x17 0x64 0xA6 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@58b035748831 0x89 0x2E 0x2E 0x58 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@001d28571943 0x31 0xA1 0x5A 0xC7 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@58170c526a2a 0xBD 0x37 0x25 0x71 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@fcc7348610cc 0x09 0x78 0x05 0x3A ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@68a86d2a9931 0x4A 0x4E 0xCD 0xE6 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@9463d1bbe2cc 0x58 0x5D 0x24 0x9E ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@0808c2fad68c 0xF1 0xC7 0xA3 0x5A ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0f8daeeae8d@a0821f3d904f 0x5C 0x17 0x64 0xA6 ... ---- EOF - GMER 2.1 ---- |
16.09.2013, 17:10 | #2 |
/// the machine /// TB-Ausbilder | Probleme mit PUP Virus-68 infizierte Objekte hi,
__________________Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
16.09.2013, 18:09 | #3 |
| Probleme mit PUP Virus-68 infizierte Objekte Grüß dich und danke erstmal
__________________Hier die files: adwCleaner: Code:
ATTFilter # AdwCleaner v3.004 - Bericht erstellt am 16/09/2013 um 18:50:09 # Updated 15/09/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : LU - LU-VAIO # Gestartet von : C:\Users\LU\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\Program Files\delta Ordner Gelöscht : C:\Users\LU\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\LU\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\LU\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\LU\AppData\Roaming\digitalsite Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EPUpdater [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87B7DFC6-458E-451B-9386-4BE0AEC375EF} [#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{87B7DFC6-458E-451B-9386-4BE0AEC375EF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@checkpoint.com/FFApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2613550 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}] Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\Software\Uniblue\DriverScanner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16686 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v ************************* AdwCleaner[R0].txt - [8091 octets] - [16/09/2013 18:48:00] AdwCleaner[S0].txt - [7923 octets] - [16/09/2013 18:50:09] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7983 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.1 (09.15.2013:1) OS: Windows 7 Home Premium x86 Ran by LU on 16.09.2013 at 18:54:40,41 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F1931C3C-1C14-41C9-8718-454578148D9E} ~~~ Files Successfully deleted: [File] C:\Windows\System32\Tasks\digitalsite Successfully deleted: [File] C:\Windows\Tasks\digitalsite.job ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 16.09.2013 at 19:01:01,20 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 Ran by LU (administrator) on LU-VAIO on 16-09-2013 19:02:47 Running from C:\Users\LU\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (T-Systems Enterprise Services GmbH) C:\Program Files\DSL-Manager\DslMgr.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (T-Systems Enterprise Services GmbH) C:\Program Files\DSL-Manager\DslMgrSvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-11-01] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-06] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1873192 2010-11-01] (Synaptics Incorporated) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM\...\Run: [] - [x] HKLM\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) MountPoints2: {4ecb6f37-63e1-11e1-bd57-001e101f1ed9} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {5939391b-63e0-11e1-ac1a-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {59393945-63e0-11e1-ac1a-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {d9a1b83d-c745-11e0-8bc0-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {d9a1b88b-c745-11e0-8bc0-9a004eb6803e} - D:\setup_vmc_lite.exe /checkApplicationPresence Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\LU\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sony.eu/vaioportal URLSearchHook: (No Name) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {07DF276A-110B-424B-972A-18A3018F1359} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {5597BEDF-ACD2-416D-BDDE-AF4A1994DC47} URL = hxxp://de.shopping.com/?linkin_id=8056363 SearchScopes: HKCU - {C58A25CA-DFD9-450D-BE35-890D5EDA37BC} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-21/4?satitle={searchTerms} BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} ========================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [284160 2011-01-06] (Advanced Micro Devices, Inc.) R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [140224 2010-06-17] (Advanced Micro Devices) R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-09] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [189048 2011-01-29] (Sony Corporation) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) R3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [64704 2011-03-05] (Sony Corporation) S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [652016 2011-05-24] (Sony Corporation) S3 VcmINSMgr; C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [385336 2011-02-18] (Sony Corporation) R3 VCService; C:\Program Files\Sony\VAIO Care\VCService.exe [44736 2011-02-14] (Sony Corporation) R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [869304 2011-08-12] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1013808 2013-03-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R0 amd_sata; C:\Windows\System32\drivers\amd_sata.sys [64128 2011-02-17] (Advanced Micro Devices) R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [32384 2011-02-17] (Advanced Micro Devices) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17408 2009-05-26] (ArcSoft, Inc.) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [102416 2011-02-15] (ATI Technologies, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-16] (Avira Operations GmbH & Co. KG) S3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [297000 2010-11-01] (Broadcom Corporation.) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [102912 2009-06-29] (Huawei Technologies Co., Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-16] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-16 19:01 - 2013-09-16 19:01 - 00000902 _____ C:\Users\LU\Desktop\JRT.txt 2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 ____D C:\Windows\ERUNT 2013-09-16 18:52 - 2013-09-16 18:52 - 00008063 _____ C:\Users\LU\Desktop\AdwCleaner[S0].txt 2013-09-16 18:47 - 2013-09-16 18:50 - 00000000 ____D C:\AdwCleaner 2013-09-16 18:46 - 2013-09-16 18:46 - 01029675 _____ (Thisisu) C:\Users\LU\Desktop\JRT.exe 2013-09-16 18:45 - 2013-09-16 18:46 - 01039554 _____ C:\Users\LU\Desktop\adwcleaner.exe 2013-09-16 17:41 - 2013-09-16 17:41 - 00000090 _____ C:\Users\LU\AppData\Roaming\WB.CFG 2013-09-16 17:41 - 2013-09-16 17:41 - 00000005 _____ C:\Users\LU\AppData\Roaming\WBPU-TTL.DAT 2013-09-16 17:06 - 2013-09-16 17:06 - 00026554 _____ C:\Users\LU\Desktop\gmer.log 2013-09-16 16:50 - 2013-09-16 16:51 - 00033153 _____ C:\Users\LU\Desktop\Addition.txt 2013-09-16 16:48 - 2013-09-16 16:48 - 00000000 ____D C:\FRST 2013-09-16 16:46 - 2013-09-16 16:47 - 00000466 _____ C:\Users\LU\Desktop\defogger_disable.log 2013-09-16 16:46 - 2013-09-16 16:46 - 00000000 _____ C:\Users\LU\defogger_reenable 2013-09-16 16:44 - 2013-09-16 16:45 - 01084083 _____ (Farbar) C:\Users\LU\Desktop\FRST.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00377856 _____ C:\Users\LU\Desktop\gmer_2.1.19163.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00050477 _____ C:\Users\LU\Desktop\Defogger.exe 2013-09-16 16:41 - 2013-09-16 16:41 - 00678784 _____ C:\Users\LU\Downloads\ZipOpenerSetup.exe 2013-09-16 15:58 - 2013-09-16 15:58 - 97787879 _____ C:\Windows\system32\랅觴ᰴ] 2013-09-13 12:11 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-13 12:11 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-13 12:11 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-13 12:11 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-13 12:11 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-13 12:11 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-13 09:35 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-13 09:35 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-13 09:35 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-13 09:34 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-13 09:34 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-13 09:34 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-13 09:34 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-13 09:34 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 23:36 - 2013-09-12 23:36 - 97412816 _____ C:\Windows\system32\圄抒ᰴ` 2013-09-11 00:29 - 2013-09-11 00:29 - 97004533 _____ C:\Windows\system32\冐ᰴi 2013-09-10 20:04 - 2013-09-10 20:04 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe_Systems_Incorporate 2013-09-10 19:52 - 2013-09-10 20:36 - 00000000 ____D C:\Users\LU\Documents\My Digital Editions 2013-09-10 19:52 - 2013-09-10 19:52 - 00002162 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk 2013-09-10 19:50 - 2013-09-10 19:50 - 05889712 _____ (Adobe Systems Incorporated) C:\Users\LU\Downloads\ADE_2.0_Installer.exe 2013-09-10 19:46 - 2013-09-10 19:46 - 00001196 _____ C:\Users\LU\Downloads\Russendisko.acsm 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\ProgramData\T-Online 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\Program Files\Common Files\T-Com 2013-09-09 12:05 - 2007-09-12 17:24 - 00026816 _____ (Printing Communications Assoc., Inc. (PCAUSA)) C:\Windows\system32\Drivers\DslTestSp5.sys 2013-09-09 12:03 - 2013-09-09 12:03 - 00000000 ____D C:\Program Files\DSL-Manager 2013-09-09 12:03 - 2007-08-01 14:49 - 00016448 _____ (T-Systems Enterprise Services GmbH) C:\Windows\system32\Drivers\dslmnlwf.sys 2013-09-09 12:02 - 2013-09-09 12:02 - 04118552 _____ (T-Online ) C:\Users\LU\Downloads\DSL-Manager_6.9.exe 2013-08-31 23:47 - 2013-08-31 23:47 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular (1).xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020892 _____ C:\Users\LU\Downloads\Marathonstaffeln Wechselpunktformular.xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular.xlsx 2013-08-30 10:10 - 2013-09-09 11:12 - 00000000 ____D C:\Program Files\Opera 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Roaming\Opera Software 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Local\Opera Software 2013-08-30 10:07 - 2013-08-30 10:09 - 32058408 _____ (Opera Software ASA) C:\Users\LU\Downloads\Opera_16.0.1196.62_Setup.exe 2013-08-30 10:06 - 2013-08-30 10:06 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-29 12:22 - 2013-08-29 14:59 - 94605346 _____ C:\Windows\system32\旹柳ᰴ] 2013-08-20 17:16 - 2013-08-20 17:16 - 99562272 _____ C:\Windows\system32\髦ᇣᰴg 2013-08-20 16:58 - 2013-08-20 16:58 - 06663848 _____ C:\Users\LU\Downloads\Niederschlag.zip 2013-08-18 17:01 - 2013-08-18 17:03 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung(1).zip 2013-08-18 17:00 - 2013-08-18 17:01 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung.zip 2013-08-18 13:17 - 2013-09-16 16:42 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-16 19:01 - 2013-09-16 19:01 - 00000902 _____ C:\Users\LU\Desktop\JRT.txt 2013-09-16 19:00 - 2009-07-14 06:34 - 00020400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-16 19:00 - 2009-07-14 06:34 - 00020400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-16 18:57 - 2010-11-20 23:01 - 01684336 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-16 18:56 - 2011-04-28 19:03 - 02053636 _____ C:\Windows\WindowsUpdate.log 2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 ____D C:\Windows\ERUNT 2013-09-16 18:52 - 2013-09-16 18:52 - 00008063 _____ C:\Users\LU\Desktop\AdwCleaner[S0].txt 2013-09-16 18:52 - 2012-06-10 10:39 - 00001086 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-16 18:51 - 2013-07-11 19:06 - 00003304 _____ C:\Windows\setupact.log 2013-09-16 18:51 - 2012-06-10 10:39 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-16 18:51 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-16 18:50 - 2013-09-16 18:47 - 00000000 ____D C:\AdwCleaner 2013-09-16 18:46 - 2013-09-16 18:46 - 01029675 _____ (Thisisu) C:\Users\LU\Desktop\JRT.exe 2013-09-16 18:46 - 2013-09-16 18:45 - 01039554 _____ C:\Users\LU\Desktop\adwcleaner.exe 2013-09-16 18:41 - 2013-07-11 19:05 - 00088226 _____ C:\Windows\PFRO.log 2013-09-16 17:41 - 2013-09-16 17:41 - 00000090 _____ C:\Users\LU\AppData\Roaming\WB.CFG 2013-09-16 17:41 - 2013-09-16 17:41 - 00000005 _____ C:\Users\LU\AppData\Roaming\WBPU-TTL.DAT 2013-09-16 17:37 - 2013-01-20 13:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-16 17:06 - 2013-09-16 17:06 - 00026554 _____ C:\Users\LU\Desktop\gmer.log 2013-09-16 16:51 - 2013-09-16 16:50 - 00033153 _____ C:\Users\LU\Desktop\Addition.txt 2013-09-16 16:48 - 2013-09-16 16:48 - 00000000 ____D C:\FRST 2013-09-16 16:47 - 2013-09-16 16:46 - 00000466 _____ C:\Users\LU\Desktop\defogger_disable.log 2013-09-16 16:46 - 2013-09-16 16:46 - 00000000 _____ C:\Users\LU\defogger_reenable 2013-09-16 16:46 - 2011-08-12 13:31 - 00000000 ____D C:\Users\LU 2013-09-16 16:45 - 2013-09-16 16:44 - 01084083 _____ (Farbar) C:\Users\LU\Desktop\FRST.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00377856 _____ C:\Users\LU\Desktop\gmer_2.1.19163.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00050477 _____ C:\Users\LU\Desktop\Defogger.exe 2013-09-16 16:42 - 2013-08-18 13:17 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-16 16:41 - 2013-09-16 16:41 - 00678784 _____ C:\Users\LU\Downloads\ZipOpenerSetup.exe 2013-09-16 16:25 - 2011-08-12 15:34 - 00000000 ____D C:\Users\LU\AppData\Roaming\Mozilla 2013-09-16 16:06 - 2011-08-12 13:38 - 00000000 ____D C:\Windows\pss 2013-09-16 15:58 - 2013-09-16 15:58 - 97787879 _____ C:\Windows\system32\랅觴ᰴ] 2013-09-16 15:57 - 2013-04-01 16:57 - 00000000 ___RD C:\Users\LU\Dropbox 2013-09-16 15:57 - 2013-04-01 16:45 - 00000000 ____D C:\Users\LU\AppData\Roaming\Dropbox 2013-09-15 15:18 - 2011-11-05 12:00 - 00079548 _____ C:\test.xml 2013-09-13 16:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-13 14:36 - 2009-07-14 06:33 - 00435144 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-13 14:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-13 12:27 - 2011-08-12 15:20 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-13 12:04 - 2013-07-24 17:10 - 00000000 ____D C:\Windows\system32\MRT 2013-09-13 12:00 - 2011-10-06 11:55 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-13 11:37 - 2012-05-26 09:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-13 11:37 - 2011-08-28 10:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-12 23:36 - 2013-09-12 23:36 - 97412816 _____ C:\Windows\system32\圄抒ᰴ` 2013-09-11 00:29 - 2013-09-11 00:29 - 97004533 _____ C:\Windows\system32\冐ᰴi 2013-09-10 20:36 - 2013-09-10 19:52 - 00000000 ____D C:\Users\LU\Documents\My Digital Editions 2013-09-10 20:04 - 2013-09-10 20:04 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe_Systems_Incorporate 2013-09-10 19:52 - 2013-09-10 19:52 - 00002162 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk 2013-09-10 19:52 - 2011-04-28 20:01 - 00000000 ____D C:\Program Files\Adobe 2013-09-10 19:50 - 2013-09-10 19:50 - 05889712 _____ (Adobe Systems Incorporated) C:\Users\LU\Downloads\ADE_2.0_Installer.exe 2013-09-10 19:46 - 2013-09-10 19:46 - 00001196 _____ C:\Users\LU\Downloads\Russendisko.acsm 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\ProgramData\T-Online 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\Program Files\Common Files\T-Com 2013-09-09 12:03 - 2013-09-09 12:03 - 00000000 ____D C:\Program Files\DSL-Manager 2013-09-09 12:03 - 2011-04-28 19:15 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-09-09 12:02 - 2013-09-09 12:02 - 04118552 _____ (T-Online ) C:\Users\LU\Downloads\DSL-Manager_6.9.exe 2013-09-09 11:12 - 2013-08-30 10:10 - 00000000 ____D C:\Program Files\Opera 2013-09-09 11:07 - 2013-08-16 16:31 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-03 09:20 - 2013-06-24 10:38 - 00000000 ____D C:\Users\LU\Desktop\Dokumente 2013-08-31 23:47 - 2013-08-31 23:47 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular (1).xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020892 _____ C:\Users\LU\Downloads\Marathonstaffeln Wechselpunktformular.xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular.xlsx 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Roaming\Opera Software 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Local\Opera Software 2013-08-30 10:09 - 2013-08-30 10:07 - 32058408 _____ (Opera Software ASA) C:\Users\LU\Downloads\Opera_16.0.1196.62_Setup.exe 2013-08-30 10:07 - 2011-08-13 18:18 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe 2013-08-30 10:06 - 2013-08-30 10:06 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-30 10:06 - 2011-10-07 14:05 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-08-30 10:06 - 2011-04-28 20:01 - 00000000 ____D C:\ProgramData\Adobe 2013-08-29 14:59 - 2013-08-29 12:22 - 94605346 _____ C:\Windows\system32\旹柳ᰴ] 2013-08-20 17:16 - 2013-08-20 17:16 - 99562272 _____ C:\Windows\system32\髦ᇣᰴg 2013-08-20 16:58 - 2013-08-20 16:58 - 06663848 _____ C:\Users\LU\Downloads\Niederschlag.zip 2013-08-20 11:27 - 2013-08-16 16:35 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 11:27 - 2013-08-16 16:31 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-18 18:02 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-08-18 17:56 - 2010-11-20 22:57 - 00000000 ____D C:\Users\Administrator 2013-08-18 17:56 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-08-18 17:03 - 2013-08-18 17:01 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung(1).zip 2013-08-18 17:01 - 2013-08-18 17:00 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung.zip 2013-08-18 12:25 - 2011-02-11 02:15 - 00000000 ____D C:\Windows\Panther Some content of TEMP: ==================== C:\Users\LU\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-31 21:49 ==================== End Of Log ============================ --- --- --- Hoffe das war alles so ok! Viele Grüße Lu |
16.09.2013, 20:17 | #4 |
/// the machine /// TB-Ausbilder | Probleme mit PUP Virus-68 infizierte ObjekteESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.09.2013, 08:03 | #5 |
| Probleme mit PUP Virus-68 infizierte Objekte Guten Morgen! hier die files: eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internet# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=9cce813d34720c4482ab0d3d90592738 # engine=15156 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-09-16 11:30:22 # local_time=2013-09-17 01:30:22 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 23104 131005413 0 0 # scanned=118815 # found=0 # cleaned=0 # scan_time=13410 Code:
ATTFilter UNSUPPORTED OPERATING SYSTEM! ABORTED! FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 Ran by LU (administrator) on LU-VAIO on 17-09-2013 08:31:26 Running from C:\Users\LU\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Advanced Micro Devices) C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Sony Corporation) C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (T-Systems Enterprise Services GmbH) C:\Program Files\DSL-Manager\DslMgr.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (T-Systems Enterprise Services GmbH) C:\Program Files\DSL-Manager\DslMgrSvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (ArcSoft, Inc.) C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Opera Software) C:\Program Files\Opera\16.0.1196.73\opera.exe () C:\Program Files\Opera\16.0.1196.73\opera_crashreporter.exe () C:\Program Files\Opera\16.0.1196.73\opera_autoupdate.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-11-01] (Realtek Semiconductor) HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-06] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1873192 2010-11-01] (Synaptics Incorporated) HKLM\...\Run: [ISBMgr.exe] - C:\Program Files\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation) HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM\...\Run: [] - [x] HKLM\...\Run: [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-08-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) MountPoints2: {4ecb6f37-63e1-11e1-bd57-001e101f1ed9} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {5939391b-63e0-11e1-ac1a-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {59393945-63e0-11e1-ac1a-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {d9a1b83d-c745-11e0-8bc0-c0f8daeeae8d} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {d9a1b88b-c745-11e0-8bc0-9a004eb6803e} - D:\setup_vmc_lite.exe /checkApplicationPresence Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\LU\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.sony.eu/vaioportal URLSearchHook: (No Name) - {fc2b76fc-2132-4d80-a9a3-1f5c6e49066b} - No File SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {07DF276A-110B-424B-972A-18A3018F1359} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices SearchScopes: HKCU - {5597BEDF-ACD2-416D-BDDE-AF4A1994DC47} URL = hxxp://de.shopping.com/?linkin_id=8056363 SearchScopes: HKCU - {C58A25CA-DFD9-450D-BE35-890D5EDA37BC} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-21/4?satitle={searchTerms} BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKCU - No Name - {FC2B76FC-2132-4D80-A9A3-1F5C6E49066B} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [258104] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.) FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} ========================== Services (Whitelisted) ================= S3 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [284160 2011-01-06] (Advanced Micro Devices, Inc.) R2 AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [140224 2010-06-17] (Advanced Micro Devices) R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [622648 2013-09-09] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-08-20] (Avira Operations GmbH & Co. KG) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [189048 2011-01-29] (Sony Corporation) R2 Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.) R3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) R2 uCamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) R2 VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [64704 2011-03-05] (Sony Corporation) S3 VcmIAlzMgr; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [652016 2011-05-24] (Sony Corporation) S3 VcmINSMgr; C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [385336 2011-02-18] (Sony Corporation) R3 VCService; C:\Program Files\Sony\VAIO Care\VCService.exe [44736 2011-02-14] (Sony Corporation) R2 VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [869304 2011-08-12] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1013808 2013-03-26] (Sony Corporation) ==================== Drivers (Whitelisted) ==================== R0 amd_sata; C:\Windows\System32\drivers\amd_sata.sys [64128 2011-02-17] (Advanced Micro Devices) R0 amd_xata; C:\Windows\System32\drivers\amd_xata.sys [32384 2011-02-17] (Advanced Micro Devices) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [17408 2009-05-26] (ArcSoft, Inc.) R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW73.sys [102416 2011-02-15] (ATI Technologies, Inc.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-08-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-16] (Avira Operations GmbH & Co. KG) S3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [297000 2010-11-01] (Broadcom Corporation.) R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [102912 2009-06-29] (Huawei Technologies Co., Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-16] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-17 08:29 - 2013-09-17 08:29 - 00000041 _____ C:\Users\LU\Desktop\checkup.txt 2013-09-16 21:39 - 2013-09-16 21:39 - 02347384 _____ (ESET) C:\Users\LU\Desktop\esetsmartinstaller_enu (1).exe 2013-09-16 21:39 - 2013-09-16 21:39 - 00891144 _____ C:\Users\LU\Desktop\SecurityCheck.exe 2013-09-16 21:38 - 2013-09-16 21:39 - 02347384 _____ (ESET) C:\Users\LU\Downloads\esetsmartinstaller_enu.exe 2013-09-16 19:05 - 2013-09-16 19:05 - 00033360 _____ C:\Users\LU\Desktop\FRST_2.txt 2013-09-16 19:01 - 2013-09-16 19:01 - 00000902 _____ C:\Users\LU\Desktop\JRT.txt 2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 ____D C:\Windows\ERUNT 2013-09-16 18:52 - 2013-09-16 18:52 - 00008063 _____ C:\Users\LU\Desktop\AdwCleaner[S0].txt 2013-09-16 18:47 - 2013-09-16 18:50 - 00000000 ____D C:\AdwCleaner 2013-09-16 18:46 - 2013-09-16 18:46 - 01029675 _____ (Thisisu) C:\Users\LU\Desktop\JRT.exe 2013-09-16 18:45 - 2013-09-16 18:46 - 01039554 _____ C:\Users\LU\Desktop\adwcleaner.exe 2013-09-16 17:41 - 2013-09-16 17:41 - 00000090 _____ C:\Users\LU\AppData\Roaming\WB.CFG 2013-09-16 17:41 - 2013-09-16 17:41 - 00000005 _____ C:\Users\LU\AppData\Roaming\WBPU-TTL.DAT 2013-09-16 17:06 - 2013-09-16 17:06 - 00026554 _____ C:\Users\LU\Desktop\gmer.log 2013-09-16 16:50 - 2013-09-16 16:51 - 00033153 _____ C:\Users\LU\Desktop\Addition.txt 2013-09-16 16:48 - 2013-09-16 16:48 - 00000000 ____D C:\FRST 2013-09-16 16:46 - 2013-09-16 16:47 - 00000466 _____ C:\Users\LU\Desktop\defogger_disable.log 2013-09-16 16:46 - 2013-09-16 16:46 - 00000000 _____ C:\Users\LU\defogger_reenable 2013-09-16 16:44 - 2013-09-16 16:45 - 01084083 _____ (Farbar) C:\Users\LU\Desktop\FRST.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00377856 _____ C:\Users\LU\Desktop\gmer_2.1.19163.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00050477 _____ C:\Users\LU\Desktop\Defogger.exe 2013-09-16 16:41 - 2013-09-16 16:41 - 00678784 _____ C:\Users\LU\Downloads\ZipOpenerSetup.exe 2013-09-16 15:58 - 2013-09-16 15:58 - 97787879 _____ C:\Windows\system32\랅觴ᰴ] 2013-09-13 12:11 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-09-13 12:11 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-09-13 12:11 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-09-13 12:11 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-09-13 12:11 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-09-13 12:11 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-09-13 12:11 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-09-13 09:35 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-09-13 09:35 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-09-13 09:35 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-09-13 09:34 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-09-13 09:34 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-09-13 09:34 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-09-13 09:34 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-09-13 09:34 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-09-13 09:34 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-09-12 23:36 - 2013-09-12 23:36 - 97412816 _____ C:\Windows\system32\圄抒ᰴ` 2013-09-11 00:29 - 2013-09-11 00:29 - 97004533 _____ C:\Windows\system32\冐ᰴi 2013-09-10 20:04 - 2013-09-10 20:04 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe_Systems_Incorporate 2013-09-10 19:52 - 2013-09-10 20:36 - 00000000 ____D C:\Users\LU\Documents\My Digital Editions 2013-09-10 19:52 - 2013-09-10 19:52 - 00002162 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk 2013-09-10 19:50 - 2013-09-10 19:50 - 05889712 _____ (Adobe Systems Incorporated) C:\Users\LU\Downloads\ADE_2.0_Installer.exe 2013-09-10 19:46 - 2013-09-10 19:46 - 00001196 _____ C:\Users\LU\Downloads\Russendisko.acsm 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\ProgramData\T-Online 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\Program Files\Common Files\T-Com 2013-09-09 12:05 - 2007-09-12 17:24 - 00026816 _____ (Printing Communications Assoc., Inc. (PCAUSA)) C:\Windows\system32\Drivers\DslTestSp5.sys 2013-09-09 12:03 - 2013-09-09 12:03 - 00000000 ____D C:\Program Files\DSL-Manager 2013-09-09 12:03 - 2007-08-01 14:49 - 00016448 _____ (T-Systems Enterprise Services GmbH) C:\Windows\system32\Drivers\dslmnlwf.sys 2013-09-09 12:02 - 2013-09-09 12:02 - 04118552 _____ (T-Online ) C:\Users\LU\Downloads\DSL-Manager_6.9.exe 2013-08-31 23:47 - 2013-08-31 23:47 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular (1).xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020892 _____ C:\Users\LU\Downloads\Marathonstaffeln Wechselpunktformular.xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular.xlsx 2013-08-30 10:10 - 2013-09-09 11:12 - 00000000 ____D C:\Program Files\Opera 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Roaming\Opera Software 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Local\Opera Software 2013-08-30 10:07 - 2013-08-30 10:09 - 32058408 _____ (Opera Software ASA) C:\Users\LU\Downloads\Opera_16.0.1196.62_Setup.exe 2013-08-30 10:06 - 2013-08-30 10:06 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-29 12:22 - 2013-08-29 14:59 - 94605346 _____ C:\Windows\system32\旹柳ᰴ] 2013-08-20 17:16 - 2013-08-20 17:16 - 99562272 _____ C:\Windows\system32\髦ᇣᰴg 2013-08-20 16:58 - 2013-08-20 16:58 - 06663848 _____ C:\Users\LU\Downloads\Niederschlag.zip 2013-08-18 17:01 - 2013-08-18 17:03 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung(1).zip 2013-08-18 17:00 - 2013-08-18 17:01 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung.zip 2013-08-18 13:17 - 2013-09-16 16:42 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-17 08:31 - 2013-07-11 19:06 - 00003752 _____ C:\Windows\setupact.log 2013-09-17 08:29 - 2013-09-17 08:29 - 00000041 _____ C:\Users\LU\Desktop\checkup.txt 2013-09-17 08:24 - 2013-01-20 13:44 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-09-17 08:24 - 2012-06-10 10:39 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-17 08:24 - 2011-04-28 19:03 - 01056756 _____ C:\Windows\WindowsUpdate.log 2013-09-16 21:39 - 2013-09-16 21:39 - 02347384 _____ (ESET) C:\Users\LU\Desktop\esetsmartinstaller_enu (1).exe 2013-09-16 21:39 - 2013-09-16 21:39 - 00891144 _____ C:\Users\LU\Desktop\SecurityCheck.exe 2013-09-16 21:39 - 2013-09-16 21:38 - 02347384 _____ (ESET) C:\Users\LU\Downloads\esetsmartinstaller_enu.exe 2013-09-16 19:09 - 2010-11-20 23:01 - 01684336 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-16 19:05 - 2013-09-16 19:05 - 00033360 _____ C:\Users\LU\Desktop\FRST_2.txt 2013-09-16 19:01 - 2013-09-16 19:01 - 00000902 _____ C:\Users\LU\Desktop\JRT.txt 2013-09-16 19:00 - 2009-07-14 06:34 - 00020400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-16 19:00 - 2009-07-14 06:34 - 00020400 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-16 18:54 - 2013-09-16 18:54 - 00000000 ____D C:\Windows\ERUNT 2013-09-16 18:52 - 2013-09-16 18:52 - 00008063 _____ C:\Users\LU\Desktop\AdwCleaner[S0].txt 2013-09-16 18:52 - 2012-06-10 10:39 - 00001086 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-16 18:51 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-16 18:50 - 2013-09-16 18:47 - 00000000 ____D C:\AdwCleaner 2013-09-16 18:46 - 2013-09-16 18:46 - 01029675 _____ (Thisisu) C:\Users\LU\Desktop\JRT.exe 2013-09-16 18:46 - 2013-09-16 18:45 - 01039554 _____ C:\Users\LU\Desktop\adwcleaner.exe 2013-09-16 18:41 - 2013-07-11 19:05 - 00088226 _____ C:\Windows\PFRO.log 2013-09-16 17:41 - 2013-09-16 17:41 - 00000090 _____ C:\Users\LU\AppData\Roaming\WB.CFG 2013-09-16 17:41 - 2013-09-16 17:41 - 00000005 _____ C:\Users\LU\AppData\Roaming\WBPU-TTL.DAT 2013-09-16 17:06 - 2013-09-16 17:06 - 00026554 _____ C:\Users\LU\Desktop\gmer.log 2013-09-16 16:51 - 2013-09-16 16:50 - 00033153 _____ C:\Users\LU\Desktop\Addition.txt 2013-09-16 16:48 - 2013-09-16 16:48 - 00000000 ____D C:\FRST 2013-09-16 16:47 - 2013-09-16 16:46 - 00000466 _____ C:\Users\LU\Desktop\defogger_disable.log 2013-09-16 16:46 - 2013-09-16 16:46 - 00000000 _____ C:\Users\LU\defogger_reenable 2013-09-16 16:46 - 2011-08-12 13:31 - 00000000 ____D C:\Users\LU 2013-09-16 16:45 - 2013-09-16 16:44 - 01084083 _____ (Farbar) C:\Users\LU\Desktop\FRST.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00377856 _____ C:\Users\LU\Desktop\gmer_2.1.19163.exe 2013-09-16 16:44 - 2013-09-16 16:44 - 00050477 _____ C:\Users\LU\Desktop\Defogger.exe 2013-09-16 16:42 - 2013-08-18 13:17 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-09-16 16:41 - 2013-09-16 16:41 - 00678784 _____ C:\Users\LU\Downloads\ZipOpenerSetup.exe 2013-09-16 16:25 - 2011-08-12 15:34 - 00000000 ____D C:\Users\LU\AppData\Roaming\Mozilla 2013-09-16 16:06 - 2011-08-12 13:38 - 00000000 ____D C:\Windows\pss 2013-09-16 15:58 - 2013-09-16 15:58 - 97787879 _____ C:\Windows\system32\랅觴ᰴ] 2013-09-16 15:57 - 2013-04-01 16:57 - 00000000 ___RD C:\Users\LU\Dropbox 2013-09-16 15:57 - 2013-04-01 16:45 - 00000000 ____D C:\Users\LU\AppData\Roaming\Dropbox 2013-09-15 15:18 - 2011-11-05 12:00 - 00079548 _____ C:\test.xml 2013-09-13 16:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-09-13 14:36 - 2009-07-14 06:33 - 00435144 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-13 14:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-09-13 12:27 - 2011-08-12 15:20 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-13 12:04 - 2013-07-24 17:10 - 00000000 ____D C:\Windows\system32\MRT 2013-09-13 12:00 - 2011-10-06 11:55 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-09-13 11:37 - 2012-05-26 09:27 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-09-13 11:37 - 2011-08-28 10:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-09-12 23:36 - 2013-09-12 23:36 - 97412816 _____ C:\Windows\system32\圄抒ᰴ` 2013-09-11 00:29 - 2013-09-11 00:29 - 97004533 _____ C:\Windows\system32\冐ᰴi 2013-09-10 20:36 - 2013-09-10 19:52 - 00000000 ____D C:\Users\LU\Documents\My Digital Editions 2013-09-10 20:04 - 2013-09-10 20:04 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe_Systems_Incorporate 2013-09-10 19:52 - 2013-09-10 19:52 - 00002162 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk 2013-09-10 19:52 - 2011-04-28 20:01 - 00000000 ____D C:\Program Files\Adobe 2013-09-10 19:50 - 2013-09-10 19:50 - 05889712 _____ (Adobe Systems Incorporated) C:\Users\LU\Downloads\ADE_2.0_Installer.exe 2013-09-10 19:46 - 2013-09-10 19:46 - 00001196 _____ C:\Users\LU\Downloads\Russendisko.acsm 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\ProgramData\T-Online 2013-09-09 12:05 - 2013-09-09 12:05 - 00000000 ____D C:\Program Files\Common Files\T-Com 2013-09-09 12:03 - 2013-09-09 12:03 - 00000000 ____D C:\Program Files\DSL-Manager 2013-09-09 12:03 - 2011-04-28 19:15 - 00000000 ___HD C:\Program Files\InstallShield Installation Information 2013-09-09 12:02 - 2013-09-09 12:02 - 04118552 _____ (T-Online ) C:\Users\LU\Downloads\DSL-Manager_6.9.exe 2013-09-09 11:12 - 2013-08-30 10:10 - 00000000 ____D C:\Program Files\Opera 2013-09-09 11:07 - 2013-08-16 16:31 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-09-03 09:20 - 2013-06-24 10:38 - 00000000 ____D C:\Users\LU\Desktop\Dokumente 2013-08-31 23:47 - 2013-08-31 23:47 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular (1).xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020892 _____ C:\Users\LU\Downloads\Marathonstaffeln Wechselpunktformular.xlsx 2013-08-31 23:46 - 2013-08-31 23:46 - 00020438 _____ C:\Users\LU\Downloads\5x2-km-Staffel Wechselpunktformular.xlsx 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Roaming\Opera Software 2013-08-30 10:10 - 2013-08-30 10:10 - 00000000 ____D C:\Users\LU\AppData\Local\Opera Software 2013-08-30 10:09 - 2013-08-30 10:07 - 32058408 _____ (Opera Software ASA) C:\Users\LU\Downloads\Opera_16.0.1196.62_Setup.exe 2013-08-30 10:07 - 2011-08-13 18:18 - 00000000 ____D C:\Users\LU\AppData\Local\Adobe 2013-08-30 10:06 - 2013-08-30 10:06 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk 2013-08-30 10:06 - 2011-10-07 14:05 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-08-30 10:06 - 2011-04-28 20:01 - 00000000 ____D C:\ProgramData\Adobe 2013-08-29 14:59 - 2013-08-29 12:22 - 94605346 _____ C:\Windows\system32\旹柳ᰴ] 2013-08-20 17:16 - 2013-08-20 17:16 - 99562272 _____ C:\Windows\system32\髦ᇣᰴg 2013-08-20 16:58 - 2013-08-20 16:58 - 06663848 _____ C:\Users\LU\Downloads\Niederschlag.zip 2013-08-20 11:27 - 2013-08-16 16:35 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2013-08-20 11:27 - 2013-08-16 16:31 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-08-18 18:02 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-08-18 17:56 - 2010-11-20 22:57 - 00000000 ____D C:\Users\Administrator 2013-08-18 17:56 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-08-18 17:03 - 2013-08-18 17:01 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung(1).zip 2013-08-18 17:01 - 2013-08-18 17:00 - 18839897 _____ C:\Users\LU\Downloads\Dateiordner_Folien_Vorlesung.zip 2013-08-18 12:25 - 2011-02-11 02:15 - 00000000 ____D C:\Windows\Panther Some content of TEMP: ==================== C:\Users\LU\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-31 21:49 ==================== End Of Log ============================ --- --- --- Ich hab jetzt grad nochmal Malwarebytes nochmal drüber laufen lassen und da wurde immernoch was gefunden: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.17.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16686 LU :: LU-VAIO [Administrator] 17.09.2013 08:41:28 MBAM-log-2013-09-17 (08-59-02).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 234428 Laufzeit: 17 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 3 C:\Users\LU\AppData\Local\Temp\mt_ffx\Delta (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\mt_ffx\Delta\delta (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.24.6 (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. Infizierte Dateien: 8 C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\BabMaint.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\CrxInstaller.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\DSearchLink.exe (PUP.Optional.Delta.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\MntrDLLInstall.dll (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\MyDeltaTB.exe (PUP.Optional.Delta) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\99CD1B80-BAB0-7891-B0F7-3F35A91ED964\Latest\Setup.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. C:\Users\LU\AppData\Local\Temp\is357113909\2038421_stp\DeltaTB.exe (PUP.Optional.Babylon.A) -> Keine Aktion durchgeführt. (Ende) |
17.09.2013, 13:16 | #6 |
/// the machine /// TB-Ausbilder | Probleme mit PUP Virus-68 infizierte Objekte Da werden nur Tempfiles angemeckert Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ --> Probleme mit PUP Virus-68 infizierte Objekte |
17.09.2013, 15:19 | #7 |
| Probleme mit PUP Virus-68 infizierte Objekte Grüß dich, hab alles gemacht und Malwarebytes zeigt auch nix mehr an! Vielen, vielen, vielen lieben Dank für deine Hilfe!!!!!!!!!!! und danke auch für die Tipps Viele Grüße Luisa |
17.09.2013, 16:24 | #8 |
/// the machine /// TB-Ausbilder | Probleme mit PUP Virus-68 infizierte Objekte Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Probleme mit PUP Virus-68 infizierte Objekte |
adobe, antivirus, avira, branding, computer, dateiordner, defender, device driver, diagnostics, epupdater, farbar, farbar recovery scan tool, fehlercode 1, flash player, infizierte, install.exe, installation, mozilla, msiinstaller, nicht installiert, ntdll.dll, officejet, phishing, plug-in, pup.optional.babsolution.a, pup.optional.babylon.a, pup.optional.delta, pup.optional.delta.a, pup.optional.installcore.a, pup.optional.startpage, realtek, registry, services.exe, software, svchost.exe, wsearch |